# Sum aggregation in kibana data table visualization for "other" bucket is always 0

**URL:** <https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430>\
**Category:** Kibana\
**Created:** [July 16, 2020, 9:59am UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430 "2020-07-16T09:59:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![webstruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webstruck/32/72441_2.png) [@webstruck](https://discuss.elastic.co/u/webstruck)\
**Post date:** [July 16, 2020, 9:59am UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/1 "2020-07-16T09:59:18Z")

</div>

I'm trying to create a data table visualization in ELK 7.8. I have a Terms aggregation with size 5 and checked "Group other values in separate bucket". So it shows Other bucket as row in the table with Count metric. I also have a Sum metric for a numeric field. For this Other bucket, the value of Sum aggregation is always 0 which is not correct. Why is SUM aggregation not performed on "Other" bucket? Are there any ways to achieve this?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/1/21d3cad66724f3f51a59eb894cdfc35c48b1cf34.png)

---

<div class="post-metadata">

**Author:** ![webstruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webstruck/32/72441_2.png) [@webstruck](https://discuss.elastic.co/u/webstruck)\
**Post date:** [July 19, 2020, 11:20pm UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/2 "2020-07-19T23:20:44Z")

</div>

Can I have some comment on this please? It sure looks like a gap to me.

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [July 24, 2020, 10:01pm UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/3 "2020-07-24T22:01:03Z")

</div>

Hi @webstruck -- what's the Elasticsearch mapping for the "operation duration" field? And I assume the Kibana index pattern has it as "Number", correct?

I just tested this in 7.8 using the sample logs data which ship with Kibana, but was unable to reproduce, so I'm trying to figure out what I'm missing

---

<div class="post-metadata">

**Author:** ![webstruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webstruck/32/72441_2.png) [@webstruck](https://discuss.elastic.co/u/webstruck)\
**Post date:** [July 27, 2020, 1:11am UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/4 "2020-07-27T01:11:02Z")

</div>

@lukeelmers The Elasticsearch mapping is

```auto
    "operationduration": {
              "type": "float"
            } 

```

and yes, Kibana index pattern has it as "Number", searchable and aggregatable.

One recent observation is, if I choose my sum aggregation (summing OperationDuration in this case) metric as "Order By" for my Terms aggregation, then the sum for "other" bucket is calculated properly. But if I choose default count metric (All Events) as "Order By " then I see above issue and sum is always 0. Hope it helps!

---

<div class="post-metadata">

**Author:** ![webstruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webstruck/32/72441_2.png) [@webstruck](https://discuss.elastic.co/u/webstruck)\
**Post date:** [August 7, 2020, 3:25am UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/5 "2020-08-07T03:25:41Z")

</div>

@lukeelmers Did you managed to reproduce it?

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [August 13, 2020, 11:15pm UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/6 "2020-08-13T23:15:39Z")

</div>

@webstruck I still haven't had any luck.

I'm using our public demo environment to try to reproduce this, [you can see what I have configured here](https://demo.elastic.co/app/kibana#/visualize/create?indexPattern=90943e30-9a47-11e8-b64d-95841ca0b247&type=table&_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-7d,to:now))&_a=(filters:!(),linked:!f,query:(language:kuery,query:''),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:machine.os.keyword,missingBucket:!f,missingBucketLabel:Missing,order:desc,orderBy:'1',otherBucket:!t,otherBucketLabel:Other,size:3),schema:bucket,type:terms),(enabled:!t,id:'4',params:(field:bytes),schema:metric,type:sum)),params:(perPage:10,percentageCol:'',showMetricsAtAllLevels:!f,showPartialRows:!f,showTotal:!t,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'',type:table))), but so far things are working as expected.

I might have configured the demo visualization incorrectly though -- are you able to reproduce the same issue in the demo environment using one of the sample data sets there? Trying to narrow down whether this is a bug, or perhaps something specific to your environment.

---

<div class="post-metadata">

**Author:** ![webstruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webstruck/32/72441_2.png) [@webstruck](https://discuss.elastic.co/u/webstruck)\
**Post date:** [September 7, 2020, 8:38am UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/7 "2020-09-07T08:38:22Z")

</div>

This surely seem to work in your demo environment. What else I could check in my environment?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2020, 8:38am UTC](https://discuss.elastic.co/t/sum-aggregation-in-kibana-data-table-visualization-for-other-bucket-is-always-0/241430/8 "2020-10-05T08:38:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
