# \#aggregations

**URL:** https://discuss.elastic.co/tag/aggregations/138.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Double Multi-field Loses Precision](https://discuss.elastic.co/t/double-multi-field-loses-precision/380561)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 7\
**Last updated:** [August 13, 2025, 7:10am UTC](https://discuss.elastic.co/t/double-multi-field-loses-precision/380561 "2025-08-13T07:10:50Z")

</div>

It seems double field under a float property loses precision in ES8. What changed on ES8? Is there a way to configure it (mapping/index/cluster) so it doesn't lose precision? I tested with the following index PUT test.…

---

## [Adding additional aggregation causes 15x performance degradation despite small result set](https://discuss.elastic.co/t/adding-additional-aggregation-causes-15x-performance-degradation-despite-small-result-set/380132)

<div class="topic-metadata">

**Author:** [@mmiliauskas](https://discuss.elastic.co/u/mmiliauskas)\
**Replies:** 3\
**Last updated:** [July 18, 2025, 2:30pm UTC](https://discuss.elastic.co/t/adding-additional-aggregation-causes-15x-performance-degradation-despite-small-result-set/380132 "2025-07-18T14:30:37Z")

</div>

I have an Elasticsearch query that returns only 107 documents but takes 1.5 seconds to execute. When I remove one specific aggregation (values\_brand), the same query completes in 100ms. The brand field only contains 8 un…

---

## [bucket script to find the percent change in filter bucket](https://discuss.elastic.co/t/bucket-script-to-find-the-percent-change-in-filter-bucket/378458)

<div class="topic-metadata">

**Author:** [@Ramji\_Balu\_Sudarsan](https://discuss.elastic.co/u/Ramji_Balu_Sudarsan)\
**Replies:** 0\
**Last updated:** [May 23, 2025, 7:24am UTC](https://discuss.elastic.co/t/bucket-script-to-find-the-percent-change-in-filter-bucket/378458 "2025-05-23T07:24:07Z")

</div>

I have formed an aggregation query to bucket my tickets based on created\_at epoch. Based on my query I will get two buckets each named previous and current. GET tickets\_trend\_analysis/\_search { "aggs": { "time\_win…

---

## [Broken track\_total\_hits behaviour in aggregation](https://discuss.elastic.co/t/broken-track-total-hits-behaviour-in-aggregation/377008)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 4\
**Last updated:** [April 11, 2025, 8:55am UTC](https://discuss.elastic.co/t/broken-track-total-hits-behaviour-in-aggregation/377008 "2025-04-11T08:55:52Z")

</div>

Hey, I am running an aggregation only request, that looks like this: GET product\_data/\_search?request\_cache=false&terminate\_after=500000 { "timeout": "300ms", "track\_total\_hits": true, "size": 0, "query": {…

---

## [Aggregation Group By With Total Count](https://discuss.elastic.co/t/aggregation-group-by-with-total-count/375057)

<div class="topic-metadata">

**Author:** [@hammadrasheed0](https://discuss.elastic.co/u/hammadrasheed0)\
**Replies:** 4\
**Last updated:** [March 5, 2025, 8:00pm UTC](https://discuss.elastic.co/t/aggregation-group-by-with-total-count/375057 "2025-03-05T20:00:55Z")

</div>

HI, I am stuck with a use case where I need to group N number of persons by company and get the total count of grouped persons across the pages. So far the query I have prepared is working fine up to the level where the…

---

## [HDR percentile aggregation memory footprint](https://discuss.elastic.co/t/hdr-percentile-aggregation-memory-footprint/375297)

<div class="topic-metadata">

**Author:** [@mike123](https://discuss.elastic.co/u/mike123)\
**Replies:** 0\
**Last updated:** [March 3, 2025, 7:23am UTC](https://discuss.elastic.co/t/hdr-percentile-aggregation-memory-footprint/375297 "2025-03-03T07:23:33Z")

</div>

Hi, I was facing huge latency in t-digest percentile aggregations, So tried out HDR percentile aggregation. it was fast but in the documentation it is mentioned that "HDR Percentile aggregation has a larger memory foo…

---

## [Sorted pagination in terms aggregation search](https://discuss.elastic.co/t/sorted-pagination-in-terms-aggregation-search/374820)

<div class="topic-metadata">

**Author:** [@julian.dto](https://discuss.elastic.co/u/julian.dto)\
**Replies:** 0\
**Last updated:** [February 20, 2025, 1:46pm UTC](https://discuss.elastic.co/t/sorted-pagination-in-terms-aggregation-search/374820 "2025-02-20T13:46:58Z")

</div>

Hello! I am trying to run an aggregation search with pagination. The solutions I found were either partitioning or using search\_after. With partitioning the sorting will only be inside of the partition, not the overall…

---

## [Aggregation over array](https://discuss.elastic.co/t/aggregation-over-array/374511)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 6\
**Last updated:** [February 13, 2025, 4:36pm UTC](https://discuss.elastic.co/t/aggregation-over-array/374511 "2025-02-13T16:36:32Z")

</div>

Hi, I have a document like this { "ip": \[ "192.168.1.1", "192.168.1.2" \] } Is it possible to make aggregation over value at zero position in the array? Something like this? { "aggs": { "my\_aggregati…

---

## [Aggregation with Concatenation](https://discuss.elastic.co/t/aggregation-with-concatenation/373526)

<div class="topic-metadata">

**Author:** [@kdwolf](https://discuss.elastic.co/u/kdwolf)\
**Replies:** 0\
**Last updated:** [January 22, 2025, 4:34pm UTC](https://discuss.elastic.co/t/aggregation-with-concatenation/373526 "2025-01-22T16:34:42Z")

</div>

I have an index (see below) which stores RTT (Realtime Text) - every time someone types a letter within a conversation, it is stored as a document as a "typed" event. If someone deletes the letter, it will be stored as a…

---

## [Using nested aggregation average result in condition](https://discuss.elastic.co/t/using-nested-aggregation-average-result-in-condition/373233)

<div class="topic-metadata">

**Author:** [@John\_Harris](https://discuss.elastic.co/u/John_Harris)\
**Replies:** 0\
**Last updated:** [January 15, 2025, 2:35pm UTC](https://discuss.elastic.co/t/using-nested-aggregation-average-result-in-condition/373233 "2025-01-15T14:35:23Z")

</div>

When attempting to using a sub aggregation metric average in a condition, I'm receiving "aggregations": { "modules": { "terms": { "field": "host.hostname.keyword", "size"…

---

## [Elastic search nested aggrigation](https://discuss.elastic.co/t/elastic-search-nested-aggrigation/371709)

<div class="topic-metadata">

**Author:** [@Abhay\_Pratap\_Singh](https://discuss.elastic.co/u/Abhay_Pratap_Singh)\
**Replies:** 0\
**Last updated:** [December 9, 2024, 2:28pm UTC](https://discuss.elastic.co/t/elastic-search-nested-aggrigation/371709 "2024-12-09T14:28:23Z")

</div>

I am try to get final price of each product of orders bu not able to calculate. The Document sample : Order Index : ------------- { "order\_id": "123", "customer": "John Doe", "deliveryFee": 40, "items": \[ …

---

## [Trying to use an alphabetical bucket sort within a terms aggregation](https://discuss.elastic.co/t/trying-to-use-an-alphabetical-bucket-sort-within-a-terms-aggregation/371490)

<div class="topic-metadata">

**Author:** [@JoshFarwig](https://discuss.elastic.co/u/JoshFarwig)\
**Replies:** 0\
**Last updated:** [December 4, 2024, 10:27pm UTC](https://discuss.elastic.co/t/trying-to-use-an-alphabetical-bucket-sort-within-a-terms-aggregation/371490 "2024-12-04T22:27:34Z")

</div>

Hey! I am currently using Elasticsearch 8.15. I am in a bit of a conundrum trying to achieve outer and inner bucket sorting for strings (sorted asc or desc alphabetically). My index, hazard, looks a little something like…

---

## [How to calculate unique contact duplicates using different fields](https://discuss.elastic.co/t/how-to-calculate-unique-contact-duplicates-using-different-fields/370716)

<div class="topic-metadata">

**Author:** [@andreyshiryaev13](https://discuss.elastic.co/u/andreyshiryaev13)\
**Replies:** 2\
**Last updated:** [November 19, 2024, 9:00pm UTC](https://discuss.elastic.co/t/how-to-calculate-unique-contact-duplicates-using-different-fields/370716 "2024-11-19T21:00:04Z")

</div>

Hi, I am trying to find an effective way to count unique contacts. Elastic 8.15 Index structure { id, email, phone, first, last } Data Example { 1, user@gmail.com, 1111111, Tom, Hanks }, { 2, user2@gmail.com, 1111111…

---

## [How to clear cache of keyword field in elastic search?](https://discuss.elastic.co/t/how-to-clear-cache-of-keyword-field-in-elastic-search/366026)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 9\
**Last updated:** [November 5, 2024, 9:43am UTC](https://discuss.elastic.co/t/how-to-clear-cache-of-keyword-field-in-elastic-search/366026 "2024-11-05T09:43:41Z")

</div>

Hi , I am facing cache issue with keyword field in Elastic. I have a document with keyword field which is indexed with some value example : abc later the same document is reindexed again with some value abcd, old value …

---

## [Terms aggregation on high cardinality field](https://discuss.elastic.co/t/terms-aggregation-on-high-cardinality-field/367196)

<div class="topic-metadata">

**Author:** [@ivan83](https://discuss.elastic.co/u/ivan83)\
**Replies:** 6\
**Last updated:** [October 17, 2024, 8:41pm UTC](https://discuss.elastic.co/t/terms-aggregation-on-high-cardinality-field/367196 "2024-10-17T20:41:32Z")

</div>

Hello! I am sharing the issue that I am having here hoping that someone can help me. We are executing terms on a field which has super high cardinality. I am talking about 40 million unique entries that represents prod…

---

## [How to aggregate the change of a field value split by multiple keyword fields?](https://discuss.elastic.co/t/how-to-aggregate-the-change-of-a-field-value-split-by-multiple-keyword-fields/365810)

<div class="topic-metadata">

**Author:** [@Jim\_Panzee](https://discuss.elastic.co/u/Jim_Panzee)\
**Replies:** 0\
**Last updated:** [August 30, 2024, 8:26am UTC](https://discuss.elastic.co/t/how-to-aggregate-the-change-of-a-field-value-split-by-multiple-keyword-fields/365810 "2024-08-30T08:26:27Z")

</div>

Give this sample data structure: "data": { "values": \[ { "A": "Room1", "B": "Team1", "C": "Chef", "X": 30}, { "A": "Room2", "B": "Team2", "C": "Waitress", "X": 24}, ...\] } Documents are coming in e…

---

## [Counting amount of buckets in aggregation](https://discuss.elastic.co/t/counting-amount-of-buckets-in-aggregation/363786)

<div class="topic-metadata">

**Author:** [@Zful](https://discuss.elastic.co/u/Zful)\
**Replies:** 2\
**Last updated:** [August 1, 2024, 1:00pm UTC](https://discuss.elastic.co/t/counting-amount-of-buckets-in-aggregation/363786 "2024-08-01T13:00:00Z")

</div>

Hi! I have an index holding connection events. I want to group them by 3 of their fields: src.ip, dst.ip and port. I'm using composite aggregation for the grouping, but I also need the total amount of buckets. Current…

---

## [Global Aggregation on nested fields with filters](https://discuss.elastic.co/t/global-aggregation-on-nested-fields-with-filters/363023)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 3\
**Last updated:** [July 26, 2024, 4:13am UTC](https://discuss.elastic.co/t/global-aggregation-on-nested-fields-with-filters/363023 "2024-07-26T04:13:36Z")

</div>

I am facing issues with aggregations on nested field. Below are the mapping fields. { "mappings": { "properties": { "autocomplete": { "type": "text", "analyzer": "autocomplete", "fiel…

---

## [Logstash Aggregate filter sometimes does not work](https://discuss.elastic.co/t/logstash-aggregate-filter-sometimes-does-not-work/362992)

<div class="topic-metadata">

**Author:** [@Fdsm](https://discuss.elastic.co/u/Fdsm)\
**Replies:** 0\
**Last updated:** [July 12, 2024, 4:30am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-sometimes-does-not-work/362992 "2024-07-12T04:30:34Z")

</div>

I have some integration logs coming from filebeat and I'm trying to use the aggregate filter to calculate the delta of the entire process. The code implemented seems to work properly, but looking at kibana some records a…

---

## [Sub-millisecond aggregation in ElasticSearch](https://discuss.elastic.co/t/sub-millisecond-aggregation-in-elasticsearch/361924)

<div class="topic-metadata">

**Author:** [@Varun\_Tokas](https://discuss.elastic.co/u/Varun_Tokas)\
**Replies:** 2\
**Last updated:** [July 8, 2024, 9:49am UTC](https://discuss.elastic.co/t/sub-millisecond-aggregation-in-elasticsearch/361924 "2024-07-08T09:49:23Z")

</div>

We are using Elasticsearch to store some time series data which has nano-second precision time stamps. Through use of the date\_nanos datatype we are able to ingest the data into Elasticsearch and plot it in Kibana. Howev…

---

## [Get Max Aggregate value for top N hits from elasticsearch](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485)

<div class="topic-metadata">

**Author:** [@Het\_Test](https://discuss.elastic.co/u/Het_Test)\
**Replies:** 3\
**Last updated:** [July 5, 2024, 5:41pm UTC](https://discuss.elastic.co/t/get-max-aggregate-value-for-top-n-hits-from-elasticsearch/362485 "2024-07-05T17:41:12Z")

</div>

Hey guys, I have an Elasticsearch field called activity\_time, and I need to get the maximum activity\_time from a subset of my data. For Ex, I want to get the max value of activity\_time from the first 100 records when s…

---

## [Variable\_width\_histogram cannot be nested in sampler](https://discuss.elastic.co/t/variable-width-histogram-cannot-be-nested-in-sampler/361822)

<div class="topic-metadata">

**Author:** [@jewell](https://discuss.elastic.co/u/jewell)\
**Replies:** 1\
**Last updated:** [June 24, 2024, 9:39am UTC](https://discuss.elastic.co/t/variable-width-histogram-cannot-be-nested-in-sampler/361822 "2024-06-24T09:39:24Z")

</div>

Greetings The variable\_width\_histogram works fine as the first aggregation GET ntsp\_dbas\_bfg/\_search { "query": { "term": { "name": { "value": "Valsartanic acid" } } }, "size": 0, "a…

---

## [How to remove hits after aggregation](https://discuss.elastic.co/t/how-to-remove-hits-after-aggregation/360735)

<div class="topic-metadata">

**Author:** [@p4charu](https://discuss.elastic.co/u/p4charu)\
**Replies:** 5\
**Last updated:** [June 5, 2024, 2:00pm UTC](https://discuss.elastic.co/t/how-to-remove-hits-after-aggregation/360735 "2024-06-05T14:00:41Z")

</div>

Hello, I'm trying to do an aggregate query to get issues at their highest state but if the highest state is 'closed' then I want to completely ignore the issue. For example, docId action issue Doc1 raised issue1…

---

## [How to visualize or count same Counter from different pods](https://discuss.elastic.co/t/how-to-visualize-or-count-same-counter-from-different-pods/360677)

<div class="topic-metadata">

**Author:** [@Mazdak\_Mansouri](https://discuss.elastic.co/u/Mazdak_Mansouri)\
**Replies:** 3\
**Last updated:** [June 4, 2024, 10:03pm UTC](https://discuss.elastic.co/t/how-to-visualize-or-count-same-counter-from-different-pods/360677 "2024-06-04T22:03:17Z")

</div>

We are using OpenTelemetry to collect custom metrics into Elastic. We have a simple counter metrics that on each of our endpoint call, increase +1. (basically we want to count how many times an endpoint called in X peri…

---

## [Prepare the aggregation query according to the first occurence of the events](https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424)

<div class="topic-metadata">

**Author:** [@vish\_anand](https://discuss.elastic.co/u/vish_anand)\
**Replies:** 2\
**Last updated:** [May 14, 2024, 5:16am UTC](https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424 "2024-05-14T05:16:41Z")

</div>

I have the the data of the access logs of the users in opensearch index, this data track the information of the users like at what time users access the door and got the arrival, but one user can swipe multiple time in a…

---

## [Convert the MongoDB query to Opensearch](https://discuss.elastic.co/t/convert-the-mongodb-query-to-opensearch/359402)

<div class="topic-metadata">

**Author:** [@vish\_anand](https://discuss.elastic.co/u/vish_anand)\
**Replies:** 2\
**Last updated:** [May 13, 2024, 6:43pm UTC](https://discuss.elastic.co/t/convert-the-mongodb-query-to-opensearch/359402 "2024-05-13T18:43:20Z")

</div>

I have the aggregation query in mongoDB which is working properly. THis query finds the count of the users hour-wise but only consider the first arrival of the user. For example if user arrives at 11 AM and then again at…

---

## [Aggregate with bucket selector and sorting on data stream time series data](https://discuss.elastic.co/t/aggregate-with-bucket-selector-and-sorting-on-data-stream-time-series-data/359041)

<div class="topic-metadata">

**Author:** [@ahw](https://discuss.elastic.co/u/ahw)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 9:20am UTC](https://discuss.elastic.co/t/aggregate-with-bucket-selector-and-sorting-on-data-stream-time-series-data/359041 "2024-05-08T09:20:36Z")

</div>

I have a data stream time series setup where i ingest metrics for different units. These metric was before in a postgres database, but now i try to move it into elasticsearch. One of my usecases is to answer questions li…

---

## [Logstash Aggregate plugin is passing by some events](https://discuss.elastic.co/t/logstash-aggregate-plugin-is-passing-by-some-events/358571)

<div class="topic-metadata">

**Author:** [@Delvin](https://discuss.elastic.co/u/Delvin)\
**Replies:** 4\
**Last updated:** [May 1, 2024, 4:34pm UTC](https://discuss.elastic.co/t/logstash-aggregate-plugin-is-passing-by-some-events/358571 "2024-05-01T16:34:19Z")

</div>

Good day everyone! I need some help, because I can't understand, why aggregate function is not working properly. The thing is, that some events are not just aggregated, though IDs are the same (in my case ID is web.trac…

---

## [Pipeline to Pipeline forked configuration to enable use of the aggregation filter](https://discuss.elastic.co/t/pipeline-to-pipeline-forked-configuration-to-enable-use-of-the-aggregation-filter/358202)

<div class="topic-metadata">

**Author:** [@finejason](https://discuss.elastic.co/u/finejason)\
**Replies:** 4\
**Last updated:** [April 25, 2024, 6:05pm UTC](https://discuss.elastic.co/t/pipeline-to-pipeline-forked-configuration-to-enable-use-of-the-aggregation-filter/358202 "2024-04-25T18:05:21Z")

</div>

I've set up a pipeline to pipeline configuration following advice given in this topic Pipeline.workers configuration and aggregation filter What I'm trying to solve is to be able to use the aggregate filter but not degr…

---

## [Line chart - aggregation based - Can't choose "normal mode"](https://discuss.elastic.co/t/line-chart-aggregation-based-cant-choose-normal-mode/357711)

<div class="topic-metadata">

**Author:** [@JenniferL](https://discuss.elastic.co/u/JenniferL)\
**Replies:** 1\
**Last updated:** [April 22, 2024, 10:43am UTC](https://discuss.elastic.co/t/line-chart-aggregation-based-cant-choose-normal-mode/357711 "2024-04-22T10:43:28Z")

</div>

Hello, I'm actually using Stack Management 7.13.1. I'm trying to do an aggregation based line chart. I'm wondering if there is a way to select the mode "normal" in the metrics while I'm using the "Percentage Mode" on t…

[Next page](https://discuss.elastic.co/tag/aggregations/138.md?match_all_tags=true&page=1&tags%5B%5D=aggregations)
