# Histogram in reverse nested

**URL:** <https://discuss.elastic.co/t/histogram-in-reverse-nested/209048>\
**Category:** Elasticsearch\
**Created:** [November 22, 2019, 11:06am UTC](https://discuss.elastic.co/t/histogram-in-reverse-nested/209048 "2019-11-22T11:06:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yamuna\_Mallikarjun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yamuna_mallikarjun/32/46913_2.png) [@Yamuna\_Mallikarjun](https://discuss.elastic.co/u/Yamuna_Mallikarjun)\
**Post date:** [November 22, 2019, 11:06am UTC](https://discuss.elastic.co/t/histogram-in-reverse-nested/209048/1 "2019-11-22T11:06:40Z")

</div>

Data format:

Basically i want to do the aggregation with histogram for 4 minutes.

1. The pattern was:

1st min send 2 requests from each port  
2nd min send 3 requests from each port  
3rd min send 4 requests from each port  
4th min send 5 requests from each port

 ![31%20PM](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd20733a82c473a5f1bf4a40c4f9e659222aefbf.png)

```
{
..........
"aggregations": {
"clientPorttopKByCount.key": {
  "nested": {
    "path": "clientPorttopKByCount"
  },
  "aggregations": {
    "orders": {
      "terms": {
        "field": "clientPorttopKByCount.key",
        "size": 5000,
        "min_doc_count": 1,
        "shard_min_doc_count": 0,
        "show_term_doc_count_error": false,
        "order": [
          {
            "_count": "desc"
          },
          {
            "_key": "asc"
          }
        ]
       },    
    "aggregations": {
        "records": {
          "reverse_nested": {
            
          },
          "aggregations": {
            "histogram": {
              "histogram": {
                "field": "timestamp",
                "interval": 60000.0,
                "offset": 0.0,
                "order": {
                  "_key": "asc"
                },
                "keyed": false,
                "min_doc_count": 0
              },
              "aggregations": {
                "clientPorttopKByCount.key": {
                  "nested": {
                    "path": "clientPorttopKByCount"
                  },
                  "aggregations": {
                    "clientPorttopKByCount.value_sum": {
                      "sum": {
                        "field": "clientPorttopKByCount.value"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}

```

}  
}

and the response is :

 ![49%20PM](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4179bebcab6fb0e0a56b9ddee2ac9025aec6db8.png)

Expected is:

 ![52%20PM](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d88f044c734c8378fb324352d7bb7e3ea1af11a.png)

Problem is, it is summing all the ports value to the each minute.

Please help me to solve this.

---

<div class="post-metadata">

**Author:** ![Yamuna\_Mallikarjun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yamuna_mallikarjun/32/46913_2.png) [@Yamuna\_Mallikarjun](https://discuss.elastic.co/u/Yamuna_Mallikarjun)\
**Post date:** [November 24, 2019, 12:25pm UTC](https://discuss.elastic.co/t/histogram-in-reverse-nested/209048/2 "2019-11-24T12:25:18Z")

</div>

Request is:

```
   {
    ..................
  "aggregations": {
  "clientPorttopKByCount.key": {
  "nested": {
    "path": "clientPorttopKByCount"
  },
  "aggregations": {
    "orders": {
      "terms": {
        "field": "clientPorttopKByCount.key",
        "size": 5000,
        "min_doc_count": 1,
        "shard_min_doc_count": 0,
        "show_term_doc_count_error": false,
        "order": [
          {
            "_count": "desc"
          },
          {
            "_key": "asc"
          }
        ]
      },
      "aggregations": {
        "records": {
          "reverse_nested": {
            
          },
          "aggregations": {
            "histogram": {
              "histogram": {
                "field": "timestamp",
                "interval": 60000.0,
                "offset": 0.0,
                "order": {
                  "_key": "asc"
                },
                "keyed": false,
                "min_doc_count": 0
              },
              "aggregations": {
                "clientPorttopKByCount.key": {
                  "nested": {
                    "path": "clientPorttopKByCount"
                  },
                  "aggregations": {
                    "clientPorttopKByCount.value_sum": {
                      "sum": {
                        "field": "clientPorttopKByCount.value"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}
}
.......
} 

```

Can some please guide me, I am blocked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2019, 12:25pm UTC](https://discuss.elastic.co/t/histogram-in-reverse-nested/209048/3 "2019-12-22T12:25:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
