# Update by script with aggregated values

**URL:** <https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731>\
**Category:** Elasticsearch\
**Created:** [April 6, 2020, 2:19pm UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731 "2020-04-06T14:19:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bastian\_Jager](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastian_jager/32/57892_2.png) [@Bastian\_Jager](https://discuss.elastic.co/u/Bastian_Jager)\
**Post date:** [April 6, 2020, 2:19pm UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731/1 "2020-04-06T14:19:27Z")

</div>

Hi,

could not found this in the documentation and only a closed ticket ([Updating source with aggregation values](https://discuss.elastic.co/t/updating-source-with-aggregation-values/138915))

The task would be:  
get min of field\_a by customer and device and add those min values to each queried document.  
In the end each doc should have a field  
`min_value_of_A_for_customer_and_device_over_target_time`  
and  
`min_value_of_A_for_customer_over_target_time`

I can query the information (as shown below), but not sure if I can feed it back with easily.

```
GET live-*/_search?size=0
{
  "query": {
    "bool": {
      "must": {
        "range": {
          " field_a": {
            "gte": 25.0
          }
        }
      }, 
      "filter": {
        "range": {
          "@timestamp": {
            "gte": "now-2M",
            "lte": "now"
          }
        }
      }
    }
  },
  "aggs": {
    "customers_terms": {
      "terms": {
        "field": "customer.keyword",
        "size": 10
      },
      "aggs": {
        "min_field_a_of_customer": {
          "min": {
            "field": "field_a"
          }
        },
        "devices_terms": {
          "terms": {
            "field": "device.keyword",
            "size": 99
          },
          "aggs": {
            "min_field_a": {
              "min": {
                "field": "field_a"
              }
            }
          }
        },
        "avg_field_a_over_devices": {
          "avg_bucket": {
            "buckets_path": "devices_terms>min_field_a"
          }
        }
      }
    }
  }
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![Bastian\_Jager](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastian_jager/32/57892_2.png) [@Bastian\_Jager](https://discuss.elastic.co/u/Bastian_Jager)\
**Post date:** [April 8, 2020, 12:56pm UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731/2 "2020-04-08T12:56:35Z")

</div>

Anyone can answer this? Is it possible or do I have to query this to some client and the run a separate logic to update?

---

<div class="post-metadata">

**Author:** ![itizir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itizir/32/63552_2.png) [@itizir](https://discuss.elastic.co/u/itizir)\
**Post date:** [April 8, 2020, 3:58pm UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731/3 "2020-04-08T15:58:24Z")

</div>

As far as I'm aware update/reindex scripts only have access to local data (the document being looked at), so you'd indeed need to use an external client.  
Not 100% certain though, so if someone else knows of magic tricks I don't...

---

<div class="post-metadata">

**Author:** ![Bastian\_Jager](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastian_jager/32/57892_2.png) [@Bastian\_Jager](https://discuss.elastic.co/u/Bastian_Jager)\
**Post date:** [April 12, 2020, 4:24pm UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731/4 "2020-04-12T16:24:56Z")

</div>

Maybe a elastic member will read this and give me at least a clear no on the topic.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 13, 2020, 1:41am UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731/5 "2020-04-13T01:41:08Z")

</div>

I agree with this.

The only job that creates data from aggs is the Rollup API. [https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-rollup.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-rollup.html)

But I don't think that's what you want @Bastian_Jager.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2020, 1:42am UTC](https://discuss.elastic.co/t/update-by-script-with-aggregated-values/226731/6 "2020-05-11T01:42:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
