# How to compare sum aggregation value with a numeric data constant

**URL:** <https://discuss.elastic.co/t/how-to-compare-sum-aggregation-value-with-a-numeric-data-constant/359441>\
**Category:** Elastic Search\
**Created:** [May 14, 2024, 8:45am UTC](https://discuss.elastic.co/t/how-to-compare-sum-aggregation-value-with-a-numeric-data-constant/359441 "2024-05-14T08:45:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Borja](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@Borja](https://discuss.elastic.co/u/Borja)\
**Post date:** [May 14, 2024, 8:45am UTC](https://discuss.elastic.co/t/how-to-compare-sum-aggregation-value-with-a-numeric-data-constant/359441/1 "2024-05-14T08:45:58Z")

</div>

Hi all,

First of all, sorry if my question is too simple but I'm relatively new to elastic.

I have to create a new rule in Kibana that checks every hour if the sum of the 'records' field of the documents in the index for a specific transaction (transaction H7A0) is greater than 150000. If the value is greater than that it should jump the rule to send an email.

I have created this query in devtools:

```auto
GET jdbc-db2-transaction-cpu-*/_search
{
  "size": 0,
     "query": {
         "bool": {
            "must": [
              {
                "terms": {
                  "transaction_id.keyword": ["H7A0"]
                }
              }
            ],
            "filter": [
                {
                  "range": {
                    "fecha": {
                      "gte": "now-60m"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
             "transaction": {
             "terms": {
                "field": "transaction_id.keyword"
             },
               "aggs": {
               "sum_H7A0_records": {
                   "sum": {
                   "field": "records"
                   }
                }
               }
             }
		   }
}

```

And if I executed it I see I get the correct value in sum\_H7A0\_records field (in this case 211598

```auto
{
  "took": 253,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 6,
      "relation": "eq"
    },
    "max_score": null,
    "hits": []
  },
  "aggregations": {
    "transaction": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "H7A0",
          "doc_count": 6,
          "sum_H7A0_records": {
            "value": 211598
          }
        }
      ]
    }
  }
}

```

How can I do it so that in this case, for example, the rule returns 1 hit (not the 6 it returns) since the value is greater than 150000 and no hits if it's below 150000?

best regards

Borja

---

<div class="post-metadata">

**Author:** ![demjened](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/demjened/32/109159_2.png) [@demjened](https://discuss.elastic.co/u/demjened)\
**Post date:** [May 14, 2024, 1:22pm UTC](https://discuss.elastic.co/t/how-to-compare-sum-aggregation-value-with-a-numeric-data-constant/359441/2 "2024-05-14T13:22:13Z")

</div>

Hi Borja, and welcome to the community 👋 !

Try a [bucket selector aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-bucket-selector-aggregation.html) that filters the sum\_H7A0\_records bucket if the sum value is less than 150K:

```json
...
       "sum_H7A0_records": {
          "sum": {
            "field": "records"
          }
        },
        "sum_records_gt_150k": {
          "bucket_selector": {
            "buckets_path": {
              "sumRecords": "sum_H7A0_records"
            },
            "script": "params.sumRecords > 150000"
          }
        }

```

Hope this helps!

---

<div class="post-metadata">

**Author:** ![Borja](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@Borja](https://discuss.elastic.co/u/Borja)\
**Post date:** [June 5, 2024, 3:17pm UTC](https://discuss.elastic.co/t/how-to-compare-sum-aggregation-value-with-a-numeric-data-constant/359441/3 "2024-06-05T15:17:36Z")

</div>

Hi Demjened,

it worked. thank you very much.

regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2024, 3:17pm UTC](https://discuss.elastic.co/t/how-to-compare-sum-aggregation-value-with-a-numeric-data-constant/359441/4 "2024-07-03T15:17:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
