# Filtering after MAX Aggregation

**URL:** <https://discuss.elastic.co/t/filtering-after-max-aggregation/41872>\
**Category:** Kibana\
**Created:** [February 16, 2016, 10:53am UTC](https://discuss.elastic.co/t/filtering-after-max-aggregation/41872 "2016-02-16T10:53:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![isaacpm](https://avatars.discourse-cdn.com/v4/letter/i/b9e5f3/32.png) [@isaacpm](https://discuss.elastic.co/u/isaacpm)\
**Post date:** [February 16, 2016, 10:53am UTC](https://discuss.elastic.co/t/filtering-after-max-aggregation/41872/1 "2016-02-16T10:53:04Z")

</div>

Hi,

I'm using ES+Kibana as timeseries and I'm trying to get a filter applied to the table visualization after the MAX aggregation has been applied.  
The problem is that all hosts will have a range of cpu metric values, so if you filter by cpu\<5 all hosts will have some entries there.  
So ideally I would need to get the max usage, then filter by \<5. In case I want to get all hosts that had less than 5% max cpu usage.

Getting the MAX is easy enough in Kibana, what I can't seem to get working is a filter applied to that MAX value.  
What would be the best way to get this filter for the MAX value?

Thanks,  
Isaac

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [February 19, 2016, 2:28pm UTC](https://discuss.elastic.co/t/filtering-after-max-aggregation/41872/3 "2016-02-19T14:28:40Z")

</div>

Could you post a screenshot from Visualize with your vis configuration expanded?

---

<div class="post-metadata">

**Author:** ![isaacpm](https://avatars.discourse-cdn.com/v4/letter/i/b9e5f3/32.png) [@isaacpm](https://discuss.elastic.co/u/isaacpm)\
**Post date:** [February 19, 2016, 3:13pm UTC](https://discuss.elastic.co/t/filtering-after-max-aggregation/41872/4 "2016-02-19T15:13:07Z")

</div>

I'm afraid is going to be a bit difficult to expand the visualization completely and screenshot it, it has 43 filters. It would take me many screenshots.  
I think I found what I need:  
[https://www.elastic.co/guide/en/elasticsearch/reference/master/search-aggregations-pipeline-bucket-selector-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-aggregations-pipeline-bucket-selector-aggregation.html)

But I can't try yet because I can restart the cluster to apply the allowing scripts change at the moment.  
Will post back if it worked (or if I need help with adding the custom json, which seems likely by my previous attempts)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:01pm UTC](https://discuss.elastic.co/t/filtering-after-max-aggregation/41872/5 "2017-07-06T14:01:38Z")

</div>


