# Field Filtering and Basic Math With Painless

**URL:** <https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452>\
**Category:** Kibana\
**Created:** [June 12, 2019, 3:06pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452 "2019-06-12T15:06:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 12, 2019, 3:06pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452/1 "2019-06-12T15:06:10Z")

</div>

Configuring a bucket script in TSVB and I want to filter on one field and then do some basic math on another. I've looked at the documentation in the Elasticsearch reference but it's not formatted the same as what Kibana is looking for, or at least I think it isn't. I know some of the painless language but not all so if someone can show me what the proper syntax is for where I am wrong below, I'd appreciate it.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7d3afb0308fa0d7fefd65edb900c946ceae122d.png)

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 12, 2019, 6:32pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452/2 "2019-06-12T18:32:26Z")

</div>

[Bucket aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-bucket-script-aggregation.html) can only be used to perform per bucket computations on specified metrics. Bucket aggregations can not be used to filter documents and do not have access to document properties.

Try using a filter aggregation before the bucket script aggregation to perform the filtering. You will also need a metric aggregation to calculate some metric on EdgeBytes such as sum, min, max, avg. You can then use the sum, min, max, or avg value in a bucket script aggregation.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 12, 2019, 7:13pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452/3 "2019-06-12T19:13:31Z")

</div>

I'm looking through the aggregation methods in TSVB Metric but I don't see one specifically called filter and I don't believe filter ratio will give me what I'm looking for. What am I missing?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 12, 2019, 8:16pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452/4 "2019-06-12T20:16:41Z")

</div>

Aggregations can be [nested](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-nested-aggregation.html). The filter aggregation filters the data. then the bucket script aggregation can be used to process the results from the filter aggregation

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 12, 2019, 8:37pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452/5 "2019-06-12T20:37:39Z")

</div>

The problem I am having is all the documentation is geared towards making queries directly against Elasticsearch. I know that's what Kibana is doing but I don't see an interface exposed to me that allows it to be done. I am also not seeing how to accomplish this in the GUI, the filter aggregate itself is not present. In TSVB\>Metric, if I select the Options tab, I see the ability to filter but that will filter all aggregations for that series. It also doesn't look like I can reference an aggregation from one series in another.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2019, 8:47pm UTC](https://discuss.elastic.co/t/field-filtering-and-basic-math-with-painless/185452/6 "2019-07-10T20:47:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
