# Scripted metric with agg field

**URL:** <https://discuss.elastic.co/t/scripted-metric-with-agg-field/130379>\
**Category:** Kibana\
**Created:** [May 3, 2018, 6:58am UTC](https://discuss.elastic.co/t/scripted-metric-with-agg-field/130379 "2018-05-03T06:58:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![1862347ba9566e72a47d](https://avatars.discourse-cdn.com/v4/letter/1/cdc98d/32.png) [@1862347ba9566e72a47d](https://discuss.elastic.co/u/1862347ba9566e72a47d)\
**Post date:** [May 3, 2018, 6:58am UTC](https://discuss.elastic.co/t/scripted-metric-with-agg-field/130379/1 "2018-05-03T06:58:52Z")

</div>

Is it possible to use scripted fields with aggregation of entities (min, max, top, etc)  
I need to find count of documents in which the value of one field is the maximum for the selected time filter.

---

<div class="post-metadata">

**Author:** ![a5a](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@a5a](https://discuss.elastic.co/u/a5a)\
**Post date:** [May 3, 2018, 3:34pm UTC](https://discuss.elastic.co/t/scripted-metric-with-agg-field/130379/2 "2018-05-03T15:34:12Z")

</div>

Hi Tatiana,

Unfortunately there isn't a way to do this in Kibana. By the way, scripted fields are only per document, rather than an aggregation.

Here's just an example of something that's possible, but it's not what you want. Just to illustrate:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eac1972937c0f90a7c646ed817cc67419c71fb5e.png)

**Explanation:** The data is some logstash-like data. Here the parent aggregation is a simple date-histogram. For every time-bucket, we do a sub-aggregation: a terms-aggregation on the `geo.dest` field. Concretely, this means it aggregates all the documents for each `geo.dest` value (China, USA, etc), and gives a `count` for each value. The `max bucket` aggregation keeps track of that sub-terms aggregation where the `count` is the highest.

Again, that doesn't solve your issue--you want to go a step further and find the count of documents with a particular max value. If you could do an aggregation to keep track of the max value, then do another request using that max value to filter documents with that, that would get you there. But it would require two requests at least to combine that data, as far as I know.

You _can_ solve this, but it doesn't involve Kibana. You could use one of the language clients for Elasticsearch and write a query that does runs an aggregation to get the max (for some time range), then filter on value = max and count those documents.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 3:34pm UTC](https://discuss.elastic.co/t/scripted-metric-with-agg-field/130379/3 "2018-05-31T15:34:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
