# Nested Aggregation in a Transforms Script

**URL:** <https://discuss.elastic.co/t/nested-aggregation-in-a-transforms-script/125068>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 21, 2018, 7:42pm UTC](https://discuss.elastic.co/t/nested-aggregation-in-a-transforms-script/125068 "2018-03-21T19:42:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yodasec](https://avatars.discourse-cdn.com/v4/letter/y/e5b9ba/32.png) [@yodasec](https://discuss.elastic.co/u/yodasec)\
**Post date:** [March 21, 2018, 7:42pm UTC](https://discuss.elastic.co/t/nested-aggregation-in-a-transforms-script/125068/1 "2018-03-21T19:42:10Z")

</div>

I am trying to apply a filter in a Transform Script and map the results to a new list. I am able to successfully do this when only using 1 aggregation. However, I am not having any luck using a second aggregation that exists inside the first one. The specific part of the script that isn't working is when I try to map values to new fields. Are there any examples of how to apply filters in a watcher that is using multiple aggregations ?

```
"transform": {
    "script": {
      "source": "ctx.payload.aggregations.image_agg.buckets.stream().filter(a -> a.parentimage_agg.buckets.stream().filter(b -> b.doc_count > ctx.metadata.condition_count)).map(b -> ['image':b.key,'count':b.doc_count]).collect(Collectors.toList());",
      "lang": "painless"
    }
  }

```

I am also including a snippet of the result output. Ultimately, I am trying to alert only on specific events using doc\_count in parentimage\_agg.buckets and want to map that doc\_count to a list, as well as the key from both aggregations.

```
"aggregations": {
          "image_agg": {
            "doc_count_error_upper_bound": 39,
            "sum_other_doc_count": 1882,
            "buckets": [
              {
                "doc_count": 12830,
                "parentimage_agg": {
                  "doc_count_error_upper_bound": 0,
                  "sum_other_doc_count": 0,
                  "buckets": [
                    {
                      "doc_count": 12830,
                      "key": "C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe"
                    }
                  ]
                },
                "key": "C:\\Windows\\System32\\wbem\\WMIC.exe"
              }
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 23, 2018, 12:13pm UTC](https://discuss.elastic.co/t/nested-aggregation-in-a-transforms-script/125068/2 "2018-03-23T12:13:12Z")

</div>

if you want to access the `doc_count` and `key` fields **inside** of the `parentimage_agg` aggregation, you have to loop through all the buckets a second time inside of your `map` statement and then decide what you want to do with the data, if there are two buckets with the same keys

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2018, 12:13pm UTC](https://discuss.elastic.co/t/nested-aggregation-in-a-transforms-script/125068/3 "2018-04-20T12:13:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
