# Attempting to perform aggregation script on ES buckets

**URL:** <https://discuss.elastic.co/t/attempting-to-perform-aggregation-script-on-es-buckets/197155>\
**Category:** Elasticsearch\
**Created:** [August 28, 2019, 3:24pm UTC](https://discuss.elastic.co/t/attempting-to-perform-aggregation-script-on-es-buckets/197155 "2019-08-28T15:24:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arty\_Sidorenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arty_sidorenko/32/53190_2.png) [@Arty\_Sidorenko](https://discuss.elastic.co/u/Arty_Sidorenko)\
**Post date:** [August 28, 2019, 3:24pm UTC](https://discuss.elastic.co/t/attempting-to-perform-aggregation-script-on-es-buckets/197155/1 "2019-08-28T15:24:43Z")

</div>

Hi,

I'm trying to use a bucket script to calculate the proportion of total of one of my buckets (query snippet below).

I was getting an error of type "Only sibling pipeline aggregations are allowed at the top level" so I included an outer aggregation with a filter that matches all (found the fix on this forum).

But currently it's not providing any result. Does anybody see any problem with my query? If this script is even possible?

Many thanks!

```
{
"size": 0,
"query": {
    "bool": {
        "must": [
            {
                "match_phrase": {
                    "url": {
                        "query": "/oauth/challenge",
                        "slop": 0,
                        "zero_terms_query": "NONE",
                        "boost": 1
                    }
                }
            },
            {
                "match_phrase": {
                    "useragent.name": {
                        "query": "familyApp",
                        "slop": 0,
                        "zero_terms_query": "NONE",
                        "boost": 1
                    }
                }
            },
            {
                "match_phrase": {
                    "web_server": {
                        "query": "test",
                        "slop": 0,
                        "zero_terms_query": "NONE",
                        "boost": 1
                    }
                }
            }
        ]
    }
},
"aggs": {
    "all_matching_docs": {
        "filters": {
            "filters": {
                "all": {
                    "match_all": {}
                }
            }
        },
        "aggs": {
            "total_attempts": {
                "value_count": {
                    "field": "response_code.keyword"
                }
            },
            "result": {
                "filter": {
                    "term": {
                        "response_code.keyword": {
                            "value": "200",
                            "boost": 1
                        }
                    }
                }
            },
            "test_script": {"bucket_script": {
                "buckets_path": {
                    "200": "result>_count", 
                    "total": "total_attempts"
                },
                "script": "200 / total"
            }}
        }
    }
}

```

}

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 30, 2019, 5:29pm UTC](https://discuss.elastic.co/t/attempting-to-perform-aggregation-script-on-es-buckets/197155/2 "2019-08-30T17:29:54Z")

</div>

You'll need to prefix the variable names with `params.` in the script. E.g. `params.total`

I would also avoid using a numeric identifier for the variable name, since the painless parser will probably interpret `200 / total` as a `(long) 200` not `params.get("200")`. Probably better to call it `response_200`, `two_hundred_status` etc.

As an FYI, we recently merged an enhancement to allow pipeline aggs to reference specific keys from a `terms` agg ([docs here](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/search-aggregations-pipeline.html#buckets-path-syntax), scroll down a bit to `"a bucket_script could select two specific buckets (via their bucket keys) to perform the calculation"`)

That would let you do a single terms agg across `response_code.keyword`, then have a `bucket_script` calculate `response_codes['200'] / _count` which is probably easier than the current setup.

> I was getting an error of type "Only sibling pipeline aggregations are allowed at the top level" so I included an outer aggregation with a filter that matches all (found the fix on this forum).

Yeah, this is an unfortunate irritation ☹ We have a ticket tracking it and hope to get it fixed at some point, but there are some technical things making it not super-easy at the moment.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 5:29pm UTC](https://discuss.elastic.co/t/attempting-to-perform-aggregation-script-on-es-buckets/197155/3 "2019-09-27T17:29:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
