# How can I view ALL buckets in aggregations?

**URL:** <https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303>\
**Category:** Elasticsearch\
**Created:** [January 5, 2018, 4:00pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303 "2018-01-05T16:00:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [January 5, 2018, 4:00pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/1 "2018-01-05T16:00:30Z")

</div>

For example, I have an aggregation of IP addresses and want to see the counts of them. However, I realized that it only shows however many you set `show` to. I need a list of every IP address and the total counts of each, but can't seem to find how to get it to include every IP address bucket. Am I going about this wrong?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 5, 2018, 4:47pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/2 "2018-01-05T16:47:35Z")

</div>

Two options for high cardinality values like IP address that are too big to handle in one request:

1. Use the terms aggregation repeatedly for different [partitions](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_filtering_values_with_partitions)
2. Use the[composite aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-composite-aggregation.html) repeatedly with the `after` parameter

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [January 5, 2018, 5:18pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/3 "2018-01-05T17:18:40Z")

</div>

Okay, I'm trying #1 and am wondering if there is a way for this to be set dynamically. We might get drastically varying numbers of IP addresses, so could the request just take the value of whatever the cardinality is and set the number of partitions and size based on that?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 5, 2018, 5:23pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/4 "2018-01-05T17:23:21Z")

</div>

No - it's up to your client app to figure out the right number of partitions as per the linked doc using the `cardinality` agg.  
The "right number of partitions" could vary wildly depending on the type of request e.g. if you were planning on nesting a date histogram under each IP to get a day-by-day summary of its activity.

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [January 5, 2018, 5:24pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/5 "2018-01-05T17:24:50Z")

</div>

Also, from reading the docs on the `cardinality` agg:

> Computing exact counts requires loading values into a hash set and returning its size. This doesn’t scale when working on high-cardinality sets and/or large values as the required memory usage and the need to communicate those per-shard sets between nodes would utilize too many resources of the cluster.

So that number won't be accurate for IP addresses since they're high cardinality?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 5, 2018, 5:26pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/6 "2018-01-05T17:26:47Z")

</div>

> [@arisbanach](#):
>
> So that number won't be accurate

More than likely good enough for figuring out how many partitions you'll need though.

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [January 5, 2018, 5:28pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/7 "2018-01-05T17:28:39Z")

</div>

I'm just getting started learning scripted fields and Painless. Is there a way to programmatically do this using Painless in a query?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 5, 2018, 5:29pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/8 "2018-01-05T17:29:58Z")

</div>

> [@arisbanach](#):
>
> Is there a way to programmatically do this using Painless in a query?

Sorry, no.  
This is logic outside of elasticsearch you'll need to figure out how many queries to run

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [January 5, 2018, 5:30pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/9 "2018-01-05T17:30:10Z")

</div>

Okay, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2018, 5:30pm UTC](https://discuss.elastic.co/t/how-can-i-view-all-buckets-in-aggregations/114303/10 "2018-02-02T17:30:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
