# How to pass the aggs top 1 value to the query

**URL:** https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496
**Category:** Elastic Observability
**Tags:** elastic-stack-alerting
**Created:** [April 6, 2023, 9:06am UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496 "2023-04-06T09:06:47Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![vrviji](https://avatars.discourse-cdn.com/v4/letter/v/9dc877/32.png) [@vrviji](https://discuss.elastic.co/u/vrviji)
#### Post date: [April 6, 2023, 9:06am UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/1 "2023-04-06T09:06:47Z")

</div>

I am trying to create an alert using ElasticDSL 7.17 query. I need to filter the documents based on certain condition and group the documents on a field and get the top first group. My query should match only the top grouped value. The below query matches only the filter criteria and i want to filter further with the top grouping name . SO i need to pass the aggs top field to the query somehow. Is it possible. Pls help.

```auto
{
  "size": 0,
  "aggregations": {
    "my_agg": {
      "filter": {
        "bool": {
          "must": [
            { "term": { "service.name": "inputservicename" }},
            { "term": { "grouping_key": "inputkey" }}
          ]
        }
      },
      "aggs": {
        "top_my_field": {
          "terms": {
            "field": "grouping_name",
            "size": 1
          }
        }
      }
    }

  },
  "query": {
    "bool": {
      "must": [
        { "match_phrase": { "service.name": "inputservicename" }},
        { "match_phrase": { "grouping_key": "inputkey" }}
      ]
    }
  }
}

```

---

<div class="post-metadata">

### Author: ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)
#### Post date: [April 6, 2023, 12:22pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/2 "2023-04-06T12:22:44Z")

</div>

You can do a [`top_hits` aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/search-aggregations-metrics-top-hits-aggregation.html) and use the `sort` option to sort by whatever field makes that the "top one".

---

<div class="post-metadata">

### Author: ![vrviji](https://avatars.discourse-cdn.com/v4/letter/v/9dc877/32.png) [@vrviji](https://discuss.elastic.co/u/vrviji)
#### Post date: [April 6, 2023, 1:37pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/3 "2023-04-06T13:37:57Z")

</div>

With the existing query, I am able to fetch the top first grouping name. I want to include this top grouping name in the query part so that the number of matched documents will be further more reduced. If i don't pass the top grouping name to the query part, the documents is just filtered by servicename and key. Instead i want to filter by service name ,key and the top value of grouping name. I am concerned on the number of matching documents because i am creating an alert if the number of matching documents \> 10 ( for Ex).

---

<div class="post-metadata">

### Author: ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)
#### Post date: [April 6, 2023, 2:46pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/4 "2023-04-06T14:46:35Z")

</div>

It's not clear to me, are you using the elasticsearch query rule type? [Elasticsearch query | Kibana Guide [8.7] | Elastic](https://www.elastic.co/guide/en/kibana/8.7/rule-type-es-query.html)

You mentioned 7.x, the doc above is for 8.7. There are some additional features in 8.7, including grouping, which does a top-level agg. It may fit your needs.

Also note that in 7.x, the only top-level fields we use in the DSL are `query` - So `aggregations` should be completely ignored when the rule runs. In 8.7, we also allow `fields`, `_source` and `runtime_mappings`, to fine-tune the query a bit more, and control what is output for fields.

---

<div class="post-metadata">

### Author: ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)
#### Post date: [April 6, 2023, 2:47pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/5 "2023-04-06T14:47:41Z")

</div>

Patrick is correct - if you truly require the use of aggregations, you'll need to use Watcher, not Kibana Alerts.

---

<div class="post-metadata">

### Author: ![vrviji](https://avatars.discourse-cdn.com/v4/letter/v/9dc877/32.png) [@vrviji](https://discuss.elastic.co/u/vrviji)
#### Post date: [April 6, 2023, 4:37pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/6 "2023-04-06T16:37:59Z")

</div>

Thank you so much! Yes that's the issue am facing, aggs are ignored while rule runs. Thanks for making it clear, that it is how 7.17 behaves.

---

<div class="post-metadata">

### Author: ![vrviji](https://avatars.discourse-cdn.com/v4/letter/v/9dc877/32.png) [@vrviji](https://discuss.elastic.co/u/vrviji)
#### Post date: [April 6, 2023, 4:38pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496/7 "2023-04-06T16:38:35Z")

</div>

Thanks for the suggestion! Will try to use watcher instead.
