Error:Class cast exception in elastic search while sorting buckets in aggregation - sorting

ClassCastException[$Bytes$WithOrdinals$FieldData cannot
be cast to$Numeric]}{[vTHdFzpuTEGMGR8MES_b9g]
My Query:
GET _search
"size" : 0,
"query" : {
"filtered" : {
"query" : {
"dis_max" : {
"tie_breaker" : 0.7,
"queries" : [ {
"bool" : {
"should" : [ {
"match" : {
"post.body" : {
"query" : "check",
"type" : "boolean"
}, {
"match" : {
"post.parentBody" : {
"query" : "check",
"type" : "boolean",
"boost" : 2.0
} ]
} ]
"aggregations" : {
"by_parent_id" : {
"terms" : {
"field" : "post.parentId",
"order" : {
"max_score" : "desc"
"aggregations" : {
"max_score" : {
"max" : {}
"top_post" : {
"top_hits" : {
"size" : 1
I want to sort buckets by max_score rather than by doc_count which is the default behaviour of elastic search.
I am trying to aggregate posts (which contains body and parentBody)
by parentId and then sorting buckets by max_score and in each bucket
I am getting top_hits. But I am getting the above error when I sorted
the buckets by defining max score aggregation. Rest everything works if I remove max_score aggregation. Every post object has parentId, body and parentBody. I have used the following references for coding this:
Elasticsearch Aggregation: How to Sort Bucket Order
Tell me what am I doing wrong? I have shared the query above.


Elasticsearch one field match different values

I want to do a query, with one field match different values,In SQL it likes:
select * from location where address like '%California%' and address like '%145%';
I tried using must condition array, it contains several phrase match conditions, but its doesnt work!
"from" : 0,
"size" : 10,
"query" : {
"bool" : {
"must" : {
"bool" : {
"must" : [ {
"match" : {
"address" : {
"query" : "California",
"type" : "phrase"
}, {
"match" : {
"address" : {
"query" : "145",
"type" : "phrase"
} ]
"sort" : [ {
"pageRankScore" : {
"order" : "desc",
"unmapped_type" : "double"
} ]
Thats my code, it only do a match '145', never match 'California'.
My question is: with several values, how to do a fuzzy match in one field?
Help me, thanks a lot!

ElasticSearch: Get all elements where a parameter is not unique

I know there is an aggregation to get the count of all unique value for a field.
For example
"query" : {
"match_all" : {}
"aggs" : {
"type_count" : {
"cardinality" : {
"field" : "name"
With this query I get the count of all the unique name.
But what I want is the list of all the names that are in the index more than once.
I want all the non unique names.
What is the best way to achieve that?
You can use the terms aggregation with a min_doc_count of 2, like this:
"query" : {
"match_all" : {}
"aggs" : {
"type_count" : {
"terms" : {
"field" : "name",
"min_doc_count": 2

elasticsearch nested functionScoreQuery cannot access parent properties

I have a type in elasticsearch that looks like this:
"hotel" : {
"field" : 1,
"rooms" : [
"type" : "single",
"magicScore" : 1
"type" : "double",
"magicScore" : 2
where rooms is of type nested. I sort using a nested functionScoreQuery:
"query" : {
"filtered" : {
"query" : {
"nested" : {
"query" : {
"function_score" : {
"filter" : {
"match_all" : { }
"functions" : [ {
"script_score" : {
"script" : "return doc['hotel.field'].value"
} ]
"path" : "rooms",
"score_mode" : "max"
Problem is hotel.field returns 0 always. Is there a way to access the parent field inside a nested query? I know I can always pack the field inside the nested document but its a hack not a solution. Would using a dismax query help me?
The query I am actually using looks something like this:
"query" : {
"bool" : {
"must" : {
"nested" : {
"query" : {
"function_score" : {
"query" : {
"not" : {
"query" : {
"terms" : {
"rooms.type" : [ "single", "triple" ]
"functions" : [ {
"script_score" : {
"script" : {
"inline" : "return doc['rooms.magicScore'].value;",
"lang" : "groovy",
"params" : {
"ratings" : {
"sample" : 0.5
"variable" : [ 0.0, 0.0, 0.0, 0.0, -0.5, -2.5]
} ],
"score_mode" : "max"
"path" : "rooms"
"filter" : {
"bool" : {
"filter" : [ {
"bool" : {
"should" : [ {
"term" : {
"cityId" : "166"
}, {
"term" : {
"cityId" : "165"
} ]
}, {
"nested" : {
"query" : {
"not" : {
"query" : {
"terms" : {
"rooms.type" : [ "single", "triple" ]
"path" : "rooms"
} ]
What I am trying to achieve is to access for example the cityId inside the function_score query which is nested.
The question is why are you accessing the parent values in a nested query. Once you are in the nested context, you cannot access parent fields or other fields from other nested fields.
From the documentation:
The nested clause “steps down” into the nested comments field. It no longer has access to fields in the root document, nor fields in any other nested document.
So, rewrite your queries so that the nested part touches the fields in that nested field and anything else is accessed outside the nested part.

Elasticsearch: has_child query with children aggregation - bucket counts are wrong

I'm attempting to find parents based on matches in their children and retrieve children term aggregations for the matches. For some reason, the bucket count for the children aggregation is showing a higher count than actual results (I would be happy if it showed the count of the parents - or the children - in the particular children bucket).
The query is similar to the following (NOTE: I use the filtered query as I will later add a filter in addition to the query):
"query" : {
"filtered" : {
"query" : {
"has_child" : {
"type" : "blog_tag",
"query" : {
"filtered" : {
"query" : {
"term" : {
"tag" : "something"
"aggs" : {
"my_children" : {
"children" : {
"type" : "my_child_type"
"aggs" : {
"field_name" : {
"terms" : {
"field" : { "blog.blog_tag.field_name" }
What is the correct way to do this?
The problem was as noted in the comments. The solution was to filter the aggregation with the query,
"query" : {
"filtered" : {
"query" : {
"has_child" : {
"type" : "blog_tag",
"query" : {
"filtered" : {
"query" : {
"term" : {
"tag" : "something"
"aggs" : {
"my_children" : {
"children" : {
"type" : "my_child_type"
"aggs" : {
"results" : {
"filter" : {
"query" : {
"filtered" : {
"query" : {
"term" : {
"tag" : "something"
"aggs" : {
"field_name" : {
"terms" : {
"field" : { "blog.blog_tag.field_name" }

How can I aggregate filtered nested documents in ElasticSearch?

Suppose I have an index with nested document that looks like this:
"id" : 1234
"cars" : [{
"id" : 987
"name" : "Volkswagen"
}, {
"id": 988
"name" : "Tesla"
I now want to get a count aggregation of "car" documents that match a certain criteria, e.g. that match a search query. My initial attempt was the following query:
"query" : {
"nested" : {
"path" : "cars",
"query" : {
"query_string" : {
"fields" : [""],
"query" : "Tes*"
"aggregations" : {
"cars" :{
"nested" : {
"path" : "cars"
"aggs" : {
"cars" : {
"terms" : {
"field" : ""
I was hoping here to get an aggregation result with only the ids of cars whose name begin with "Tes". However, the aggregation instead uses all cars that are in a top-level document that also contains a matching nested documents. That is, in the above example "Volkswagen" would also be counted because the top-level document also contains a car that does match.
How can I get an aggregation of just the matching nested documents?
In the mean time I've figured it out: to achieve this a filter aggregation should be added around the the terms aggregation like so:
"aggregations" : {
"cars" :{
"nested" : {
"path" : "cars"
"aggs" : {
"cars-filter" : {
"filter" : {
"query" : {
"query_string" : {
"fields" : [""],
"query" : "Tes*"
"aggs" : {
"cars" : {
"terms" : {
"field" : ""
