# Nested aggregation on ctx.payload.hits

**URL:** <https://discuss.elastic.co/t/nested-aggregation-on-ctx-payload-hits/124584>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 19, 2018, 3:03pm UTC](https://discuss.elastic.co/t/nested-aggregation-on-ctx-payload-hits/124584 "2018-03-19T15:03:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![erickiersky](https://avatars.discourse-cdn.com/v4/letter/e/898d66/32.png) [@erickiersky](https://discuss.elastic.co/u/erickiersky)\
**Post date:** [March 19, 2018, 3:03pm UTC](https://discuss.elastic.co/t/nested-aggregation-on-ctx-payload-hits/124584/1 "2018-03-19T15:03:41Z")

</div>

Hello, Elastic Fans!

I am trying to use this example as a starting point:

The changes I am making are detecting a steep rise, not a drop. And for the input, I need to aggregate a bucket that is simply the average document count in the time spans. I suppose the total might work as well.

I am having trouble with:  
`"avg": { "field": "ctx.payload.hits" }`

which yields an error:  
"result": {  
"execution\_time": "2018-03-19T14:25:17.681Z",  
"execution\_duration": 1,  
"input": {  
"type": "search",  
"status": "failure",  
"reason": "UnknownNamedObjectException[Unknown BaseAggregationBuilder [avg\_errors]]"

How should I write this?  
Thank you!  
Eric

See the rest of the input section below.

```
  "input": {
    "search": {
      "request": {
        "indices": "logs-pmc-app-*",
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": {
                "range": {
                  "@timestamp": {
                      "from": "now-10m",
                      "to": "now"
                  }
                }
              }
            }
          },
          "aggs": {
            "five_min": {
              "filters": {
                "filters": {
                  "latest5": {
                    "range": {
                      "@timestamp": {
                          "gte": "now-5m",
                          "lte": "now"
                      }
                    }
                  },
                  "previous5": {
                    "range": {
                      "@timestamp": {
                          "gte": "now-10m",
                          "lte": "now-5m"
                      }
                    }
                  }
                }
              }
            },
            "aggs": {
              "avg_errors": {
                "avg": {
                  "field": "ctx.payload.hits"
                }
              }
            }
          }
        }
      }
    }
  },
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 21, 2018, 5:34pm UTC](https://discuss.elastic.co/t/nested-aggregation-on-ctx-payload-hits/124584/2 "2018-03-21T17:34:08Z")

</div>

I think your indentation is wrong (humans are not the worlds best JSON parsers...).

The `"aggs/avg_errors"` part needs to be within the `five_min` structure.

--Alex

---

<div class="post-metadata">

**Author:** ![erickiersky](https://avatars.discourse-cdn.com/v4/letter/e/898d66/32.png) [@erickiersky](https://discuss.elastic.co/u/erickiersky)\
**Post date:** [March 21, 2018, 5:57pm UTC](https://discuss.elastic.co/t/nested-aggregation-on-ctx-payload-hits/124584/3 "2018-03-21T17:57:45Z")

</div>

Thank you for the reply. The good news is I solved this a little earlier today using different techniques. I eliminated that `aggs/error` section, then used `docs_count` property references in the condition:

```
  "condition": {
    "script": {
      "source": "return ctx.payload.aggregations.five_min.buckets.latest5.doc_count > 2 * ctx.payload.aggregations.five_min.buckets.previous5.doc_count",
      "lang": "painless"
    }

```

I had to guess that that “doc\_count” property existed, after reading a lot of related material. I did not find detailed comprehensive documentation that explains how all of the this.that.other style references work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2018, 5:58pm UTC](https://discuss.elastic.co/t/nested-aggregation-on-ctx-payload-hits/124584/4 "2018-04-18T17:58:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
