# How does elasticsearch return buckets when aggs by sum is used?

**URL:** <https://discuss.elastic.co/t/how-does-elasticsearch-return-buckets-when-aggs-by-sum-is-used/280740>\
**Category:** Elasticsearch\
**Created:** [August 8, 2021, 5:35pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-return-buckets-when-aggs-by-sum-is-used/280740 "2021-08-08T17:35:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chrisan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisan/32/12335_2.png) [@chrisan](https://discuss.elastic.co/u/chrisan)\
**Post date:** [August 8, 2021, 5:35pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-return-buckets-when-aggs-by-sum-is-used/280740/1 "2021-08-08T17:35:23Z")

</div>

> **[Terms aggregation | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html)**

> By default, the `terms` aggregation will return the buckets for the top ten terms ordered by the `doc_count` . One can change this default behaviour by setting the `size` parameter.

If I am doing a search like below, how can I know I get back the "largest" by sum?

For example, I am parsing Cloudfront logs to find bandwidth use by customer. The `index.html` might be the most frequent document but only amount to a gig or so while `my-large-movie.mp4` would be the largest by total sum but may have thousands less of records

```auto
# POST /_search
{
    "size": 0,
    "query": {
        "bool": {
            "must": [
                {
                    "range": {
                        "@timestamp": {
                            "gte": "2021-07-01T00:00:00.000",
                            "lt": "2021-08-01T00:00:00.000"
                        }
                    }
                },
                {
                    "match": {
                        "type": {
                            "query": "assets"
                        }
                    }
                }
            ]
        }
    },
    "aggs": {
        "by_url": {            
            "terms": {
                "field": "cs_uri_stem.keyword",
                "size" : 100
            },
            "aggs": {
                "total_bytes": {
                    "sum": {
                        "field": "sc_bytes"
                    }
                }
            }
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 9, 2021, 3:54pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-return-buckets-when-aggs-by-sum-is-used/280740/2 "2021-08-09T15:54:20Z")

</div>

See the [order parameter](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-order) in the terms aggregation docs and the example for _"Ordering the buckets by single value metrics sub-aggregation"_

---

<div class="post-metadata">

**Author:** ![chrisan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisan/32/12335_2.png) [@chrisan](https://discuss.elastic.co/u/chrisan)\
**Post date:** [August 9, 2021, 4:00pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-return-buckets-when-aggs-by-sum-is-used/280740/3 "2021-08-09T16:00:23Z")

</div>

wow, I am blind, right on the page I linked.

Thanks and sorry ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2021, 4:01pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-return-buckets-when-aggs-by-sum-is-used/280740/4 "2021-09-06T16:01:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
