# Sum Aggregation using multiple fields

**URL:** <https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357>\
**Category:** Elasticsearch\
**Created:** [December 16, 2022, 1:14am UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357 "2022-12-16T01:14:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [December 16, 2022, 1:14am UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/1 "2022-12-16T01:14:58Z")

</div>

Hi team!

I am indexing the following sample data:

travel index

Flight price - 550  
Hotel price - 220  
Meals - 120

(Total Expense - 890)

1. If I query for travel index with total expense \< 1000, it should return results as the total expense \< 1000
2. If I query for travel index with total expense \> 1000, it should not return results as the total expense \< 1000

Is there a way to query to get the sum of all the fields and then apply the filter say in this case \<1000?

I see nested aggregations but not sure if it can be done across multiple fields

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 16, 2022, 5:05am UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/2 "2022-12-16T05:05:20Z")

</div>

Welcome!

What does a typical json document looks like?

---

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [December 16, 2022, 10:29am UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/3 "2022-12-16T10:29:26Z")

</div>

{“city”:”Chicago”,  
“Traveldate”:”12dec2022”,  
“Flightprice”: “350”,  
“Hotelprice”: “200”,  
“Meals”: “120”  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 16, 2022, 12:55pm UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/4 "2022-12-16T12:55:21Z")

</div>

And why not doing this at index time?

```auto
{
  "city":"Chicago",
  "Traveldate":"12dec2022",
  "Flightprice": 350,
  "Hotelprice": 200,
  "Meals": 120,
  "Total": 670
}

```

---

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [December 16, 2022, 2:54pm UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/5 "2022-12-16T14:54:03Z")

</div>

So create a new field called total expense in the document? How do I do the summation during indexing?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 16, 2022, 7:02pm UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/6 "2022-12-16T19:02:00Z")

</div>

The best thing is to do that in your application. Should not be hard.  
But you can also use an ingest pipeline if the first solution does not work for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2023, 7:02pm UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357/7 "2023-01-13T19:02:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
