# Return document for aggregation result

**URL:** <https://discuss.elastic.co/t/return-document-for-aggregation-result/85510>\
**Category:** Elasticsearch\
**Created:** [May 12, 2017, 7:21am UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510 "2017-05-12T07:21:52Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![animageofmine](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Post date:** [May 12, 2017, 7:21am UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/1 "2017-05-12T07:21:52Z")

</div>

Stupid question and might be easy for experts:

I want to perform max aggregation and want to get the corresponding document for the the result:

```
POST /sales/_search?&size=1
{
    "aggs" : {        
        "max_price" : {             
            "max" : {
                "field" : "price",             
            }        
        }
    }
}

```

Right now, the document returned is different that the one that has max price. If I want to return the document with max price, how can that be achieved?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 12, 2017, 7:44am UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/2 "2017-05-12T07:44:47Z")

</div>

You can get that if you [sort your search results.] ([https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html)) by price.

You have set the size to 1 already to retrieve one doc alongside your agg results so sorting should ensure it is the doc with the highest price.

---

<div class="post-metadata">

**Author:** ![animageofmine](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Post date:** [May 12, 2017, 1:59pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/3 "2017-05-12T13:59:16Z")

</div>

I thought about sorting, but isn't it an expensive operation since it uses more memory compared to max aggregation?

Isn't there a way to return the document with the above query?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 12, 2017, 2:06pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/4 "2017-05-12T14:06:19Z")

</div>

The max agg accesses the same doc-value lookup mechanism as the sorting logic does and for the same number of matching docs.

---

<div class="post-metadata">

**Author:** ![animageofmine](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Post date:** [May 12, 2017, 2:17pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/5 "2017-05-12T14:17:30Z")

</div>

Understood. Somehow I thought that elasticsearch keeps additional metadata for each shard like memsql does, especially for min/max values. Is there any documentation I can reference to understand the details of how max aggregation and/or sorting work internally? Would love to deep dive here.

Will use sorting then. Thanks for your quick reply and help, really appreciate it. Following is how query looks like with sort in case someone references the same question in future.

```
GET /bank/_search?&size=1
{
    "sort" : { "price" : {"order" : "desc"} }
}
```

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 12, 2017, 2:20pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/6 "2017-05-12T14:20:20Z")

</div>

> [@animageofmine](#):
>
> I thought that elasticsearch keeps additional metadata for each shard like memsql does, especially for min/max values.

Max agg is designed for use in a context which would prevent it from making use of any such pre-computed global max values - see [Very slow aggregation performance for trivial aggs - #2 by Mark\_Harwood](https://discuss.elastic.co/t/very-slow-aggregation-performance-for-trivial-aggs/24964/2)

---

<div class="post-metadata">

**Author:** ![animageofmine](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Post date:** [May 12, 2017, 2:30pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/7 "2017-05-12T14:30:28Z")

</div>

That makes sense.

I would argue a bit here though. Global min/max are only expected to be used for normal cases without additional filters and is a very common scenario. I am not saying that it is easy to implement(I come from storage background as well).

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 12, 2017, 2:34pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/8 "2017-05-12T14:34:38Z")

</div>

> [@animageofmine](#):
>
> Global min/max are only expected to be used for normal cases without additional filters and is a very common scenario

Row-level security is also a common requirement and any pre-aggregated values that go unfiltered in a store can represent a security risk. Each one of these values would need an "if security enabled do X, else do Y" safeguard adding around it.

---

<div class="post-metadata">

**Author:** ![animageofmine](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Post date:** [May 12, 2017, 2:39pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/9 "2017-05-12T14:39:02Z")

</div>

Fair enough. I have no idea why would pre-aggregated values require security, but then I don't deal with security, so pardon my knowledge in that domain.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 12, 2017, 2:43pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/10 "2017-05-12T14:43:36Z")

</div>

```
GET /bank/accounts/_search
{
	"aggs" : { 
		"any-oligarchs-hiding-here?" : {
			"max" : { "field":"balance"} 
		}
	}
}

```

🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2017, 2:51pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510/11 "2017-06-09T14:51:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
