# How to query by value in past bucket

**URL:** <https://discuss.elastic.co/t/how-to-query-by-value-in-past-bucket/263352>\
**Category:** Elasticsearch\
**Created:** [February 5, 2021, 8:45am UTC](https://discuss.elastic.co/t/how-to-query-by-value-in-past-bucket/263352 "2021-02-05T08:45:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![111439](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111439/32/83462_2.png) [@111439](https://discuss.elastic.co/u/111439)\
**Post date:** [February 5, 2021, 8:45am UTC](https://discuss.elastic.co/t/how-to-query-by-value-in-past-bucket/263352/1 "2021-02-05T08:45:32Z")

</div>

Hi, Im' Newbie of ELK Stack.  
I have question of elasticsearch REST API, I want to select data 2 time. First I use range (-20s to -140s) and aggregation term and bucket sort to find min value in this time.  
ex : 08.30 AM : [{A:30, B:35, C:40}]

And second I use range (-20s to -30 m) and i want to filter term aggregation where data in before bucket [{A:30, B:35, C:40}] How to use what aggs for this question  
**Thank You.**

> GET shc-\*/\_search  
> {  
> "aggs": {  
> "find\_min\_last\_1m": {  
> "range": {  
> "field": "@timestamp",  
> "ranges": [{  
> "from": "now-140s",  
> "to": "now-20s"  
> }]  
> },  
> "aggs": {  
> "process\_term": {  
> "terms": { "field": "pid.keyword", "size": 65},  
> "aggs": {  
> "sort\_min\_last\_1m": {  
> "bucket\_sort": {  
> "sort": [{ "\_count": { "order": "asc"}}],  
> "size": 3  
> }  
> }  
> }  
> }  
> }  
> },  
> "min": {  
> "range": {  
> "field": "@timestamp",  
> "ranges": [{  
> "from": "now-30m",  
> "to": "now-20s"  
> }]  
> },  
> "aggs": {  
> "time\_buckets": {  
> "date\_histogram": {  
> "field": "@timestamp",  
> "interval": "10m"  
> },  
> "aggs": {  
> "process\_filter": {  
> "filter": {  
> "terms": {  
> "pid.keyword": [  
> "shc:13370766",  
> "shc:13238406",  
> "shc:24314018"  
> ]  
> }  
> },  
> "aggs": {  
> "process\_term": {  
> "terms": {  
> "field": "pid.keyword"  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2021, 8:45am UTC](https://discuss.elastic.co/t/how-to-query-by-value-in-past-bucket/263352/2 "2021-03-05T08:45:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
