# Sum aggregation on distinct values of field

**URL:** <https://discuss.elastic.co/t/sum-aggregation-on-distinct-values-of-field/105088>\
**Category:** Elasticsearch\
**Created:** [October 24, 2017, 3:22pm UTC](https://discuss.elastic.co/t/sum-aggregation-on-distinct-values-of-field/105088 "2017-10-24T15:22:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharongur](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@sharongur](https://discuss.elastic.co/u/sharongur)\
**Post date:** [October 24, 2017, 3:22pm UTC](https://discuss.elastic.co/t/sum-aggregation-on-distinct-values-of-field/105088/1 "2017-10-24T15:22:08Z")

</div>

Hi,

I want to make a query that returns my wanted documents. from those documents i need to sum aggregate

> field1

on all the distinct values of

> field2

small example:

i have index that has 500 documents with fields

> download

and

> application

now ill try to describe the result im looking for:

total\_docs\_in\_index: 500

total\_search\_hit: 10

sum\_agg:  
application: twitter : {hits: 3 ,download : 123456}  
( this will show 2 aggregations, first, how many documents with twitter as their application there is and secondly is the sum of all download field of these documents)  
application: wahtsapp: {hits: 3, download: 6789}  
application: facebook:{hits: 4, download: 90123}

is it possible?

I find it easy to aggregate each field by itself ( normal aggregation to see how many application: twitter in my query documents, or sum aggregation on the download field) but i cant seem to be able to combine the 2.

Thanks in advance.

P.S - the "result" i wrote is fictional to try and better describe what i need, i just need to know how to do that complex aggregation, all the rest can be the default response of elasticsearch

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [October 27, 2017, 4:41pm UTC](https://discuss.elastic.co/t/sum-aggregation-on-distinct-values-of-field/105088/2 "2017-10-27T16:41:11Z")

</div>

I'm not positive I understood what you're after, but I think this is it:

```auto
GET _search
{
  "aggs": {
    "application": {
      "terms": {
        "field": "application",
        "size": 10
      },
      "aggs": {
        "num_downloads": {
          "sum": {
            "field": "download"
          }
        }
      }
    }
  }
}

```

That will give you a bucket-per-application, and inside each bucket it'll tally up the sum of the download field of all documents that have the particular application.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2017, 4:41pm UTC](https://discuss.elastic.co/t/sum-aggregation-on-distinct-values-of-field/105088/3 "2017-11-24T16:41:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
