# Getting 400 "request does not support \[aggs\]" Error

**URL:** <https://discuss.elastic.co/t/getting-400-request-does-not-support-aggs-error/279253>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [July 21, 2021, 10:37am UTC](https://discuss.elastic.co/t/getting-400-request-does-not-support-aggs-error/279253 "2021-07-21T10:37:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![thejusjose-mindcurv](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@thejusjose-mindcurv](https://discuss.elastic.co/u/thejusjose-mindcurv)\
**Post date:** [July 21, 2021, 10:37am UTC](https://discuss.elastic.co/t/getting-400-request-does-not-support-aggs-error/279253/1 "2021-07-21T10:37:07Z")

</div>

Hi all,  
Getting a 400 Error while trying to fetch the total count of IP connecting to our system and then sort the IP list based on the top 5.

We have Kibana version 7.8 installed.

**Requirement ::**  
Get the list of top 5 IPs connecting to our system in the last 30 minutes.

**Command used** ::

```auto
curl -ks -u "user:password" -H 'Content-Type: application/json' -XGET 'https://<Elastic_IP>/logstash-yyyy.mm.dd/_count?pretty' -d '{
  "aggs": {
    "2": {
      "terms": {
        "field": "ap_client_ip.keyword",
        "order": {
          "_count": "desc"
        },
        "size": 5
      },
      "aggs": {
        "3": {
          "terms": {
            "field": "geoip.country_name.keyword",
            "order": {
              "_count": "desc"
            },
            "size": 5
          }
        }
      }
    }
  },
  "size": 0,
  "stored_fields": [
    "*"
  ],
  "script_fields": {},
  "docvalue_fields": [
    {
      "field": "@timestamp",
      "format": "date_time"
    },
    {
      "field": "event_timestamp",
      "format": "date_time"
    }
  ],
  "_source": {
    "excludes": []
  },
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "match_all": {}
        },
        {
          "bool": {
            "filter": [
              {
                "bool": {
                  "should": [
                    {
                      "match_phrase": {
                        "application": "apache"
                      }
                    }
                  ],
                  "minimum_should_match": 1
                }
              },
              {
                "bool": {
                  "should": [
                    {
                      "match_phrase": {
                        "environment": "PROD"
                      }
                    }
                  ],
                  "minimum_should_match": 1
                }
              }
            ]
          }
        },
        {
          "range": {
            "@timestamp": {
            "gt": "now-30m",
            "format": "strict_date_optional_time"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}'

```

**Output Received ::**

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "parsing_exception",
        "reason" : "request does not support [aggs]",
        "line" : 2,
        "col" : 3
      }
    ],
    "type" : "parsing_exception",
    "reason" : "request does not support [aggs]",
    "line" : 2,
    "col" : 3
  },
  "status" : 400
}

```

Can someone please have a check on the command used and advise ?

P.S. Checked the [doc](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-sum-bucket-aggregation.html) but cannot identify what is missing.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 21, 2021, 2:02pm UTC](https://discuss.elastic.co/t/getting-400-request-does-not-support-aggs-error/279253/2 "2021-07-21T14:02:29Z")

</div>

You are running a `_count` request, that is only used to count documents matching your query. if you want to use aggregations, use the `_search` endpoint.

---

<div class="post-metadata">

**Author:** ![thejusjose-mindcurv](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@thejusjose-mindcurv](https://discuss.elastic.co/u/thejusjose-mindcurv)\
**Post date:** [July 21, 2021, 5:47pm UTC](https://discuss.elastic.co/t/getting-400-request-does-not-support-aggs-error/279253/3 "2021-07-21T17:47:25Z")

</div>

Thanks @spinscale

It worked !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2021, 5:48pm UTC](https://discuss.elastic.co/t/getting-400-request-does-not-support-aggs-error/279253/4 "2021-08-18T17:48:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
