Composite aggregation

Composite aggregation #

Paginated multi-source bucket aggregation: the composite key is a tuple built from several sources (a terms field, a histogram interval, a date_histogram, a geotile_grid), and pages of buckets are pulled with an after cursor — the way to stream all combinations without oversizing size.

Examples #

Page through merchant × day combinations:

POST /sales/_search
{
  "aggs": {
    "matrix": {
      "composite": {
        "size": 100,
        "sources": [
          { "merchant": { "terms": { "field": "merchant" } } },
          { "day": { "date_histogram": { "field": "date", "calendar_interval": "day" } } }
        ],
        "after": { "merchant": "shop_b", "day": 1700000000000 }
      }
    }
  }
}

Each response page carries an after_key; pass it back as after to fetch the next page, until a page returns no after_key.

Parameters for composite #

  • size
    (Optional, integer, default: 10) Maximum number of composite buckets to return per page.
  • sources
    (Required, array) Source definitions — each produces one dimension of the composite key. Each entry is a named source of one of:
    • terms — distinct values of a field.
    • histogram — numeric buckets of a fixed interval.
    • date_histogram — calendar/fixed interval buckets of a date field (with format/offset/time_zone options).
    • geotile_grid — geo tiles at a precision.
  • after
    (Optional, object) Pagination cursor — the after_key from the previous page.
  • aggs
    (Optional, object) Nested sub-aggregations, computed per bucket.
Calendar September 26, 2026
Edit Edit this page