# ES|QL and the \_size field

**URL:** <https://discuss.elastic.co/t/es-ql-and-the-size-field/374753>\
**Category:** Elasticsearch\
**Tags:** esql\
**Created:** [February 19, 2025, 10:48am UTC](https://discuss.elastic.co/t/es-ql-and-the-size-field/374753 "2025-02-19T10:48:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pilarjin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pilarjin/32/141451_2.png) [@pilarjin](https://discuss.elastic.co/u/pilarjin)\
**Post date:** [February 19, 2025, 10:48am UTC](https://discuss.elastic.co/t/es-ql-and-the-size-field/374753/1 "2025-02-19T10:48:46Z")

</div>

Hi, is it possible to use `_size` field in ES|QL? I didn't find it mentioned in the [limitations documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql-limitations.html).

We are trying to identify traces that generate too much data as feedback for developers what to optimize.

Example query summing size of all traces with the same name per service:

```esql
FROM .ds-traces-apm-default-2025.02.18-007935
| EVAL traceName=CASE(parent.id IS NULL, transaction.name, null) 
| STATS traceSize=SUM(_size), traceName=MAX(traceName) BY trace.id, service.name, service.environment 
| EVAL traceName=CASE(traceName IS NOT NULL, traceName, trace.id) 
| STATS sumTraceSizeMiB=TO_DOUBLE(SUM(traceSize))/(1024*1024) by traceName, service.name, service.environment 
| SORT sumTraceSizeMiB DESC 
| LIMIT 30 

```

Results in error

> Unable to retrieve search results
> 
> [esql] \> Unexpected error from Elasticsearch: verification\_exception - Found 1 problem  
> line 3:23: Unknown column [\_size]

In discover I see `_size` correctly.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/555012c22412e11bce2cca27b151f0e0edb0a7ae.png)

We are using Elastic Cloud 8.17.1.

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [February 19, 2025, 11:13am UTC](https://discuss.elastic.co/t/es-ql-and-the-size-field/374753/2 "2025-02-19T11:13:13Z")

</div>

I don't think it's possible to play with \_size. \_size is a metadata field, and I can't find it on the list of metadata fields that can be used with ESQL

> **[ES|QL metadata fields | Elasticsearch Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql-metadata-fields.html)**
