# Top Hit / last value metrics aggregation doesn't work on Runtime fields

**URL:** <https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924>\
**Category:** Kibana\
**Tags:** runtime-fields\
**Created:** [April 8, 2022, 5:35am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924 "2022-04-08T05:35:34Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![BitBucketUser\_user](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitbucketuser_user/32/79679_2.png) [@BitBucketUser\_user](https://discuss.elastic.co/u/BitBucketUser_user)\
**Post date:** [April 8, 2022, 5:35am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/1 "2022-04-08T05:35:34Z")

</div>

Hello All,  
I use Kibana version 7.15.2.  
I'm not able to perform TopHits or last value metrics aggregation on runtime fields. I just see blanks or dashes '-' when I do so.

Here is an example:  
On the kibana\_sample\_data\_logs index, I create an index pattern with a runtime field of type **long** to calculate the square of the bytes field. The name of this field is **Bytes power 2**  
Here is my runtime field script :

```auto
emit(doc['bytes'].value*doc['bytes'].value);

```

In a lens table, I try to find the last value of bytesSquare for top agent.name and I don't get expected results:

1. ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/6/167a60b49522292caebefe5e78e9ee71795a51f7.png)

2. ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e8c06c3f38d464880fbd1528afef5aa224cf8b3.png)

3. 

This works with scripted fields but not with runtime fields. I'm I going wrong anywhere?  
Please help me with this..

---

<div class="post-metadata">

**Author:** ![BitBucketUser\_user](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitbucketuser_user/32/79679_2.png) [@BitBucketUser\_user](https://discuss.elastic.co/u/BitBucketUser_user)\
**Post date:** [April 14, 2022, 6:16am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/2 "2022-04-14T06:16:15Z")

</div>

Hi All, Can I please get some inputs here?

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [April 14, 2022, 1:28pm UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/3 "2022-04-14T13:28:28Z")

</div>

Try filtering the lens metrics for where your runtime field has a value. sometimes the nulls can trip up the last value operation. So much so that we add this metric filter by default in version 8.2

does that work?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/8/08a5715eefa4c2cd4bc014e4fed5ee61feaf816c.png)

---

<div class="post-metadata">

**Author:** ![BitBucketUser\_user](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitbucketuser_user/32/79679_2.png) [@BitBucketUser\_user](https://discuss.elastic.co/u/BitBucketUser_user)\
**Post date:** [April 18, 2022, 5:11am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/4 "2022-04-18T05:11:24Z")

</div>

Thanks for the reply Graham. I tried adding field exists filter, doesn't seem to work.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d40b58bf82d7680bffa4bc0e5ef6309edbfee482.png)

Also I've modified runtime field script so as to never return null by emitting **0** whenever **bytes** field doesn't exist or is empty.. and I still get dashes when calculating **last value or TopHits**  
This is the modified script :

```auto
if (!doc.containsKey('bytes') || doc['bytes'].empty) { emit(0); } else emit(doc['bytes'].value*doc['bytes'].value);

```

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [April 18, 2022, 9:00pm UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/5 "2022-04-18T21:00:31Z")

</div>

Interestingly enough it works for me.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9faad40c7561bd73b424cd42cf14db86f3437e07.png)

I'll have to check 7.15.2....can you upgrade?

---

<div class="post-metadata">

**Author:** ![BitBucketUser\_user](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitbucketuser_user/32/79679_2.png) [@BitBucketUser\_user](https://discuss.elastic.co/u/BitBucketUser_user)\
**Post date:** [April 19, 2022, 5:07am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/6 "2022-04-19T05:07:35Z")

</div>

Thanks Graham. I just checked with version 7.17.2 and it seems to be working fine there. Is this a bug or limitation in 7.15.2? Is there a workaround to get this working in 7.15.2?

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [April 19, 2022, 9:49pm UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/7 "2022-04-19T21:49:34Z")

</div>

I checked and we don't normally backport to older releases on the same major version unless it's very serious (like a security issue). If you can upgrade to 7.17.x then that's the recommended solution. if you are unable to upgrade you could also try the legacy data table visualization as an alternative.

---

<div class="post-metadata">

**Author:** ![BitBucketUser\_user](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitbucketuser_user/32/79679_2.png) [@BitBucketUser\_user](https://discuss.elastic.co/u/BitBucketUser_user)\
**Post date:** [April 20, 2022, 5:28am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/8 "2022-04-20T05:28:03Z")

</div>

Thanks Graham!  
Legacy data tables in 7.15.2 also have same problem.  
Thanks for the assistance. Now I know that upgrade to 7.17.x is the only way to make it work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2022, 5:28am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924/9 "2022-05-18T05:28:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
