# Too many aggregation buckets

**URL:** <https://discuss.elastic.co/t/too-many-aggregation-buckets/56631>\
**Category:** Elasticsearch\
**Created:** [July 28, 2016, 1:51pm UTC](https://discuss.elastic.co/t/too-many-aggregation-buckets/56631 "2016-07-28T13:51:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![orweinberger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orweinberger/32/580_2.png) [@orweinberger](https://discuss.elastic.co/u/orweinberger)\
**Post date:** [July 28, 2016, 1:51pm UTC](https://discuss.elastic.co/t/too-many-aggregation-buckets/56631/1 "2016-07-28T13:51:56Z")

</div>

I have a query with an aggregation of a date histogram that creates buckets per 10 seconds for a full day, on that aggregation I perform a sum of a field and at the end I use the max\_bucket aggregation to extract the highest sum of those buckets.

Consider this query:

```
{
  "size": 0,
  "aggs": {
    "mos": {
      "terms": {
        "field": "mo_id",
        "size": 0
      },
      "aggs": {
        "histogram": {
          "date_histogram": {
            "field": "time_stamp",
            "interval": "10s",
            "min_doc_count": 1
          },
          "aggs": {
            "sum_per_interval": {
              "sum": {
                "field": "throughput"
              }
            }
          }
        },
        "peak_throughput": {
          "max_bucket": {
            "buckets_path": "histogram>sum_per_interval"
          }
        }
      }
    }
  },
  "query": {
    "filtered": {
      "filter": {
        "range": {
          "time_stamp": {
            "gte": "2016-07-25T00:00:00",
            "lt": "2016-07-26T00:00:00",
            "format": "yyyy-MM-dd'T'HH:mm:ss"
          }
        }
      }
    }
  }
}

```

My problem is that the actual response from the server is too large to handle, and I'm only interested in the results of the peak\_throughput value. Is there a way to calculate the date\_histogram buckets but not to return these in the response? I thought about using scripted aggregations to achieve this but I could not find a scripted aggregation that would simulate the date\_histogram that ES is running.

---

<div class="post-metadata">

**Author:** ![cbuescher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cbuescher/32/60402_2.png) [@cbuescher](https://discuss.elastic.co/u/cbuescher)\
**Post date:** [July 28, 2016, 2:05pm UTC](https://discuss.elastic.co/t/too-many-aggregation-buckets/56631/2 "2016-07-28T14:05:42Z")

</div>

Hi,

If it's only about reducing the size of the response, maybe Response Filtering could help: [https://www.elastic.co/guide/en/elasticsearch/reference/2.3/common-options.html#\_response\_filtering](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/common-options.html#_response_filtering)

---

<div class="post-metadata">

**Author:** ![orweinberger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orweinberger/32/580_2.png) [@orweinberger](https://discuss.elastic.co/u/orweinberger)\
**Post date:** [August 1, 2016, 10:01am UTC](https://discuss.elastic.co/t/too-many-aggregation-buckets/56631/3 "2016-08-01T10:01:07Z")

</div>

Perfect, exactly what I was looking for, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:31pm UTC](https://discuss.elastic.co/t/too-many-aggregation-buckets/56631/4 "2017-07-05T22:31:16Z")

</div>


