# Elastic Search percentile aggregations filtering issue

**URL:** <https://discuss.elastic.co/t/elastic-search-percentile-aggregations-filtering-issue/165037>\
**Category:** Elasticsearch\
**Created:** [January 21, 2019, 11:22am UTC](https://discuss.elastic.co/t/elastic-search-percentile-aggregations-filtering-issue/165037 "2019-01-21T11:22:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sukku77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukku77/32/52068_2.png) [@sukku77](https://discuss.elastic.co/u/sukku77)\
**Post date:** [January 21, 2019, 11:22am UTC](https://discuss.elastic.co/t/elastic-search-percentile-aggregations-filtering-issue/165037/1 "2019-01-21T11:22:58Z")

</div>

Hi Guys,  
Below is my problem statement  
I have one post search call to elasticsearch which is having query to calculate 99% percentile aggregations on one of the field. In return i am getting proper response with aggregations which is 99% percentile calculated field values. But I need to apply filter, using "bucket\_selector" to filter out the values. For instance, if the percentile field value is \> 60 then i need to include in my report generation.  
Below is my sample aggregation request json:

```
{
  "aggs": {
    "2": {
       "terms": {
       "field": "component",
       "size": 500,
       "order": {
       "1": "desc"
      }
     },
     "aggs": {
          "1": {
               "percentiles": {
                   "field": "field1",
                    "percents": [
                        99
                     ],
              "keyed": false
               }
          },
    "filter_gt_than_60sec": {
      "bucket_selector": {
        "buckets_path": {
          "value": "1"
        },
        "script": "params.value > 60L"
      }
    }
  }
  }
 },
  "size": 0,
  "_source": {
	"excludes": []
  },
  "stored_fields": [
	"*"
  ],
  "script_fields": {},
  "query": {
	"bool": {
	  "must": [
		{
		  "match_all": {}
		},
		{
		  "range": {
			"@timestamp": {
			  "gte": 1547889125683,
			  "lte": 1547975525684,
			  "format": "epoch_millis"
			}
		  }
		}
	  ],
	  "filter": [],
	  "should": [],
	  "must_not": []
	}
  },
  "timeout": "30000ms"
 }

```

Error i am getting:

```
	{
		"error": {
			"root_cause": [],
			"type": "search_phase_execution_exception",
			"reason": "",
			"phase": "fetch",
			"grouped": true,
			"failed_shards": [],
			"caused_by": {
				"type": "aggregation_execution_exception",
				"reason": "buckets_path must reference either a number value or a single value numeric metric aggregation, got: org.elasticsearch.search.aggregations.metrics.percentiles.tdigest.InternalTDigestPercentiles"
			}
		},
		"status": 503
	}

```

I understood from the above error is that, I can't apply "bucket\_selector" on percentile fields, Then how can i filter out the aggregated response "field1" whose values are greater than 60. I read about "percentile\_bucket" but it is to calculate percentiles on field values; but it is not filter on the aggregated percentile fields. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [January 28, 2019, 10:15pm UTC](https://discuss.elastic.co/t/elastic-search-percentile-aggregations-filtering-issue/165037/2 "2019-01-28T22:15:51Z")

</div>

I'm not at a computer where I can test this, but you should be able to use [bracket syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html#dots-in-agg-names) to access the individual percents of the percentiles agg. Something like:

```auto
"buckets_path": {
  "value": "1[99.0]"
},

```

---

<div class="post-metadata">

**Author:** ![sukku77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukku77/32/52068_2.png) [@sukku77](https://discuss.elastic.co/u/sukku77)\
**Post date:** [January 29, 2019, 8:29am UTC](https://discuss.elastic.co/t/elastic-search-percentile-aggregations-filtering-issue/165037/3 "2019-01-29T08:29:58Z")

</div>

Thanks a lot. It is working now with the format that you provided above.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2019, 8:30am UTC](https://discuss.elastic.co/t/elastic-search-percentile-aggregations-filtering-issue/165037/4 "2019-02-26T08:30:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
