# How to perform sum aggregation and term aggregation in single query?

**URL:** <https://discuss.elastic.co/t/how-to-perform-sum-aggregation-and-term-aggregation-in-single-query/298151>\
**Category:** Elasticsearch\
**Created:** [February 24, 2022, 11:09am UTC](https://discuss.elastic.co/t/how-to-perform-sum-aggregation-and-term-aggregation-in-single-query/298151 "2022-02-24T11:09:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Harish\_fragger](https://avatars.discourse-cdn.com/v4/letter/h/edb3f5/32.png) [@Harish\_fragger](https://discuss.elastic.co/u/Harish_fragger)\
**Post date:** [February 24, 2022, 11:09am UTC](https://discuss.elastic.co/t/how-to-perform-sum-aggregation-and-term-aggregation-in-single-query/298151/1 "2022-02-24T11:09:23Z")

</div>

I want to know if there is a method to write a query that can get the sum of a field value and such type of fields top 10 occurrences. For example, if I have 20 IP address in 100 documents and each document also tells me the amount of bytes sent and received by that IP at a point of time.

> { 'ip' : "192.168.0.1",  
> "sentbytes" : "20",  
> "receivebytes" : "10",  
> },  
> { 'ip' : "183.19.22.15",  
> "sentbytes" : "20",  
> "receivebytes" : "10",  
> },  
> and so on

Is there a concept where I will get the top 10 IP's that have shared the maximum amount of send bytes and IP's that have max. receive bytes.

I know that Term aggregation will give me top 10 occurrences of IP and sum will sum up the IP's but I want to kind of merge these 2 functionalities.

Example output:  
{ 'ip' : "192.168.0.1",  
"sentbytes" : "100",  
"receivebytes" : 200,  
}  
{ 'ip' : "183.19.22.15",  
"sentbytes" : "20",  
"receivebytes" : "10",  
}

NOTE: My sentBytes and receivebytes are of type KEYWORD

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 24, 2022, 3:52pm UTC](https://discuss.elastic.co/t/how-to-perform-sum-aggregation-and-term-aggregation-in-single-query/298151/2 "2022-02-24T15:52:44Z")

</div>

Just to be sure, we're talking about the same thing, maybe provide a small example and expected result.

First, you can have a `terms` aggregation and then within each term (which is an IP) you could have a sum aggregation.

Second, if you want to do math operations like summing values up, your field types **MUST** be numbers and not keywords.

Hope this helps as a start.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2022, 3:53pm UTC](https://discuss.elastic.co/t/how-to-perform-sum-aggregation-and-term-aggregation-in-single-query/298151/3 "2022-03-24T15:53:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
