# Elasticsearch Aggregation Error

**URL:** <https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946>\
**Category:** Elasticsearch\
**Created:** [June 14, 2018, 2:53pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946 "2018-06-14T14:53:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [June 14, 2018, 2:53pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/1 "2018-06-14T14:53:20Z")

</div>

Hi All,

I am using Graylog as our web interface and have Elasticsearch in the backend. We run aggregation searches for alerting in Graylog, but we seem to be getting errors which cause Elasticsearch to stop working for a few minutes.

I have tried setting my index mapping to field data = true for the streams field but that didn't seem to work.

Below is the offending log within the ES log file.

[https://pastebin.com/BughdWZD](https://pastebin.com/BughdWZD)

Cheers,

George

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [June 18, 2018, 11:10am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/2 "2018-06-18T11:10:16Z")

</div>

Anyone got any ideas? This is causing us some serious problems.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 18, 2018, 11:21am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/3 "2018-06-18T11:21:33Z")

</div>

Filter `gl2_filter` looks to be the source of the complaint. It's actually superfluous in your requests so removing it may be a client-side workaround.

---

<div class="post-metadata">

**Author:** ![Johnnycc1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnnycc1/32/26069_2.png) [@Johnnycc1](https://discuss.elastic.co/u/Johnnycc1)\
**Post date:** [June 18, 2018, 11:27am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/4 "2018-06-18T11:27:18Z")

</div>

The error from your log is java.lang.IllegalStateException: "value source config is invalid; must have either a field context or a script or marked as unwrapped".

I wonder if you can run the query in the log directly against elasticsearch.

From what I can see on my phone the aggregation looks like it's missing a field setting for the terms aggregation.

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [June 18, 2018, 1:17pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/5 "2018-06-18T13:17:12Z")

</div>

@Mark_Harwood  
The aggregation searches are coming from inbuilt alerting functions on the Graylog web client, I am unsure how I would remove the gl2\_terms field from the query.

I will let the guys at Graylog know and maybe then can do some further testing and resolve the issue.

@Johnnycc1

Could you advise me on how to run the query directly against Elasticsearch?

Cheers both for your replies,

George

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 18, 2018, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/6 "2018-06-18T13:23:02Z")

</div>

Good spot, @Johnnycc1 - the `gl2_terms` aggregation is indeed missing a choice of field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2018, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-error/135946/7 "2018-07-16T13:23:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
