# Bucket-key=custom, value=array(\_ids) aggregation?

**URL:** <https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682>\
**Category:** Elasticsearch\
**Created:** [April 28, 2016, 1:46pm UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682 "2016-04-28T13:46:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [April 28, 2016, 1:46pm UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/1 "2016-04-28T13:46:10Z")

</div>

Hi!,

I have a mapping with fields "`a string,b string,c string,t timestamp`". Can I make bucket aggregations, where I can specify the key to be for example::

`key=t(yymmdd):a:b` (generate the key from script)

Each bucket should have as `value an array of documents` with the ability to also include \_source. Ability to return top(x) + doc-count if there are alot of documents in a bucket.

The buckets should be `sortable by a field-value (ex: t timestamp)`

`Ability to limit the number of buckets.`

I also need to get back the min(timestamp) that is on the whole aggregation (in case the last bucket has too many documents to return the \_source of them all).

Is this possible ? If not, can I do anything (custom java?) to make it possible ?

I think this can be done using terms-script-aggregation to generate the initial buckets [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script)  
+  
top-hits as sub-aggregation to return the documents for each bucket [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html) ?

But I don't know how to get the "minimum timestamp" on the last bucket ? Maybe by sorting by timestamp-ascending on the top-hits-sub-aggregation (so I get the top-documents) ?

Makes sense ?

Thanks

---

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [April 30, 2016, 11:03am UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/2 "2016-04-30T11:03:13Z")

</div>

shameless bumping

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2016, 11:18am UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/3 "2016-05-04T11:18:15Z")

</div>

Can you reformat your OP, it's hard to see what is happening. Wrap it in code tags 🙂

---

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [May 4, 2016, 10:38pm UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/4 "2016-05-04T22:38:27Z")

</div>

Hope it's more clear now.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2016, 11:21pm UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/5 "2016-05-04T23:21:41Z")

</div>

It sounds like you are on the right track, regarding scripting. But I can't help there as I don't know much on that.

However a better solution might be to look at crafting fields with these sorts of values during ingestion, that way it'll be much simpler (and better on your resources).

---

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [May 4, 2016, 11:25pm UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/6 "2016-05-04T23:25:41Z")

</div>

The "what/how to group on" is dynamic (from the client side) so I can't do that. I just wanted to know if that's the right way, and looks like it is.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:53pm UTC](https://discuss.elastic.co/t/bucket-key-custom-value-array--ids-aggregation/48682/7 "2017-07-05T22:53:55Z")

</div>


