# Filtered Transform aggregations

**URL:** <https://discuss.elastic.co/t/filtered-transform-aggregations/233492>\
**Category:** Elasticsearch\
**Created:** [May 20, 2020, 8:41am UTC](https://discuss.elastic.co/t/filtered-transform-aggregations/233492 "2020-05-20T08:41:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [May 20, 2020, 8:41am UTC](https://discuss.elastic.co/t/filtered-transform-aggregations/233492/1 "2020-05-20T08:41:45Z")

</div>

We want to extract the first time an occurrence happened.

For now, we use a scripted metric, which works fine:

```auto
"creation": {
        "scripted_metric": {
          "init_script": "state.timestamps = []",
          "map_script": "if (doc.action.value == 'create') { state.timestamps.add(doc.timestamp.value.getMillis()) }",
          "combine_script": "return state.timestamps.length > 0 ? Collections.min(state.timestamps) : -1L",
          "reduce_script": "long first = 0; for (a in states) { if(!(a == -1L) && (a < first || first == 0)) { first = a } } return first"
        }
      }

```

But it looks like it would be nicer, and perform better, to combine min and filter agg, such as:

```auto
"creation": {
            "filter": { "term": { "action": "create" } },
            "aggs":{ "minValue": {"min": { "field": "timestamp" } }}
          }

```

However, I cannot seem to get it to work, I tried multiple combinations. Is it even possible?

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [May 20, 2020, 9:25am UTC](https://discuss.elastic.co/t/filtered-transform-aggregations/233492/2 "2020-05-20T09:25:14Z")

</div>

Transform only supports a subset of aggregations, we expand support with every release.

Support for `filter` has been added in `7.7` which should make your example possible.

Which version are you using? If you already use `7.7`, but still can not get it to work, can you post the error?

---

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [May 20, 2020, 9:37am UTC](https://discuss.elastic.co/t/filtered-transform-aggregations/233492/3 "2020-05-20T09:37:00Z")

</div>

We are using 7.6, another good reason for upgrading. Thanks!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 9:37am UTC](https://discuss.elastic.co/t/filtered-transform-aggregations/233492/4 "2020-06-17T09:37:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
