# Invalid term order aggregation path

**URL:** <https://discuss.elastic.co/t/invalid-term-order-aggregation-path/104536>\
**Category:** Elasticsearch\
**Created:** [October 19, 2017, 10:13am UTC](https://discuss.elastic.co/t/invalid-term-order-aggregation-path/104536 "2017-10-19T10:13:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SJLG](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@SJLG](https://discuss.elastic.co/u/SJLG)\
**Post date:** [October 19, 2017, 10:13am UTC](https://discuss.elastic.co/t/invalid-term-order-aggregation-path/104536/1 "2017-10-19T10:13:21Z")

</div>

Hi

In our software we use the following terms aggregation to group the records by the field sGroup. Each record has a timestamp lTsRequest, which we use to retrieve the most recent / latest values of some other field for each group.

```
POST /myFancyIndex/_search?size=0
{
  "aggs": {
    "group": {
      "terms": {
        "field": "sGroup.keyword"
      },
      "aggs": {
        "most_recent_status": {
          "terms": {
            "field": "iStatus",
            "size" : 1
          },
          "aggs": {
            "most_recent_timestamp": {
              "top_hits": {
                "size": 1,
                "sort": [
                  {
                    "myTimestamp": {
                      "order": "desc"
                    }
                  }
                ]
              }
            }
          }
        }
      }
    }
  }
}

```

This works like a charm. Now we wish to order the results by their most recent status, which we implemented using

```
"order" : {
   "most_recent_status > most_recent_timestamp" : "desc"
}

```

defined in the group aggregation. ES reponds with

_Invalid terms aggregation order path [most\_recent\_status\>most\_recent\_timestamp]. Terms buckets can only be sorted on a sub-aggregator path that is built out of zero or more single-bucket aggregations within the path and a final single-bucket or a metrics aggregation at the path end. Sub-path [most\_recent\_status] points to non single-bucket aggregation_

Why does this happen? Each aggregation on the path returns at most one bucket.

I appreciate your help and thank you in advance.

Cheers  
Simon

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [October 27, 2017, 3:30pm UTC](https://discuss.elastic.co/t/invalid-term-order-aggregation-path/104536/2 "2017-10-27T15:30:14Z")

</div>

> [@SJLG](#):
>
> Why does this happen? Each aggregation on the path returns at most one bucket.

Yeah, that error is a bit confusing because it's using terms that are internal to ES. Inside Elasticsearch, there are multi-bucket aggs like `terms`, `date_histo`, etc which return multiple buckets. And there are single-bucket aggs, like `filter` which always return a single bucket.

The error message is referring to that; the type of agg, not necessarily how many buckets are actually being returned based on your `size` param.

We could probably improve the code to allow pathing into multi-bucket aggs when they only return one bucket due to an explicit `size`, but today it doesn't have that capability.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2017, 3:30pm UTC](https://discuss.elastic.co/t/invalid-term-order-aggregation-path/104536/3 "2017-11-24T15:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
