# Get Max Aggregate value for top N hits from elasticsearch

**URL:** <https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485>\
**Category:** Logstash\
**Tags:** aggregations\
**Created:** [July 3, 2024, 5:11pm UTC](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485 "2024-07-03T17:11:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Het\_Test](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/het_test/32/132982_2.png) [@Het\_Test](https://discuss.elastic.co/u/Het_Test)\
**Post date:** [July 3, 2024, 5:11pm UTC](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485/1 "2024-07-03T17:11:35Z")

</div>

Hey guys,  
I have an Elasticsearch field called `activity_time`, and I need to get the maximum `activity_time` from a subset of my data. For Ex, I want to get the max value of `activity_time` from the first 100 records when sorted in ascending order by `activity_time`.  
I am aware of the max aggregation query,

```auto
{
.....
  "max_activity_time":{
     "max":{
          "field":"activity_time"
      }
  }
}

```

However, I'm struggling to limit this to only the first 100 records. I read up about sampler aggregation but cannot seem to make it work, any assistance would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [July 3, 2024, 6:06pm UTC](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485/2 "2024-07-03T18:06:28Z")

</div>

Thanks, @Het_Test. Do you have an example of some queries that haven't worked? I would expect something like this to work for you here:

```auto
{
  "size": 0,
  "aggs": {
    "sample": {
      "sampler": {
        "shard_size": 100
      },
      "aggs": {
        "max_activity_time": {
          "max": {
            "field": "activity_time"
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Het\_Test](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/het_test/32/132982_2.png) [@Het\_Test](https://discuss.elastic.co/u/Het_Test)\
**Post date:** [July 4, 2024, 6:26am UTC](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485/3 "2024-07-04T06:26:09Z")

</div>

Hey,  
I was using the following example as reference,

[https://stackoverflow.com/questions/28896043/limit-elasticsearch-aggregation-to-top-n-query-results/35971531#35971531](https://limit-elasticsearch-aggregation-to-top-n-query-results)

I tried the solution you provided but it does not seem to get the top 100 in ascending order of activity time, would it be possible to do so?

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [July 5, 2024, 5:41pm UTC](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485/4 "2024-07-05T17:41:12Z")

</div>

Thanks for following up, @Het_Test. That may be because the sampler returns a random subset from the dataset. What about a multi-step query such as this one?

```auto
{
  "size": 0,
  "aggs": {
    "top_hits_sample": {
      "top_hits": {
        "size": 100,
        "sort": [
          {
            "activity_time": {
              "order": "asc"
            }
          }
        ]
      }
    },
    "max_activity_time_from_sample": {
      "max_bucket": {
        "buckets_path": "top_hits_sample>max_activity_time"
      }
    },
    "aggs": {
      "max_activity_time": {
        "max": {
          "field": "activity_time"
        }
      }
    }
  }
}

```
