I am facing an issue with Elasticsearch.
I would like use the geo distance feature to fetch all the item located N km maximum from a given localization.
Here is my DB schema:
"user_id": "abcde",
"pin" : {
"location" : {
"lat" : 40.12,
"lon" : -71.34
"is_active": true,
"action_zone": 50
I have this query which works pretty well:
"query": {
"bool" : {
"must" :
"term": {
"is_active": True
"filter" : {
"geo_distance" : {
"distance" : "200km",
"pin.location" : {
"lat" : 40,
"lon" : -70
Now, I would like to modify this query a bit to replace dynamically the distance (200km in my example) by the value "action_zone" of each item of in the DB.
That would be great if someone could help me. :)

I found the solution using a script :D Thanks anyway !
"query": {
"bool" : {
"must" :
"term": {
"is_active": True
"script" : {
"script" : {
"params": {
"lat": 40.8,
"lon": -70.1
"source": "doc['location'].arcDistance(params.lat, params.lon) / 1000 < doc['action_zone'].value",
"lang": "painless"
Doc: https://www.elastic.co/guide/en/elasticsearch/reference/6.1/query-dsl-script-query.html

Unfortunately, the geo_distance query doesn't allow to use scripting in order to specify a dynamic distance. What you could do, however, would be to use a terms aggregation on the action_zone field so as to bucket all your documents within a specific action zone.
"query": {
"bool": {
"must": [
"term": {
"is_active": True
"filter": {
"geo_distance": {
"distance": "200km",
"pin.location": {
"lat": 40,
"lon": -70
"aggs": {
"zones": {
"terms": {
"field": "action_zone"
Otherwise, you could also use a range aggregation on the action_zone field with a few specific distances:
"query": {
"bool": {
"must": [
"term": {
"is_active": "True"
"filter": {
"geo_distance": {
"distance": "200km",
"pin.location": {
"lat": 40,
"lon": -70
"aggs": {
"zones": {
"range": {
"field": "action_zone",
"ranges": [
"to": 50
"from": 50,
"to": 100
"from": 100,
"to": 150
"from": 150


In ElasticSearch break down hits per filter?

Given the following query, how can I get the number of hits independently for each range and term query and what are the performance implications for this? As of yet, I can't find anything in the documentation that indicates how to do this. Where can I find the docs for such a feature?
"query": {
"bool" : {
"must" : {
"term" : { "user.id" : "kimchy" }
"filter": {
"term" : { "tags" : "production" }
"must_not" : {
"range" : {
"age" : { "gte" : 10, "lte" : 20 }
You can use filter aggregation for getting document count per query clause. As you are providing query as well, you need to use global aggregation with filter aggregation. If you dont use global aggregation then it will return count based on top level query and you will not able to get total document for specific query clause.
Below is sample query with aggregation:
"query": {
"bool": {
"must": {
"term": {
"user.id": "kimchy"
"filter": {
"term": {
"tags": "production"
"must_not": {
"range": {
"age": {
"gte": 10,
"lte": 20
"aggs": {
"Total": {
"global": {},
"aggs": {
"user_term": {
"filter": {
"term": {
"user.id": "kimchy"
"tag_term": {
"filter": {
"term": {
"tags": "production"
"age_range_not": {
"filter": {
"bool": {
"must_not": {
"range": {
"age": {
"gte": 10,
"lte": 20
"age_range": {
"filter": {
"range": {
"age": {
"gte": 10,
"lte": 20
You will get below response:
"aggregations" : {
"Total" : {
"doc_count" : 3,
"age_range" : {
"doc_count" : 2
"age_range_not" : {
"doc_count" : 1
"tag_term" : {
"doc_count" : 3
"user_term" : {
"doc_count" : 2

ElasticSearch Aggregation Filter (not nested) Array

I have mapping like that:
PUT myindex1/_mapping
"properties": {
"rounds" : {
"properties" : {
"id" : {
"type" : "keyword"
"name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
And my example docs:
POST myindex1/_doc
"program": {
{"id":"00000000-0000-0000-0000-000000000000", "name":"Test1"},
{"id":"00000000-0000-0000-0000-000000000001", "name":"Fact2"}
POST myindex1/_doc
"program": {
{"id":"00000000-0000-0000-0000-000000000002", "name":"Test3"},
{"id":"00000000-0000-0000-0000-000000000003", "name":"Fact4"}
POST myindex1/_doc
"program": {
{"id":"00000000-0000-0000-0000-000000000004", "name":"Test5"},
{"id":"00000000-0000-0000-0000-000000000005", "name":"Fact6"}
Purpose: get only names of rounds that filtered as wildcard by user.
Aggregation query:
GET myindex1/_search
"aggs": {
"result": {
"aggs": {
"names": {
"terms": {
"field": "program.rounds.name.keyword",
"size": 10000,
"order": {
"_key": "asc"
"filter": {
"bool": {
"wildcard": {
"program.rounds.name": "*test*"
"size": 0
This aggregation returns all 6 names, but I need only Test1,Test3,Test5. Also tried include": "/tes.*/i" regex pattern for terms, but ignore case does not work.
Note: I'm note sure abount nested type, because I don't interested in association between Id and Name (at least for now).
ElasticSearch version: 7.7.0
If you want to only aggregate specific rounds based on a condition on the name field, then you need to make rounds nested, otherwise all name values end up in the same field.
Your mapping needs to be changed to this:
PUT myindex1/
"mappings": {
"properties": {
"program": {
"properties": {
"rounds": {
"type": "nested", <--- add this
"properties": {
"id": {
"type": "keyword"
"name": {
"type": "text",
"fields": {
"keyword": {
"type": "keyword",
"ignore_above": 256
And then your query needs to change to this:
GET myindex1/_search
"size": 0,
"query": {
"nested": {
"path": "program.rounds",
"query": {
"bool": {
"must": [
"wildcard": {
"program.rounds.name": "*Test*"
"aggs": {
"rounds": {
"nested": {
"path": "program.rounds"
"aggs": {
"name_filter": {
"filter": {
"wildcard": {
"program.rounds.name": "*Test*"
"aggs": {
"names": {
"terms": {
"field": "program.rounds.name.keyword",
"size": 10000,
"order": {
"_key": "asc"
And the result will be:
"aggregations" : {
"rounds" : {
"doc_count" : 6,
"name_filter" : {
"doc_count" : 3,
"names" : {
"doc_count_error_upper_bound" : 0,
"sum_other_doc_count" : 0,
"buckets" : [
"key" : "Test1",
"doc_count" : 1
"key" : "Test3",
"doc_count" : 1
"key" : "Test5",
"doc_count" : 1
Actually, you can achieve what you want without introducing nested types with the following query. You were close, but the include pattern was wrong
GET myindex1/_search
"aggs": {
"result": {
"aggs": {
"names": {
"terms": {
"field": "program.rounds.name.keyword",
"size": 10000,
"include": "[Tt]est.*",
"order": {
"_key": "asc"
"filter": {
"bool": {
"must": [
"wildcard": {
"program.rounds.name": "*Test*"
"size": 0

Elasticsearch: aggregation and select docs only having max value of field

I am using elastic search 6.5.
Basically, based on my query my index can return multiple documents, I need only those documents which has the max value for a particular field.
"query": {
"bool": {
"must": [
"match": { "header.date" : "2019-07-02" }
"match": { "header.field" : "ABC" }
"bool": {
"should": [
"regexp": { "body.meta.field": "myregex1" }
"regexp": { "body.meta.field": "myregex2" }
"size" : 10000
The above query will return lots of documents/messages as per the query. The sample data returned is:
"header" : {
"id" : "Text_20190702101200123_111",
"date" : "2019-07-02"
"field": "ABC"
"body" : {
"meta" : {
"field" : "myregex1",
"timestamp": "2019-07-02T10:12:00.123Z",
"header" : {
"id" : "Text_20190702151200123_121",
"date" : "2019-07-02"
"field": "ABC"
"body" : {
"meta" : {
"field" : "myregex2",
"timestamp": "2019-07-02T15:12:00.123Z",
"header" : {
"id" : "Text_20190702081200133_124",
"date" : "2019-07-02"
"field": "ABC"
"body" : {
"meta" : {
"field" : "myregex1",
"timestamp": "2019-07-02T08:12:00.133Z",
So based on the above 3 documents, I only want the max timestamp one to be shown i.e. "timestamp": "2019-07-02T15:12:00.123Z"
I only want one document in above example.
I tried doing it as below:
"query": {
"bool": {
"must": [
"match": { "header.date" : "2019-07-02" }
"match": { "header.field" : "ABC" }
"bool": {
"should": [
"regexp": { "body.meta.field": "myregex1" }
"regexp": { "body.meta.field": "myregex2" }
"aggs": {
"group": {
"terms": {
"field": "header.id",
"order": { "group_docs" : "desc" }
"aggs" : {
"group_docs": { "max" : { "field": "body.meta.tiemstamp" } }
"size": "10000"
Executing the above, I am still getting all the 3 documents, instead of only one.
I do get the buckets though, but I need only one of them and not all the buckets.
The output in addition to all the records,
"aggregations": {
"group": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": "Text_20190702151200123_121",
"doc_count": 29,
"group_docs": {
"value": 1564551683867,
"value_as_string": "2019-07-02T15:12:00.123Z"
"key": "Text_20190702101200123_111",
"doc_count": 29,
"group_docs": {
"value": 1564551633912,
"value_as_string": "2019-07-02T10:12:00.123Z"
"key": "Text_20190702081200133_124",
"doc_count": 29,
"group_docs": {
"value": 1564510566971,
"value_as_string": "2019-07-02T08:12:00.133Z"
What am I missing here?
Please note that I can have more than one messages for same timestamp. So I want them all i.e. all the messages/documents belonging to the max time stamp.
In above example there are 29 messages for same timestamp (It can go to any number). So there are 29 * 3 messages being retrieved by my query after using the above aggregation.
Basically I am able to group correctly, I am looking for something like HAVING in SQl?

how do I get the latest document grouped by a field?

I have an index with many documents in this format:
"userId": 1234,
"locationDate" "2016-07-19T19:24:51+0000",
"location": {
"lat": -47.38163,
"lon": 26.38916
In this index I have incremental positions from the user, updated every few seconds.
I would like to execute a search that would return me the latest position (sorted by locationDate) from each user (grouped by userId)
Is this possible with elastic search? the best I could do was get all the positions from the last 30 seconds, using this:
"filtered" : {
"query" : {
"match_all" : { }
"filter" : {
"range" : {
"locationDate" : {
"from" : "2016-07-19T18:54:51+0000",
"to" : null,
"include_lower" : true,
"include_upper" : true
And then after that I sort them out by hand, but I would like to do this directly on elastic search
IMPORTANT: I am using elasticsearch 1.5.2
Try this (with aggregations):
"query": {
"filtered": {
"query": {
"match_all": {}
"filter": {
"range": {
"locationDate": {
"from": "2016-07-19T18:54:51+0000",
"to": null,
"include_lower": true,
"include_upper": true
"aggs": {
"byUser": {
"terms": {
"field": "userId",
"size": 10
"aggs": {
"firstOne": {
"top_hits": {
"size": 1,
"sort": [
"locationDate": {
"order": "desc"

Using aggregation with filters in elastic search

I have an elastic search running with documents like this one:
id: 1,
price: 620000,
propertyType: "HO",
location: {
lat: 51.41999,
lon: -0.14426
active: true,
rentOrSale: "S",
I'm trying to use aggregates to get statistics about a certain area using aggregations and the query I'm using is the following:
"sort": [
"id": "desc"
"query": {
"bool": {
"must": [
"term": {
"rentOrSale": "s"
"term": {
"active": true
"filtered": {
"filter": {
"and": [
"geo_distance": {
"distance": "15.0mi",
"location": {
"lat": 51.50735,
"lon": -0.12776
"aggs": {
"propertytype_agg": {
"terms": {
"field": "propertyType"
"aggs": {
"avg_price": {
"avg": {
"field": "price"
"bed_agg": {
"terms": {
"field": "numberOfBedrooms"
"aggs": {
"avg_price": {
"avg": {
"field": "price"
But in the result I can't see the aggregations. As soon as I remove either the bool or filtered part of the query I can see the aggregations. I can't figure out why this is happening, nor how do I get the aggregations for these filters. I've tried using the answer to this question but I've not been able to solve it. Any ideas?
I think your query need to be slightly re-arranged - move the "filtered" further up and repeat the "query" command:
"query": {
"filtered": {
"query" : {
"bool": {
"filter": {
