# Kibana work with two aggregation

**URL:** <https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557>\
**Category:** Kibana\
**Created:** [March 29, 2019, 3:17pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557 "2019-03-29T15:17:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcos\_Belarmino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_belarmino/32/40447_2.png) [@Marcos\_Belarmino](https://discuss.elastic.co/u/Marcos_Belarmino)\
**Post date:** [March 29, 2019, 3:17pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557/1 "2019-03-29T15:17:16Z")

</div>

Hi,  
I'm trying to create using kibana visualizations with two buckets to produce an aggregated results, that i need apply factors and sum both.  
Use case: dedicated an shared (like building)  
My documents at Elasticsearch  
doc 1: { '\_id': 1, 'cost': 10, 'Department': 'SALES', '\_type': 'cost' }  
doc 2: { '\_id': 2, 'cost': 50, 'Building': 'MyTower', '\_type': 'cost' }  
doc 3: { '\_id': 3, 'cost': 10, 'Department': 'SALES', '\_type': 'cost' }  
doc 4: { '\_id': 4, 'cost': 30, 'Building': 'MyTower', '\_type': 'cost' }

My attempts:  
1 - Use two buckets.  
- Create first Sum bucket aggregated by term filed Department  
- Create second sum bucket aggregation by term field Builid  
I was not able to use script to sum both aggregation results.

2 - Simple sum metric and create bucket using filters.  
Restriction here was access the filtered result in script field.

3 - Create script field to calculate:  
documents that has Department.keyword value = SALES and sum with documents that has Build.keyword value

My impression is the usage of scripted fields seems to be fit more here but can someone guide to samples regarding script fields?

Thanks for any assistance

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 29, 2019, 9:38pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557/2 "2019-03-29T21:38:03Z")

</div>

Hi, if I'm understanding this correctly, it sounds like it will work to have 2 filtered buckets at the top-level, plus 1 unfiltered bucket.

I'm working through this making an aggregated data table visualization:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/6/969eed248579396552ce3e7827ae9b5995edcd07.png)

The metric there is doc count. If you want it to be `sum` of something, you can add another metric:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d96ac5d9f2b0422a2b00d5f5063ecbb99f43bdc.png)

I think this is a little bit what you were trying?

---

<div class="post-metadata">

**Author:** ![Marcos\_Belarmino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_belarmino/32/40447_2.png) [@Marcos\_Belarmino](https://discuss.elastic.co/u/Marcos_Belarmino)\
**Post date:** [March 29, 2019, 11:59pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557/3 "2019-03-29T23:59:02Z")

</div>

Hi Tim,  
Thanks a lot. for the time and attention.  
My objective work with sum metric. Filter two terms.  
The first one is an dedicated cost the second tem "Bulding field" is a shared resource.  
The idea is represent a single cost for sales  
sum(department filter value) + ((Bulding filter value)\*0.5)  
My limitation is how to sum both results. (Sales: 60)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/534506e4ac4bfe9b7b26f2a2abe35a46a01022e5.png)

---

<div class="post-metadata">

**Author:** ![Marcos\_Belarmino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_belarmino/32/40447_2.png) [@Marcos\_Belarmino](https://discuss.elastic.co/u/Marcos_Belarmino)\
**Post date:** [April 2, 2019, 10:16pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557/4 "2019-04-02T22:16:14Z")

</div>

There is any way to display filter label Shared res + filter label Department as an single result ?

---

<div class="post-metadata">

**Author:** ![Marcos\_Belarmino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_belarmino/32/40447_2.png) [@Marcos\_Belarmino](https://discuss.elastic.co/u/Marcos_Belarmino)\
**Post date:** [April 4, 2019, 2:52pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557/5 "2019-04-04T14:52:30Z")

</div>

Hi I've found an alternative. If the buckets we change from terms to filters and create filters to match the exact condition worked.  
The only impact that I have is how to access filter values using the advanced, and add a json file to create an painless function.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2019, 2:52pm UTC](https://discuss.elastic.co/t/kibana-work-with-two-aggregation/174557/6 "2019-05-02T14:52:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
