# Where did my aggregation data go! The case of the missing bucket

**URL:** <https://discuss.elastic.co/t/where-did-my-aggregation-data-go-the-case-of-the-missing-bucket/39295>\
**Category:** Elasticsearch\
**Created:** [January 15, 2016, 1:17am UTC](https://discuss.elastic.co/t/where-did-my-aggregation-data-go-the-case-of-the-missing-bucket/39295 "2016-01-15T01:17:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![zdrummond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zdrummond/32/4233_2.png) [@zdrummond](https://discuss.elastic.co/u/zdrummond)\
**Post date:** [January 15, 2016, 1:17am UTC](https://discuss.elastic.co/t/where-did-my-aggregation-data-go-the-case-of-the-missing-bucket/39295/1 "2016-01-15T01:17:17Z")

</div>

When I ask ES for an aggregation, by time, of the sum of a size by ID; I get a result where some events work correctly (end up in bucket with the correct term key), but other data, seemingly randomly, ends up with a blank term key

For example, with this as my aggs

```auto
 "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "interval": "1m",
        "time_zone": "America/Los_Angeles",
        "min_doc_count": 1,
        "extended_bounds": {
          "min": 1452209723842,
          "max": 1452214986379
        }
      },
      "aggs": {
        "3": {
          "terms": {
            "field": "collection_id.raw",
            "size": 0,
            "order": {
              "1": "desc"
            }
          },
          "aggs": {
            "1": {
              "sum": {
                "field": "size"
              }
            }
          }
        }
      }
    }
  }

```

I get the the following result  
...

```auto
 "aggregations": {
    "2": {
      "buckets": [
        {
          "3": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": []
          },
          "key_as_string": "2016-01-07T15:38:00.000-08:00",
          "key": 1452209880000,
          "doc_count": 1
        },
        {
          "3": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
              {
                "1": {
                  "value": 140355866
                },
                "key": "19488",
                "doc_count": 43
              }
            ]
          },
          "key_as_string": "2016-01-07T16:59:00.000-08:00",
          "key": 1452214740000,
          "doc_count": 43
        },
        {
          "3": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
              {
                "1": {
                  "value": 63037240
                },
                "key": "19488",
                "doc_count": 8
              }
            ]
          },
          "key_as_string": "2016-01-07T17:01:00.000-08:00",
          "key": 1452214860000,
          "doc_count": 8
        }
      ]
    }
  }

```

Note that I get three buckets. Two of them have a value in `buckets`, one of them does not.

If i dig into the Event data, I see nothing odd about them, Here is a snippet for an event that does get into a well defined bucket,

```auto
@timestamp January 7th 2016, 16:59:32.000
t@version 1
t_id AVIevu0_l2HWhQn5VZHu
t_index logstash-2016.01.08
... 	
collection_id 19488

```

and one that does not. Note they have all the same key data.

```auto
@timestamp January 7th 2016, 15:38:33.000
t@version 1
t_id AVIedMH2l2HWhQn5U0QH
t_index logstash-2016.01.07
...
collection_id 19456

```

No idea what is going on, and what makes some data special and others not so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:24pm UTC](https://discuss.elastic.co/t/where-did-my-aggregation-data-go-the-case-of-the-missing-bucket/39295/2 "2017-07-05T23:24:16Z")

</div>


