# Calculations on Bucket's doc\_count

**URL:** <https://discuss.elastic.co/t/calculations-on-buckets-doc-count/127518>\
**Category:** Elasticsearch\
**Created:** [April 10, 2018, 4:28pm UTC](https://discuss.elastic.co/t/calculations-on-buckets-doc-count/127518 "2018-04-10T16:28:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [April 10, 2018, 4:28pm UTC](https://discuss.elastic.co/t/calculations-on-buckets-doc-count/127518/1 "2018-04-10T16:28:18Z")

</div>

Hi all,  
I'm trying to get some statistics about certain events by time interval.  
Is it possible to use a Pipeline aggregation that uses the doc\_count of the parent aggregation?  
Something like this...  
Thank you!  
Ana

```
GET /temp_sbc2/_search?size=0
{
  "query": {
                        "bool": {
                          "must" : [
                                {"term": {"oper.keyword": "START"}},
                                {"term": { "dir.keyword": "O"}},
                                {"term": { "tags.keyword": "parsed_ok" }},
                                {"range": {
                                  "@timestamp": {
                                    "gte": "2018-03-01T00:00:00.00000Z",
                                    "lte": "now" }
                                }}
                                
                        ]
        								}
   },
    "aggs" : {
            "start_over_time" : {
              "date_histogram" : {
                "min_doc_count" : 300,
                "field" : "@timestamp",
                "interval" : "5m"
            },"aggs": {
          "test": {
        "avg_bucket": {
          "buckets_path": "start_over_time>doc_count"
        }
      }
    }
}}}
```

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [April 11, 2018, 7:43am UTC](https://discuss.elastic.co/t/calculations-on-buckets-doc-count/127518/2 "2018-04-11T07:43:02Z")

</div>

There is a [special path "`_count`"](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html#_special_paths) that gives you the doc\_count of the buckets in a bucket aggregation.

The `avg_bucket` aggregation is a sibling aggregation, so you need to restructure your request a bit. The following should work:

```auto
GET /temp_sbc2/_search?size=0
{
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "oper.keyword": "START"
          }
        },
        {
          "term": {
            "dir.keyword": "O"
          }
        },
        {
          "term": {
            "tags.keyword": "parsed_ok"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "2018-03-01T00:00:00.00000Z",
              "lte": "now"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "start_over_time": {
      "date_histogram": {
        "min_doc_count": 300,
        "field": "@timestamp",
        "interval": "5m"
      }
    },
    "test": {
      "avg_bucket": {
        "buckets_path": "start_over_time>_count"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [April 11, 2018, 8:00am UTC](https://discuss.elastic.co/t/calculations-on-buckets-doc-count/127518/3 "2018-04-11T08:00:35Z")

</div>

Many Many Thanks @abdon  
It worked like a charm!

Regards  
Ana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2018, 8:00am UTC](https://discuss.elastic.co/t/calculations-on-buckets-doc-count/127518/4 "2018-05-09T08:00:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
