# In query using aggregation but response null\_pointer\_exception

**URL:** <https://discuss.elastic.co/t/in-query-using-aggregation-but-response-null-pointer-exception/122998>\
**Category:** Elasticsearch\
**Created:** [March 8, 2018, 4:22am UTC](https://discuss.elastic.co/t/in-query-using-aggregation-but-response-null-pointer-exception/122998 "2018-03-08T04:22:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Edson\_Hsu](https://avatars.discourse-cdn.com/v4/letter/e/85e7bf/32.png) [@Edson\_Hsu](https://discuss.elastic.co/u/Edson_Hsu)\
**Post date:** [March 8, 2018, 4:22am UTC](https://discuss.elastic.co/t/in-query-using-aggregation-but-response-null-pointer-exception/122998/1 "2018-03-08T04:22:35Z")

</div>

Hi all

I'm testing ES aggregation function , currently I use snmp polling as source date

Device : forti 100D

Here is my query:

{  
"size": 0,  
"query": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "1520471015615",  
"lte": "1520472815615",  
"format": "epoch\_millis"  
}  
}  
},  
{  
"query\_string": {  
"analyze\_wildcard": true,  
"query": "type\_instance: "ae0.1" AND collectd\_type: "forti\_in""  
}  
}  
]  
}  
},  
"aggs": {  
"2": {  
"date\_histogram": {  
"interval": "15s",  
"field": "@timestamp",  
"min\_doc\_count": 0,  
"format": "epoch\_millis"  
},  
"aggs": {  
"1": {  
"avg": {  
"field": "value"  
}  
},  
"3": {  
"derivative": {  
"buckets\_path": "1"  
}  
}  
}  
}  
}  
}

Cause the raw data is counter type , so I need use derivative to get speed,  
then I want to query when speed is over some value.

here is the result  
{  
"error": {  
"root\_cause": [],  
"type": "search\_phase\_execution\_exception",  
"reason": "",  
"phase": "fetch",  
"grouped": true,  
"failed\_shards": [],  
"caused\_by": {  
"type": "script\_exception",  
"reason": "runtime error",  
"script\_stack": [  
"params.final \> 100000",  
" ^---- HERE"  
],  
"script": "params.final \> 100000",  
"lang": "painless",  
"caused\_by": {  
"type": "null\_pointer\_exception",  
"reason": null  
}  
}  
},  
"status": 503  
}

I think the reason is the first derivative value was null , so is there anyway to fix this? or other better solution ? thanks!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2018, 4:22am UTC](https://discuss.elastic.co/t/in-query-using-aggregation-but-response-null-pointer-exception/122998/2 "2018-04-05T04:22:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
