# How to apply a histogram aggregation from the set of doc\_counts from a previous aggregation?

**URL:** <https://discuss.elastic.co/t/how-to-apply-a-histogram-aggregation-from-the-set-of-doc-counts-from-a-previous-aggregation/250883>\
**Category:** Elasticsearch\
**Created:** [October 3, 2020, 11:16pm UTC](https://discuss.elastic.co/t/how-to-apply-a-histogram-aggregation-from-the-set-of-doc-counts-from-a-previous-aggregation/250883 "2020-10-03T23:16:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pushshift](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pushshift/32/50408_2.png) [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Post date:** [October 3, 2020, 11:16pm UTC](https://discuss.elastic.co/t/how-to-apply-a-histogram-aggregation-from-the-set-of-doc-counts-from-a-previous-aggregation/250883/1 "2020-10-03T23:16:32Z")

</div>

I ran a terms aggregation and got back a bunch of buckets with keys and doc\_counts. I want to treat the doc\_counts from all the buckets returned as the input for a histogram aggregation (treat the doc\_counts as a set). This is for analysis of API logs to determine how many different clients (IP addresses) use the API on a daily basis. So I would like to end up with data that would tell me 800 clients make 0-100 hits, 900 clients make 100-200 hits, etc.

How can this be accomplished? Would this be a sub-aggregation? Pipeline? Nested?

TL;DR: How to apply a histogram aggregation from the results of a terms aggregation (using the doc\_counts as a set for input into the histogram aggregation.

Thank you!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 5, 2020, 9:25am UTC](https://discuss.elastic.co/t/how-to-apply-a-histogram-aggregation-from-the-set-of-doc-counts-from-a-previous-aggregation/250883/2 "2020-10-05T09:25:08Z")

</div>

Hey,

from my first read, I would guess this is a `histogram` aggregation within the `terms` aggregation. The histogram agg, then works on all the documents that are part of the terms agg bucket - which I think is what you are after, correct?

--Alex

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [October 5, 2020, 9:26am UTC](https://discuss.elastic.co/t/how-to-apply-a-histogram-aggregation-from-the-set-of-doc-counts-from-a-previous-aggregation/250883/3 "2020-10-05T09:26:54Z")

</div>

> [@pushshift](#):
>
> analysis of API logs to determine how many different clients (IP addresses) use the API on a daily basis.

Sounds like this would be the `cardinality` agg on the IP underneath the histogram so :

```
GET my_index/_search
{
  "size":0,
  "aggs": {
	"days": {
	  "date_histogram": {
		"field": "date",
		"interval": "day"
	  },
	  "aggs":{
		"daily users":{
		  "cardinality": {
			"field": "IP"
		  }
		}
	  }
	}
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2020, 9:27am UTC](https://discuss.elastic.co/t/how-to-apply-a-histogram-aggregation-from-the-set-of-doc-counts-from-a-previous-aggregation/250883/4 "2020-11-02T09:27:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
