# Unable to parse BaseAggregationBuilder

**URL:** <https://discuss.elastic.co/t/unable-to-parse-baseaggregationbuilder/217457>\
**Category:** Elasticsearch\
**Created:** [January 31, 2020, 8:04pm UTC](https://discuss.elastic.co/t/unable-to-parse-baseaggregationbuilder/217457 "2020-01-31T20:04:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![WLH](https://avatars.discourse-cdn.com/v4/letter/w/a183cd/32.png) [@WLH](https://discuss.elastic.co/u/WLH)\
**Post date:** [January 31, 2020, 8:04pm UTC](https://discuss.elastic.co/t/unable-to-parse-baseaggregationbuilder/217457/1 "2020-01-31T20:04:02Z")

</div>

Good afternoon, I am trying to build an elastic watcher query using nested aggs, that feed the variables into a bucket script that will subtract one field from another, then put that value into a watcher on a threashold. I've done plenty of watchers on standard searches on logs which work great. But this is a bit of a different beast to me.

I am hoping that I am doing something syntactically wrong on my first step of building the nested agg.

I read through this as my "yellow brick road"  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.5/search-aggregations-pipeline.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/search-aggregations-pipeline.html)

When I run this, I get all the topics back:

```
GET /metricbeat-7.4.0-2020.01.31-000051/_search
{

  "size": 0,
  "aggs": {
    "group_by_topic": {
      "terms": {
        "field": "kafka.topic.name",
        "size": 50
      } 
    }
    }

}

}

```

But when I run this in dev tools I get back object not found exception. I checked to make sure that the agg was nested, but it's not working out too well.

```
GET /metricbeat-7.4.0-2020.01.31-000051/_search
{

  "size": 0,
  "aggs": {
    "group_by_topic": {
      "terms": {
        "field": "kafka.topic.name",
        "size": 50
      } 
    },
    "aggs": {
      "sum_partition_offset_newest":{ "sum": { "field": "kafka.partition.offset.newest" }
      }
    }

}

}

"type": "named_object_not_found_exception",
"reason": "[12:37] unable to parse BaseAggregationBuilder with name 
[sum_partition_offset_newest]: parser not found"
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 3, 2020, 3:23pm UTC](https://discuss.elastic.co/t/unable-to-parse-baseaggregationbuilder/217457/2 "2020-02-03T15:23:58Z")

</div>

can you try to nest the `aggs: sum_partition_offset_newest` part within the `group_by_topic` field?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 3:24pm UTC](https://discuss.elastic.co/t/unable-to-parse-baseaggregationbuilder/217457/3 "2020-03-02T15:24:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
