I want to get average document count by date without getting the whole bunch of buckets data and get average value by hand cause there are years of data and when I group by the date I get too_many_buckets_exception.
So my current query is
"query": {
"bool": {
"must": [],
"filter": []
"aggs": {
"groupByChannle": {
"terms": {
"field": "channel"
"aggs": {
"docs_per_day": {
"date_histogram": {
"field": "message_date",
"fixed_interval": "1d"
How can I get an average doc count grouped by message_date(day) and channel without taking buckets array of this data
"buckets" : [
"key_as_string" : "2018-03-17 00:00:00",
"key" : 1521244800000,
"doc_count" : 4027
"key_as_string" : "2018-03-18 00:00:00",
"key" : 1521331200000,
"doc_count" : 10133
...thousands of rows
my index structure looks like this
"mappings" : {
"properties" : {
"channel" : {
"type" : "keyword"
"message" : {
"type" : "text"
"message_date" : {
"type" : "date",
"format" : "yyyy-MM-dd HH:mm:ss"
By this query, I want to get JUST A AVERAGE DOC COUNT BY DATE and nothing else

"avg_count": {
"avg_bucket": {
"buckets_path": "docs_per_day>_count"
after docs_per_day ending this.
avg_count provides average count.
_count refers the bucket count

I think, that you can use stats aggregation with the script :
"size": 0,
"aggs": {
"term": {
"terms": {
"field": "chanel"
"aggs": {
"stats": {
"stats": {
"field": "message_date"
"result": {
"bucket_script": {
"buckets_path": {
"max" : "stats.max",
"min" : "stats.min",
"count" : "stats.count"
"script": "params.count/(params.max - params.min)/1000/86400)"


Finding intersection of two buckets using Elastic

I have data structured as the following in an elastic index:
[ { customer_id: 1, date_of_purchase: 01-01-2022 },
{ customer_id: 2, date_of_purchase: 01-02-2022 },
{ customer_id: 1, date_of_purchase: 01-02-2022 },
I want to find the numbers of users who have bought something in both September and October, but having issues figuring out how to make a query for this. Any suggestions would rock, thanks!
I have used following aggregations
1. Terms aggregation
2. Bucket selector
3. Date Range
In query I have filtered all documents which either have purchase date in Jan or in Feb. This reduces number of documents for aggregation to work on. In aggregation I have done a group by(terms aggregation) on customer_id and then further grouped documents based on date ranges(1 bucket for each month). Then I have eliminated months(using bucket selector) which have zero documents i.e. with no purchase date in that month and further eliminated customers which have 1 or zero buckets
"query": {
"bool": {
"should": [
"range": {
"date_of_purchase": {
"gte": "2022-01-01",
"lte": "2022-01-31"
"range": {
"date_of_purchase": {
"gte": "2022-02-01",
"lte": "2022-02-28"
"aggs": {
"cutomers": {
"terms": {
"field": "customer_id",
"size": 10
"aggs": {
"range": {
"date_range": {
"field": "date_of_purchase",
"ranges": [
"to": "2022-01-31",
"from": "2022-01-01"
"to": "2022-02-28",
"from": "2022-02-01"
"aggs": {
"filter_months": {
"bucket_selector": {
"buckets_path": {
"script": "params.doc_count>=1"
"bucket_selector": {
"buckets_path": {
"script": "params.bucket_count>1"
"aggregations" : {
"cutomers" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 0,
"buckets" : [
"key" : 1,
"doc_count" : 2,
"range" : {
"buckets" : [
"key" : "2022-01-01T00:00:00.000Z-2022-01-31T00:00:00.000Z",
"from" : 1.6409952E12,
"from_as_string" : "2022-01-01T00:00:00.000Z",
"to" : 1.6435872E12,
"to_as_string" : "2022-01-31T00:00:00.000Z",
"doc_count" : 1
"key" : "2022-02-01T00:00:00.000Z-2022-02-28T00:00:00.000Z",
"from" : 1.6436736E12,
"from_as_string" : "2022-02-01T00:00:00.000Z",
"to" : 1.6460064E12,
"to_as_string" : "2022-02-28T00:00:00.000Z",
"doc_count" : 1

How to filter by sub-aggregated results in Elasticsearch

I've got the following elastic search query in order to get the number of product sales per hour grouped by product id and hour of sale.
POST /my_sales/_search?size=0
"aggs": {
"sales_per_hour": {
"date_histogram": {
"field": "event_time",
"fixed_interval": "1h",
"format": "yyyy-MM-dd:HH:mm"
"aggs": {
"sales_per_hour_per_product": {
"terms": {
"field": "name.keyword"
One example of data :
"#timestamp" : "2020-10-29T18:09:56.921Z",
"name" : "my-beautifull_product",
"event_time" : "2020-10-17T08:01:33.397Z"
This query returns several buckets (one per hour and per product) but i would like to only retrieve those who have a doc_count higher than 10 for example, is it possible ?
For those results i would like to know the id of the product and the event_time bucket.
Thanks for your help.
Perhaps using the Bucket Selector feature will help on filtering out the results.
Try out this below search query:
"aggs": {
"sales_per_hour": {
"date_histogram": {
"field": "event_time",
"fixed_interval": "1h",
"format": "yyyy-MM-dd:HH:mm"
"aggs": {
"sales_per_hour_per_product": {
"terms": {
"field": "name.keyword"
"aggs": {
"the_filter": {
"bucket_selector": {
"buckets_path": {
"the_doc_count": "_count"
"script": "params.the_doc_count > 10"
It will filter out all the documents, whose count is greater than 10 based on "params.the_doc_count > 10"
Thank you for your help this is not far from what i would like but not exactly ; with the bucket selector i have something like this :
"aggregations" : {
"sales_per_hour" : {
"buckets" : [
"key_as_string" : "2020-08-31:23:00",
"key" : 1598914800000,
"doc_count" : 16,
"sales_per_hour_per_product" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 0,
"buckets" : [
"key" : "my_product_1",
"doc_count" : 2
"key" : "my_product_2",
"doc_count" : 2
"key" : "myproduct_3",
"doc_count" : 12
And sometimes none of the buckets are greater than 10, is it possible to have the same thing but with the filter on _count applied to the second level aggregation (sales_per_hour_per_product) and not on the first level (sales_per_hour) ?

How to count number of fields inside nested field? - Elasticsearch

I did the following mapping. I would like to count the number of products in each nested field "products" (for each document separately). I would also like to do a histogram aggregation, so that I would know the number of specific bucket sizes.
PUT /receipts
"mappings": {
"properties": {
"id" : {
"type": "integer"
"user_id" : {
"type": "integer"
"date" : {
"type": "date"
"sum" : {
"type": "double"
"products" : {
"type": "nested",
"properties": {
"name" : {
"type" : "text"
"number" : {
"type" : "double"
"price_single" : {
"type" : "double"
"price_total" : {
"type" : "double"
I've tried this query, but I get the number of all the products instead of number of products for each document separately.
GET /receipts/_search
"query": {
"match_all": {}
"size": 0,
"aggs": {
"terms": {
"nested": {
"path": "products"
"aggs": {
"bucket_size": {
"value_count": {
"field": "products"
Result of the query:
"aggregations" : {
"terms" : {
"doc_count" : 6552,
"bucket_size" : {
"value" : 0
Now I have this code where I make separate buckets for each id and count the number of products inside them.
GET /receipts/_search
"query": {
"match_all": {}
"size" : 0,
"aggs": {
"field": "_id"
"aggs": {
"nested": {
"nested": {
"path": "products"
"aggs": {
"bucket_size": {
"value_count": {
"field": "products.number"
Result of the query:
"aggregations" : {
"terms" : {
"doc_count_error_upper_bound" : 5,
"sum_other_doc_count" : 490,
"buckets" : [
"key" : "1",
"doc_count" : 1,
"nested" : {
"doc_count" : 21,
"bucket_size" : {
"value" : 21
"key" : "10",
"doc_count" : 1,
"nested" : {
"doc_count" : 5,
"bucket_size" : {
"value" : 5
"key" : "100",
"doc_count" : 1,
"nested" : {
"doc_count" : 12,
"bucket_size" : {
"value" : 12
Is is possible to group these values (21, 5, 12, ...) into buckets to make a histogram of them?
products is only the path to the array of individual products, not an aggregatable field. So you'll need to use it on one of your product's field -- such as the number:
GET receipts/_search
"size": 0,
"aggs": {
"terms": {
"nested": {
"path": "products"
"aggs": {
"bucket_size": {
"value_count": {
"field": "products.number"
Note that is a product has no number, it'll not contribute to the total count. It's therefore best practice to always include an ID in each of them and then aggregate on that field.
Alternatively you could use a script to account for missing values. Luckily value_count does not deduplicate -- meaning if two products are alike and/or have empty values, they'll still be counted as two:
GET receipts/_search
"size": 0,
"aggs": {
"terms": {
"nested": {
"path": "products"
"aggs": {
"bucket_size": {
"value_count": {
"script": {
"source": "doc['products.number'].toString()"
You could also use a nested composite aggregation which'll give you the histogrammed product count w/ the corresponding receipt id:
GET /receipts/_search
"size": 0,
"aggs": {
"my_aggs": {
"nested": {
"path": "products"
"aggs": {
"composite_parent": {
"composite": {
"sources": [
"receipt_id": {
"terms": {
"field": "_id"
"product_number": {
"histogram": {
"field": "products.number",
"interval": 1
The interval is modifiable.

Elastic script from buckets and higher level aggregation

I want to compare the daily average of a metric (the frequency of words appearing in texts) to the value of a specific day. This is during a week. My goal is to check whether there's a spike. If the last day is way higher than the daily average, I'd trigger an alarm.
So from my input in Elasticsearch I compute the daily average during the week and find out the value for the last day of that week.
For getting the daily average for the week, I simply cut a week's worth of data using a range query on date field, so all my available data is the given week. I compute the sum and divide by 7 for a daily average.
For getting the last day's value, I did a terms aggregation on the date field with descending order and size 1 as suggested in a different question (How to select the last bucket in a date_histogram selector in Elasticsearch)
The whole output is as follows. Here you can see words "rama0" and "rama1" with their corresponding frequencies.
"aggregations" : {
"the_keywords" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 0,
"buckets" : [
"key" : "rama0",
"doc_count" : 4200,
"the_last_day" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 3600,
"buckets" : [
"key" : 1580169600000,
"key_as_string" : "2020-01-28T00:00:00.000Z",
"doc_count" : 600,
"the_last_day_frequency" : {
"value" : 3000.0
"the_weekly_sum" : {
"value" : 21000.0
"the_daily_average" : {
"value" : 3000.0
"key" : "rama1",
"doc_count" : 4200,
"the_last_day" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 3600,
"buckets" : [
"key" : 1580169600000,
"key_as_string" : "2020-01-28T00:00:00.000Z",
"doc_count" : 600,
"the_last_day_frequency" : {
"value" : 3000.0
"the_weekly_sum" : {
"value" : 21000.0
"the_daily_average" : {
"value" : 3000.0
Now I have the_daily_average in a high level of the output, and the_last_day_frequency in the single-element buckets list in the_last_day aggregation. I cannot use a bucket_script to compare those, because I cannot refer to a single bucket (if I place the script outside the_last_day aggregation) and I cannot refer to higher-level aggregations if I place the script inside the_last_day.
IMO the reasonable thing to do would be to put the script outside the aggregation and use a buckets_path using the <AGG_NAME><MULTIBUCKET_KEY> syntax mentioned in the docs, but I have tried "var1": "the_last_day[1580169600000]>the_last_day_frequency" and variations (hardcoding first until it works), but I haven't been able to refer to a particular bucket.
My ultimate goal is to have a list of keywords for which the last day frequency greatly exceeds the daily average.
For anyone interested, my current query is as follows. Notice that the part I'm struggling with is commented out.
"query": {
"range": {
"date": {
"gte": "START",
"lte": "END"
"aggs": {
"the_keywords": {
"terms": {
"field": "keyword",
"size": 100
"aggs": {
"the_weekly_sum": {
"sum": {
"field": "frequency"
"the_daily_average" : {
"bucket_script": {
"buckets_path": {
"weekly_sum": "the_weekly_sum"
"script": {
"inline": "return params.weekly_sum / 7"
"the_last_day": {
"terms": {
"field": "date",
"size": 1,
"order": {"_key": "desc"}
"aggs": {
"the_last_day_frequency": {
"sum": {
"field": "frequency"
"the_spike": {
"bucket_script": {
"buckets_path": {
"last_day_frequency": "the_last_day>the_last_day_frequency",
"daily_average": "the_daily_average"
"script": {
"inline": "return last_day_frequency / daily_average"
In your query the_last_day>the_last_day_frequency points to a bucket not a single value so it is throwing error. You need to get single metric value from "the_last_day_frequency", you can achieve it using max_bucket. Then you can use bucket_Selector aggregation to compare last day value with average value
"aggs": {
"the_keywords": {
"terms": {
"field": "keyword",
"size": 100
"aggs": {
"the_weekly_sum": {
"sum": {
"field": "frequency"
"the_daily_average": {
"bucket_script": {
"buckets_path": {
"weekly_sum": "the_weekly_sum"
"script": {
"inline": "return params.weekly_sum / 7"
"the_last_day": {
"terms": {
"field": "date",
"size": 1,
"order": {
"_key": "desc"
"aggs": {
"the_last_day_frequency": {
"sum": {
"field": "frequency"
"max_frequency_last_day": {
"max_bucket": {
"buckets_path": "the_last_day>the_last_day_frequency"
"the_spike": {
"bucket_selector": {
"buckets_path": {
"last_day_frequency": "max_frequency_last_day",
"daily_average": "the_daily_average"
"script": {
"inline": "params.last_day_frequency > params.daily_average"

How to aggregate nested fields to include null values?

I'm having trouble aggregating my nested data to include null values as well.
I'm using Elasticsearch version 6.8
I'll simplify the problem, I've a nested field that looks like:
PUT test/doc/_mapping
"properties": {
"fields": {
"type" : "nested",
"properties" : {
"name" : {
"type" : "keyword"
"value" : {
"type" : "long"
I created 3 documents:
PUT test/doc/1
"fields" : {
"name" : "aaa",
"value" : 1
PUT test/doc/2
"fields" : [{
"name" : "aaa",
"value" : 1
"name" : "bbb",
"value" : 2
PUT test/doc/3
"fields" : [
"name" : "bbb",
"value" : 2
Now I want to group my data to get how many documents there are where name="bbb" group by each value.
For the above data I want to get:
2 – 2 documents
N/A – 1 document (the first document where bbb is missing)
The problem is with the null values, I cannot find a way to match the documents where "bbb" is null and put them in a N/A bucket.
So far I wrote a query that match the values where "bbb" exist:
GET test/doc/_search
"size": 0,
"query": {
"match_all": {}
"aggs": {
"my_agg": {
"nested": {
"path": "fields"
"aggs": {
"my_filter": {
"filter": {
"term": {
"fields.name": "bbb"
"aggs": {
"my_term": {
"terms": {
"field": "fields.value"
And the response is:
"aggregations" : {
"my_agg" : {
"doc_count" : 4,
"my_filter" : {
"doc_count" : 2,
"my_term" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 0,
"buckets" : [
"key" : 2,
"doc_count" : 2
I want to get also:
"key" : 0 (for N/A)
"doc_count" : 1
What am I missing?
If I understand this correctly, you want to know the buckets where there was zero/null/no matches. You can use min_doc_count
GET test/doc/_search
"size": ,
"query": {
"match_all": {}
"aggs": {
"my_agg": {
"nested": {
"path": "fields"
"aggs": {
"my_filter": {
"filter": {
"term": {
"fields.name": "bbb"
"aggs": {
"my_term": {
"terms": {
"field": "fields.value", --> you can also use "_id" to get count based on each document
"min_doc_count": 0 --> this will include all the buckets where count is zero/ or there is no match.
You could also use inner_hits to find a hit in each document or use _id in above aggregations query.
POST test/_search
"query": {
"bool": {
"should": [
"match_all": {}
"nested": {
"path": "fields",
"query": {
"match": {
"fields.name": "bbb"
"inner_hits": {}
