Bucket sort aggregation

Bucket sort aggregation

A parent pipeline aggregation which sorts the buckets of its parent multi-bucket aggregation. Zero or more sort fields may be specified together with the corresponding sort order. Each bucket may be sorted based on its _key, _count or its sub-aggregations. In addition, parameters from and size may be set in order to truncate the result buckets.

The bucket_sort aggregation, like all pipeline aggregations, is executed after all other non-pipeline aggregations. This means the sorting only applies to whatever buckets are already returned from the parent aggregation. For example, if the parent aggregation is terms and its size is set to 10, the bucket_sort will only sort over those 10 returned term buckets.

Syntax

A bucket_sort aggregation looks like this in isolation:

  1. {
  2. "bucket_sort": {
  3. "sort": [
  4. { "sort_field_1": { "order": "asc" } },
  5. { "sort_field_2": { "order": "desc" } },
  6. "sort_field_3"
  7. ],
  8. "from": 1,
  9. "size": 3
  10. }
  11. }

Here, sort_field_1 is the bucket path to the variable to be used as the primary sort and its order is ascending.

Table 51. bucket_sort Parameters

Parameter NameDescriptionRequiredDefault Value

sort

The list of fields to sort on. See sort for more details.

Optional

from

Buckets in positions prior to the set value will be truncated.

Optional

0

size

The number of buckets to return. Defaults to all buckets of the parent aggregation.

Optional

gap_policy

The policy to apply when gaps are found in the data (see Dealing with gaps in the data for more details)

Optional

skip

The following snippet returns the buckets corresponding to the 3 months with the highest total sales in descending order:

  1. POST /sales/_search
  2. {
  3. "size": 0,
  4. "aggs": {
  5. "sales_per_month": {
  6. "date_histogram": {
  7. "field": "date",
  8. "calendar_interval": "month"
  9. },
  10. "aggs": {
  11. "total_sales": {
  12. "sum": {
  13. "field": "price"
  14. }
  15. },
  16. "sales_bucket_sort": {
  17. "bucket_sort": {
  18. "sort": [
  19. { "total_sales": { "order": "desc" } }
  20. ],
  21. "size": 3
  22. }
  23. }
  24. }
  25. }
  26. }
  27. }

sort is set to use the values of total_sales in descending order

size is set to 3 meaning only the top 3 months in total_sales will be returned

And the following may be the response:

  1. {
  2. "took": 82,
  3. "timed_out": false,
  4. "_shards": ...,
  5. "hits": ...,
  6. "aggregations": {
  7. "sales_per_month": {
  8. "buckets": [
  9. {
  10. "key_as_string": "2015/01/01 00:00:00",
  11. "key": 1420070400000,
  12. "doc_count": 3,
  13. "total_sales": {
  14. "value": 550.0
  15. }
  16. },
  17. {
  18. "key_as_string": "2015/03/01 00:00:00",
  19. "key": 1425168000000,
  20. "doc_count": 2,
  21. "total_sales": {
  22. "value": 375.0
  23. }
  24. },
  25. {
  26. "key_as_string": "2015/02/01 00:00:00",
  27. "key": 1422748800000,
  28. "doc_count": 2,
  29. "total_sales": {
  30. "value": 60.0
  31. }
  32. }
  33. ]
  34. }
  35. }
  36. }

Truncating without sorting

It is also possible to use this aggregation in order to truncate the result buckets without doing any sorting. To do so, just use the from and/or size parameters without specifying sort.

The following example simply truncates the result so that only the second bucket is returned:

  1. POST /sales/_search
  2. {
  3. "size": 0,
  4. "aggs": {
  5. "sales_per_month": {
  6. "date_histogram": {
  7. "field": "date",
  8. "calendar_interval": "month"
  9. },
  10. "aggs": {
  11. "bucket_truncate": {
  12. "bucket_sort": {
  13. "from": 1,
  14. "size": 1
  15. }
  16. }
  17. }
  18. }
  19. }
  20. }

Response:

  1. {
  2. "took": 11,
  3. "timed_out": false,
  4. "_shards": ...,
  5. "hits": ...,
  6. "aggregations": {
  7. "sales_per_month": {
  8. "buckets": [
  9. {
  10. "key_as_string": "2015/02/01 00:00:00",
  11. "key": 1422748800000,
  12. "doc_count": 2
  13. }
  14. ]
  15. }
  16. }
  17. }