# Calculations inside ES Query

**URL:** <https://discuss.elastic.co/t/calculations-inside-es-query/323610>\
**Category:** Elasticsearch\
**Tags:** kql-kibana-query-language, eql-elastic-query-language\
**Created:** [January 20, 2023, 3:56pm UTC](https://discuss.elastic.co/t/calculations-inside-es-query/323610 "2023-01-20T15:56:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bpax51](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bpax51/32/116217_2.png) [@bpax51](https://discuss.elastic.co/u/bpax51)\
**Post date:** [January 20, 2023, 3:56pm UTC](https://discuss.elastic.co/t/calculations-inside-es-query/323610/1 "2023-01-20T15:56:01Z")

</div>

So I have to following query that gives me to count of successful and failed http queries using aggregations.

```auto
{
    "size": 0,
    "query": {
        "bool": {
            "filter": [
                {
                    "match_phrase": {
                        "protocol": {
                            "query": "http"
                        }
                    }
                },
                {
                    "bool": {
                        "should": [
                            {
                                "match_phrase": {
                                    "destination": {
                                        "query": "75.124.145.217"
                                    }
                                }
                            },
                            {
                                "match_phrase": {
                                    "destination.domain": {
                                        "query": "75.124.145.218"
                                    }
                                }
                            }
                        ],
                    }
                },
                {
                    "range": {
                        "@timestamp": {
                            "from": "now-1d",
                        }
                    }
                }
            ],
        }
    },
    "aggregations": {
        "tot_success": {
            "filter": {
                "term": {
                    "http.response.status_code": {
                        "value": "200"
                    }
                }
            }
        },
        "tot_error": {
            "filter": {
                "bool": {
                    "must_not": [
                        {
                            "term": {
                                "http.response.status_code": {
                                    "value": "200"
                                }
                            }
                        }
                    ]
                }
            }
        }
    }
}

```

That result is like the following:

```auto
{
    "_shards": {
        "total": 320,
        "failed": 0,
        "successful": 320,
        "skipped": 315
    },
    "hits": {
        "hits": [],
        "total": {
            "value": 821,
            "relation": "eq"
        },
        "max_score": null
    },
    "took": 815,
    "timed_out": false,
    "aggregations": {
        "tot_success": {
            "doc_count": 809
        },
        "tot_error": {
            "doc_count": 12
        }
    }
}

```

I was wondering if there is anyway I can make mathematical calculations with the aggregations result and get a result within the same query.

For example calculating the ratio of **tot\_error/tot\_success**.

I looked around and found that bucket script might be the solution to my problem, but to be honest I couldn't manage to implement it in my previous query

Can someone help me achieve this.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [January 20, 2023, 4:43pm UTC](https://discuss.elastic.co/t/calculations-inside-es-query/323610/2 "2023-01-20T16:43:07Z")

</div>

Would you be able to provide the example query with bucket\_script that you came up with? I believe you'd want to do something similar to this example: [calculate ratio between aggregation buckets · Issue #16040 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/16040#issuecomment-172518421)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2023, 4:43pm UTC](https://discuss.elastic.co/t/calculations-inside-es-query/323610/3 "2023-02-17T16:43:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
