# Data Frame Aggregation Order

**URL:** <https://discuss.elastic.co/t/data-frame-aggregation-order/209473>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [November 26, 2019, 10:42am UTC](https://discuss.elastic.co/t/data-frame-aggregation-order/209473 "2019-11-26T10:42:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 26, 2019, 10:42am UTC](https://discuss.elastic.co/t/data-frame-aggregation-order/209473/1 "2019-11-26T10:42:31Z")

</div>

Kibana 7.3.2 Data Frames

No matter in what order I add aggregations, somehow some fields are always added first in the result..

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/627bbfd1f796acee9c36357dfce4aed7ca8f2e64.png)

As you can see in the above, event.outcome is in the first column, while added after the ruleset...

Pivot json:

```
{
  "group_by": {
    "panw.panos.ruleset": {
      "terms": {
        "field": "panw.panos.ruleset"
      }
    },
    "event.outcome": {
      "terms": {
        "field": "event.outcome"
      }
    }
  },
  "aggregations": {
    "panw.panos.flow_id.cardinality": {
      "cardinality": {
        "field": "panw.panos.flow_id"
      }
    }
  }
}

```

Is this a bug or am I missing something

---

<div class="post-metadata">

**Author:** ![walterra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/walterra/32/139867_2.png) [@walterra](https://discuss.elastic.co/u/walterra)\
**Post date:** [November 26, 2019, 3:51pm UTC](https://discuss.elastic.co/t/data-frame-aggregation-order/209473/2 "2019-11-26T15:51:05Z")

</div>

Thanks for the feedback!

The columns in the preview table show the group-by columns first, then the aggregated columns. Within each group (group-by/aggregations) the columns are sorted alphabetically.

Note that the column order doesn't affect the result of the transform, the resulting transformed index will always be the same regardless of the order in the form or preview.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2019, 3:51pm UTC](https://discuss.elastic.co/t/data-frame-aggregation-order/209473/3 "2019-12-24T15:51:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
