# Filter with aggregate value in Query DSL

**URL:** <https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [October 13, 2020, 2:05pm UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915 "2020-10-13T14:05:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![coline](https://avatars.discourse-cdn.com/v4/letter/c/34f0e0/32.png) [@coline](https://discuss.elastic.co/u/coline)\
**Post date:** [October 13, 2020, 2:05pm UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/1 "2020-10-13T14:05:00Z")

</div>

Hi everybody,  
I'm kind of new on elastic and I'm trying to apply this filter on my index : cpu \> 0.6 x max\_daily\_cpu. I succeed to create a query to get the max daily CPU :

```
POST /_search
{
      "size": 0,
      "aggs": {
        "cpu_per_day": {
         "date_histogram": {
          "field": "@timestamp",
          "calendar_interval": "day"
          },
          "aggs": {
            "max_daily_cpu": {
             "max": {
                "field": "cpu_load"
            }
          }
        }
     }
   }
 }

```

But I don't know how to use this result in a query DSL.  
Thanks for your help!

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [October 13, 2020, 7:09pm UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/2 "2020-10-13T19:09:47Z")

</div>

Can you be more specific about how you intend to use the results where this filter is being applied? Depending on your use case, the answer could range from "this isn't supported" to "there is a simple way to do this".

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 13, 2020, 7:19pm UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/3 "2020-10-13T19:19:50Z")

</div>

I think you are looking to add a [bucket selector aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-bucket-selector-aggregation.html).

Something similar to the below.

```auto
{
  "bucket_selector": {
    "buckets_path": {
      "my_var1": "cpu_per_day",                     
      "my_var2": "max_daily_cpu"
    },
    "script": "params.my_var1 > (params.my_var2 * .6)"
  }
}

```

---

<div class="post-metadata">

**Author:** ![coline](https://avatars.discourse-cdn.com/v4/letter/c/34f0e0/32.png) [@coline](https://discuss.elastic.co/u/coline)\
**Post date:** [October 14, 2020, 7:22am UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/4 "2020-10-14T07:22:41Z")

</div>

Firstly, it will be use in Discover to access to every document in my index that matches the filter and then this filter will be apply in some visualizations (for example, the average CPU for each device, the average size of network packet by device...).

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [October 14, 2020, 2:40pm UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/5 "2020-10-14T14:40:46Z")

</div>

Kibana filters can only operate on values that exist in individual documents, so you can't filter based on aggregates. If you had a field on individual documents that represented the average CPU usage, then you could do this. Some users find that the [transforms](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html) feature of Elasticsearch is able to do this, but you'd have to evaluate it for your use.

---

<div class="post-metadata">

**Author:** ![coline](https://avatars.discourse-cdn.com/v4/letter/c/34f0e0/32.png) [@coline](https://discuss.elastic.co/u/coline)\
**Post date:** [October 15, 2020, 9:07am UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/6 "2020-10-15T09:07:26Z")

</div>

Ok thanks for you answers, I will look into it!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2020, 9:07am UTC](https://discuss.elastic.co/t/filter-with-aggregate-value-in-query-dsl/251915/7 "2020-11-12T09:07:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
