# Scripted metrics aggregation based on complicated terms buckets as an entry data

**URL:** <https://discuss.elastic.co/t/scripted-metrics-aggregation-based-on-complicated-terms-buckets-as-an-entry-data/64469>\
**Category:** Elasticsearch\
**Created:** [October 31, 2016, 5:15pm UTC](https://discuss.elastic.co/t/scripted-metrics-aggregation-based-on-complicated-terms-buckets-as-an-entry-data/64469 "2016-10-31T17:15:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dkulichkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkulichkin/32/12847_2.png) [@dkulichkin](https://discuss.elastic.co/u/dkulichkin)\
**Post date:** [October 31, 2016, 5:15pm UTC](https://discuss.elastic.co/t/scripted-metrics-aggregation-based-on-complicated-terms-buckets-as-an-entry-data/64469/1 "2016-10-31T17:15:16Z")

</div>

I have an index containing various mobile platform feature-related events, for example Bluetooth accessibility status switching on/off. To simplify let's say the appropriate type's schema looks like this:

```auto
"BLUETOOTH_STATUS": {
  "properties": {
    "device_id" : { "type" : "string", "index" : "not_analyzed" },
    "time" : { "type" : "date" },        
    "os" : { "type" : "string", "index" : "not_analyzed" },
    "status" : { "type": "boolean" }
  }
}

```

I.e. every device can populate multiple on/off events for the Bluetooth while using the application. Eventually I need to show a number of the ones with the feature status enabled. Currently I've not found any better way to approach it but making the following combination of the terms/top\_hits aggregations:

```auto
"BLUETOOTH_STATUS": {
  "filter": {
    "term": {"_type": "BLUETOOTH_STATUS"}
  },
  "aggs": {    
    "by_device": {
      "terms": { "field": "device_id", "size": 0 },
      "aggs": {
        "max_date": {
          "top_hits": {
            "size": 1,
            "sort": [{ "time": { "order": "desc" } }],
            "_source": { "include": ["status"]}
          }
        }
      }
    }    
  }
}

```

This ends up with having a big payload delivered and needed to be handled subsequently on the client with a last feature status per device\_id and accounting only positive ones:

```auto
const bluetoothEnabledCount = by_device.buckets.filter((device) => 
   device.max_date.hits.hits[0]._source.status ).length;

```

I.e. having a few thousand unique users (device\_id) in the system I always need to deal with a payload of these few thousand device id buckets.

Is there are any better way to come up with this metric right from the server at once? At least avoid doing it on the client? I started to look towards the scripted\_metric but didn't find how to provide my terms/top\_hits buckets as an init\_script data.

So whether it's possible to approach the problem in a more effective way rather than I'm doing it now?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [October 31, 2016, 6:00pm UTC](https://discuss.elastic.co/t/scripted-metrics-aggregation-based-on-complicated-terms-buckets-as-an-entry-data/64469/2 "2016-10-31T18:00:20Z")

</div>

See this similar "devices with last status of X" question here: [Find servers whose last logged event was "error"](https://discuss.elastic.co/t/find-servers-whose-last-logged-event-was-error/64146/5?u=mark_harwood)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:08pm UTC](https://discuss.elastic.co/t/scripted-metrics-aggregation-based-on-complicated-terms-buckets-as-an-entry-data/64469/3 "2017-07-05T22:08:07Z")

</div>


