# Combine Terms aggregation with Composite aggregation

**URL:** <https://discuss.elastic.co/t/combine-terms-aggregation-with-composite-aggregation/308573>\
**Category:** Elasticsearch\
**Tags:** vega\
**Created:** [June 30, 2022, 12:29pm UTC](https://discuss.elastic.co/t/combine-terms-aggregation-with-composite-aggregation/308573 "2022-06-30T12:29:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mirokrastev](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mirokrastev](https://discuss.elastic.co/u/mirokrastev)\
**Post date:** [June 30, 2022, 12:29pm UTC](https://discuss.elastic.co/t/combine-terms-aggregation-with-composite-aggregation/308573/1 "2022-06-30T12:29:56Z")

</div>

I have the following ES Query

```auto
GET logstash-*/_search
{
  "size": 0,
  "aggs": {
    "table": {
      "composite": {
        "size": 10000,
        "sources": [
          {
            "stk1": {
              "terms": {
                "field": "geo.src"
              }
            }
          },
          {
            "stk2": {
              "terms": {
                "field": "geo.dest"
              }
            }
          }
        ]
      }
    }
  }

```

I want the composite bucket to include only `geo.src` from top X, which I can get with Terms aggregation.

How can I mix both Terms aggregation AND composite aggregation to create buckets for only the top 10 results from Terms aggregation? I want to have at max 10 `geo.src` with however many `geo.dest` it connects to.

Terms aggregation query:

```auto
GET logstash-*/_search
{
  "size": 0,
  "aggs": {
    "top_10": {
      "terms": {
        "field": "geo.src",
        "size": 10
      }
    }
  }
}

```

Response from Terms aggregation:

```auto
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "top_10" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 5444,
      "buckets" : [
        {
          "key" : "CN",
          "doc_count" : 2626
        },
        {
          "key" : "IN",
          "doc_count" : 2326
        },
        {
          "key" : "US",
          "doc_count" : 1201
        },
        {
          "key" : "ID",
          "doc_count" : 461
        },
        {
          "key" : "BR",
          "doc_count" : 396
        },
        {
          "key" : "PK",
          "doc_count" : 368
        },
        {
          "key" : "BD",
          "doc_count" : 348
        },
        {
          "key" : "NG",
          "doc_count" : 313
        },
        {
          "key" : "RU",
          "doc_count" : 272
        },
        {
          "key" : "JP",
          "doc_count" : 250
        }
      ]
    }
  }
}

```

I've looked up at pipeline aggregation, multi terms and top\_hits, but it does not satisfy me. I need the composite aggregation response for Sankey diagram ([Sankey Visualization with Vega in Kibana 6.2 | Elastic Blog](https://www.elastic.co/blog/sankey-visualization-with-vega-in-kibana))

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2022, 12:30pm UTC](https://discuss.elastic.co/t/combine-terms-aggregation-with-composite-aggregation/308573/2 "2022-07-28T12:30:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
