# Can't filter Rollup index results

**URL:** <https://discuss.elastic.co/t/cant-filter-rollup-index-results/264097>\
**Category:** Kibana\
**Created:** [February 12, 2021, 8:52am UTC](https://discuss.elastic.co/t/cant-filter-rollup-index-results/264097 "2021-02-12T08:52:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [February 12, 2021, 8:52am UTC](https://discuss.elastic.co/t/cant-filter-rollup-index-results/264097/1 "2021-02-12T08:52:24Z")

</div>

Hi,

I have a rollup index with some values, e.g. `customer`. I've created a Kibana dashboard from it. When I try to filter the dashboard with `customer : some-customer`, I get an error. When I do a [custom query](https://gist.github.com/a8bef790b940cc1cf16d5d1675be987b), I can filter by customer, but the trick is that I have to hit the `/[index]/_rollup_search` endpoint.

Is this the reason the Kibana dashboard doesn't work? Is there something I can make it work?

Both Kibana and Elasticsearch are at v7.9.1.

Kibana gives me a [log output](https://gist.github.com/a4eb37577b4fb845e607317bef6a4b0d) saying there was a 400 error, but Elasticsearch is silent.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 22, 2021, 4:06pm UTC](https://discuss.elastic.co/t/cant-filter-rollup-index-results/264097/2 "2021-02-22T16:06:33Z")

</div>

Can you share the mappings of the rollup index, along with the exact query you are providing? And if you're using KQL or lucene query. I'm thinking there could be a syntax error with your query, somehow.

---

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [February 25, 2021, 7:18am UTC](https://discuss.elastic.co/t/cant-filter-rollup-index-results/264097/3 "2021-02-25T07:18:16Z")

</div>

- Mappings of the rollup index: [here](https://gist.github.com/rokcarl/6ccd0db96d5bbce37125cdf60c7029a7).
- The exact query is what I wrote above: `customer : some-customer`. This is KQL, as far as I'm aware. I don't see the underlying Elasticsearch query that Kibana does.

I've tried debugging this while being on Visualize and I get more info here. If I filter for `app : some-app`, you can see the [video here](https://user-images.githubusercontent.com/42874/109116635-27d85280-7741-11eb-91cb-6fb877390aec.gif), I get the following in my chrome debugger tools:

```
{"statusCode":400,"error":"Bad Request","message":"[illegal_argument_exception] Unsupported Query in search request: [match]","attributes":{"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"Unsupported Query in search request: [match]"}],"type":"illegal_argument_exception","reason":"Unsupported Query in search request: [match]"}}}

```

Additionally, I have a problem doing an average of `credits`, [video here](https://user-images.githubusercontent.com/42874/109116643-2ad34300-7741-11eb-9027-cfecf32aeb52.gif), but a sum works okay. The error is:

```
{"statusCode":500,"error":"Internal Server Error","message":"[aggregation_execution_exception] Invalid aggregation order path [1]. The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets.","attributes":{"error":{"root_cause":[{"type":"aggregation_execution_exception","reason":"Invalid aggregation order path [1]. The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets."}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"stat_rollups","node":"UQqa5Uz0Ti2QrLk0cxX8NQ","reason":{"type":"aggregation_execution_exception","reason":"Invalid aggregation order path [1]. The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets.","caused_by":{"type":"illegal_argument_exception","reason":"The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets."}}}]}}}

```

So I'm guessing this is a bug in Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2021, 7:18am UTC](https://discuss.elastic.co/t/cant-filter-rollup-index-results/264097/4 "2021-03-25T07:18:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
