Elasticsearch Terms or Cardinality Aggregation - Order by number of distinct values - elasticsearch

I am doing some analysis to find unique pairs from 100s of millions of documents. The mock example is as shown below:
doc field1 field2
90% of the document contains an unique pair as shown above in doc 3, 4, 5, 6 and 7 which I am not interested on my aggregation result. I am interested to aggregate doc 1 and 2.
Terms Aggregation Query:
"aggs": {
"f1": {
"terms": {
"field": "FIELD1",
"min_doc_count": 2
"aggs": {
"f2": {
"terms": {
"field": "FIELD2"
Term Aggregation Result
"aggregations": {
"f1": {
"buckets": [
"key": "PPP",
"doc_count": 2,
"f2": {
"buckets": [
"key": "QQQ",
"doc_count": 2
"key": "XXX",
"doc_count": 2,
"f2": {
"buckets": [
"key": "YYY",
"doc_count": 2
"key": "AAA",
"doc_count": 2,
"f2": {
"buckets": [
"key": "BBB",
"doc_count": 1
"key": "CCC",
"doc_count": 1
I am interested only on key AAA to be in the aggregation result. What is the best way to filter the aggregation result containing distinct pairs?
I tried with cardinality aggregation which result unque value count. However I am not able to filter out what I am not interested from the aggregation results.
Cardinality Aggregation Query
"aggs": {
"f1": {
"terms": {
"field": "FIELD1",
"min_doc_count": 2
"aggs": {
"f2": {
"cardinality": {
"field": "FIELD2"
Cardinality Aggregation Result
"aggregations": {
"f1": {
"buckets": [
"key": "PPP",
"doc_count": 2,
"f2": {
"value" : 1
"key": "XXX",
"doc_count": 2,
"f2": {
"value" : 1
"key": "AAA",
"doc_count": 2,
"f2": {
"value" : 2
Atleast if I could sort by cardinal value, that would be help me to find some workarounds. Please help me in this regard.
P.S: Writing a spark/mapreduce program to post process/filter the aggregation result is not expected solution for this issue.

I suggest to use filter query along with aggregations, since you are only interested in field1=AAA.
I have a similar example here.
For example, I have an index of all patients in my hospital. I store their drug use in a nested object DRUG. Each patient could take different drugs, and each could take a single drug for multiple times.
Now if I wanted to find the number of patients who took aspirin at least once, the query could be:
"size": 0,
"_source": false,
"query": {
"filtered": {
"query": {
"match_all": {}
"filter": {
"nested": {
"path": "DRUG",
"filter": {
"bool": {
"must": [{ "term": { "DRUG.NAME": "aspirin" } }]
"aggs": {
"nested": {
"path": "DRUG"
"aggs": {
"terms": { "field": "DRUG.NAME", "size": 0 },
"aggs": {
"DISTINCT": { "cardinality": { "field": "DRUG.PATIENT" } }
Sample result:
"took": 6,
"timed_out": false,
"_shards": {
"total": 5,
"successful": 5,
"failed": 0
"hits": {
"total": 6,
"max_score": 0,
"hits": []
"aggregations": {
"doc_count": 11,
"buckets": [
"key": "aspirin",
"doc_count": 6,
"value": 6
"key": "vitamin-b",
"doc_count": 3,
"value": 2
"key": "vitamin-c",
"doc_count": 2,
"value": 2
The first one in the buckets would be aspirin. But you can see other 2 patients had also taken vitamin-b when they took aspirin.
If you change the field value of DRUG.NAME to another drug name for example "vitamin-b", I suppose you would get vitamin-b in the first position of the buckets.
Hopefully this is helpful to your question.

A bit late, hope it would help for others.
A simple approach is to filter only 'AAA' records in top aggregation:
"size": 0,
"aggregations": {
"filterAAA": {
"filter": {
"term": {
"aggregations": {
"f1": {
"terms": {
"field": "FIELD1",
"min_doc_count": 2
"aggregations": {
"f2": {
"terms": {
"field": "FIELD2"


Nested array of objects aggregation in Elasticsearch

Documents in the Elasticsearch are indexed as such
Document 1
"task_completed": 10
"tagged_object": [
"category": "cat",
"count": 10
"category": "cars",
"count": 20
Document 2
"task_completed": 50
"tagged_object": [
"category": "cars",
"count": 100
"category": "dog",
"count": 5
As you can see that the value of the category key is dynamic in nature. I want to perform a similar aggregation like in SQL with the group by category and return the sum of the count of each category.
In the above example, the aggregation should return
cat: 10,
cars: 120 and
dog: 5
Wanted to know how to write this aggregation query in Elasticsearch if it is possible. Thanks in advance.
You can achieve your required result, using nested, terms, and sum aggregation.
Adding a working example with index mapping, search query and search result
Index Mapping:
"mappings": {
"properties": {
"tagged_object": {
"type": "nested"
Search Query:
"size": 0,
"aggs": {
"resellers": {
"nested": {
"path": "tagged_object"
"aggs": {
"books": {
"terms": {
"field": "tagged_object.category.keyword"
Search Result:
"aggregations": {
"resellers": {
"doc_count": 4,
"books": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": "cars",
"doc_count": 2,
"sum_of_count": {
"value": 120.0
"key": "cat",
"doc_count": 1,
"sum_of_count": {
"value": 10.0
"key": "dog",
"doc_count": 1,
"sum_of_count": {
"value": 5.0

Elasticsearch: Querying nested objects

Dear elasticsearch experts,
i have a problem querying nested objects. Lets use the following simplified mapping:
"mappings" : {
"_doc" : {
"properties" : {
"companies" : {
"type": "nested",
"properties" : {
"company_id": { "type": "long" },
"name": { "type": "text" }
"title": { "type": "text" }
And put some documents in the index:
PUT my_index/_doc/1
"title" : "CPU release",
"companies" : [
{ "company_id" : 1, "name" : "AMD" },
{ "company_id" : 2, "name" : "Intel" }
PUT my_index/_doc/2
"title" : "GPU release 2018-01-10",
"companies" : [
{ "company_id" : 1, "name" : "AMD" },
{ "company_id" : 3, "name" : "Nvidia" }
PUT my_index/_doc/3
"title" : "GPU release 2018-03-01",
"companies" : [
{ "company_id" : 3, "name" : "Nvidia" }
PUT my_index/_doc/4
"title" : "Chipset release",
"companies" : [
{ "company_id" : 2, "name" : "Intel" }
Now i want to execute queries like this:
"query": {
"bool": {
"must": [
{ "match": { "title": "GPU" } },
{ "nested": {
"path": "companies",
"query": {
"bool": {
"must": [
{ "match": { "companies.name": "AMD" } }
"inner_hits" : {}
As result I want to get the matching companies with the number of matching documents. So the above query should give me:
{ "company_id" : 1, "name" : "AMD", "matched_documents:": 1 }
The following query:
"query": {
"bool": {
"must": [
{ "match": { "title": "GPU" } }
{ "nested": {
"path": "companies",
"query": { "match_all": {} },
"inner_hits" : {}
should give me all companies assigned to a document whichs title contains "GPU" with the number of matching documents:
{ "company_id" : 1, "name" : "AMD", "matched_documents:": 1 },
{ "company_id" : 3, "name" : "Nvidia", "matched_documents:": 2 }
Is there any possibility with good performance to achieve this result? I'm explicitly not interested in the matching documents, only in the number of matched documents and the nested objects.
Thanks for your help.
What you need to do in terms of Elasticsearch is:
filter "parent" documents on desired criteria (like having GPU in title, or also mentioning Nvidia in the companies list);
group "nested" documents by a certain criteria, a bucket (e.g. company_id);
count how many "nested" documents there are per each bucket.
Each of the nested objects in the array are indexed as a separate hidden document, which complicates life a bit. Let's see how to aggregate on them.
So how to aggregate and count the nested documents?
You can achieve this with a combination of a nested, terms and top_hits aggregation:
POST my_index/doc/_search
"query": {
"bool": {
"must": [
"match": {
"title": "GPU"
"nested": {
"path": "companies",
"query": {
"match_all": {}
"aggs": {
"Extract nested": {
"nested": {
"path": "companies"
"aggs": {
"By company id": {
"terms": {
"field": "companies.company_id"
"aggs": {
"Examples of such company_id": {
"top_hits": {
"size": 1
This will give the following output:
"hits": { ... },
"aggregations": {
"Extract nested": {
"doc_count": 4, <== How many "nested" documents there were?
"By company id": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": 3, <== this bucket's key: "company_id": 3
"doc_count": 2, <== how many "nested" documents there were with such company_id?
"Examples of such company_id": {
"hits": {
"total": 2,
"max_score": 1.5897496,
"hits": [ <== an example, "top hit" for such company_id
"_nested": {
"field": "companies",
"offset": 1
"_score": 1.5897496,
"_source": {
"company_id": 3,
"name": "Nvidia"
"key": 1,
"doc_count": 1,
"Examples of such company_id": {
"hits": {
"total": 1,
"max_score": 1.5897496,
"hits": [
"_nested": {
"field": "companies",
"offset": 0
"_score": 1.5897496,
"_source": {
"company_id": 1,
"name": "AMD"
Notice that for Nvidia we have "doc_count": 2.
But what if we want to count the number of "parent" objects who's got Nvidia vs Intel?
What if we want to count parent objects based on a nested bucket?
It can be achieved with reverse_nested aggregation.
We need to change our query just a little bit:
POST my_index/doc/_search
"query": { ... },
"aggs": {
"Extract nested": {
"nested": {
"path": "companies"
"aggs": {
"By company id": {
"terms": {
"field": "companies.company_id"
"aggs": {
"Examples of such company_id": {
"top_hits": {
"size": 1
"original doc count": { <== we ask ES to count how many there are parent docs
"reverse_nested": {}
The result will look like this:
"hits": { ... },
"aggregations": {
"Extract nested": {
"doc_count": 3,
"By company id": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": 3,
"doc_count": 2,
"original doc count": {
"doc_count": 2 <== how many "parent" documents have such company_id
"Examples of such company_id": {
"hits": {
"total": 2,
"max_score": 1.5897496,
"hits": [
"_nested": {
"field": "companies",
"offset": 1
"_score": 1.5897496,
"_source": {
"company_id": 3,
"name": "Nvidia"
"key": 1,
"doc_count": 1,
"original doc count": {
"doc_count": 1
"Examples of such company_id": {
"hits": {
"total": 1,
"max_score": 1.5897496,
"hits": [
"_nested": {
"field": "companies",
"offset": 0
"_score": 1.5897496,
"_source": {
"company_id": 1,
"name": "AMD"
How can I spot the difference?
To make the difference evident, let's change the data a bit and add another Nvidia item in the document list:
PUT my_index/doc/2
"title" : "GPU release 2018-01-10",
"companies" : [
{ "company_id" : 1, "name" : "AMD" },
{ "company_id" : 3, "name" : "Nvidia" },
{ "company_id" : 3, "name" : "Nvidia" }
The last query (the one with reverse_nested) will give us the following:
"By company id": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": 3,
"doc_count": 3, <== 3 "nested" documents with Nvidia
"original doc count": {
"doc_count": 2 <== but only 2 "parent" documents
"Examples of such company_id": {
"hits": {
"total": 3,
"max_score": 1.5897496,
"hits": [
"_nested": {
"field": "companies",
"offset": 2
"_score": 1.5897496,
"_source": {
"company_id": 3,
"name": "Nvidia"
As you can see, this is a subtle difference that is hard to grasp, but it changes the semantics completely.
What's about performance?
While for most of the cases the performance of nested query and aggregations should be enough, of course it comes with a certain cost. It is therefore recommended to avoid using nested or parent-child types when tuning for search speed.
In Elasticsearch the best performance is often achieved through denormalization, although there is no single recipe and you should select the data model depending on your needs.
Hope this clarifies this nested thing for you a bit!

Is it possible to returns other fields when you aggregate results on Elasticsearch?

Here is the mappings of my index PublicationsLikes:
id : String
account : String
api : String
date : Date
I'm currently making an aggregation on ES where I group the results counts by the id (of the publication).
"key": "<publicationId-1>",
"doc_count": 25
"key": "<publicationId-2>",
"doc_count": 387
"key": "<publicationId-3>",
"doc_count": 7831
The returned "key" (the id) is an information but I also need to select another fields of the publication like account and api. A bit like that:
"key": "<publicationId-1>",
"api": "Facebook",
"accountId": "65465z4fe6ezf456ezdf",
"doc_count": 25
"key": "<publicationId-2>",
"api": "Twitter",
"accountId": "afaez5f4eaz",
"doc_count": 387
How can I manage this?
This requirement is best achieved by top_hits aggregation, where you can sort the documents in each bucket and choose the first and also you can control which fields you want returned:
"size": 0,
"aggs": {
"publications": {
"terms": {
"field": "id"
"aggs": {
"sample": {
"top_hits": {
"size": 1,
"_source": ["api","accountId"]
You can use subaggregation for this.
GET /PublicationsLikes/_search
"aggs" : {
"ids": {
"terms": {
"field": "id"
"aggs": {
"accounts": {
"terms": {
"field": "account",
"size": 1
Your result will not exactly what you want but it will be a bit similar:
"key": "<publicationId-1>",
"doc_count": 25,
"accounts": {
"buckets": [
"key": "<account-1>",
"doc_count": 25
"key": "<publicationId-2>",
"doc_count": 387,
"accounts": {
"buckets": [
"key": "<account-2>",
"doc_count": 387
"key": "<publicationId-3>",
"doc_count": 7831,
"accounts": {
"buckets": [
"key": "<account-3>",
"doc_count": 7831
You can also check the link to find more information
Thanks both for your quick replies. I think the first solution is the most "beautiful" (in terms of request but also to retrieves the results) but both seems to be sub aggregations queries.
"size": 0,
"aggs": {
"publications": {
"terms": {
"size": 0,
"field": "publicationId"
"aggs": {
"sample": {
"top_hits": {
"size": 1,
"_source": ["accountId", "api"]
I think I must be careful to size=0 parameter, so, because I work in the Java Api, I decided to put INT.Max instead of 0.
Thnaks a lot guys.

Why is my query ignoring my filter aggregation?

I have 4 days experience of Elasticsearch 1.7.2.
I have a collection of documents, each document is a User. The User has a number of Answers which is linked through UserAnswers. Which gives a document reference of user_answers.answer[]. Where the answers array is an array of objects.
The user_answers.answer[].correct is a boolean field which tells me if the answer given by the user is correct or not.
I would like to list the users and also display the total number of correct and incorrect answers they have.
So far I have tried a number of different approaches and the one I'll include here is as close as I've got so far in 1.5 days of trying.
Use a terms aggregation to create a bucket for each User by username.
Filter each bucket to leave only correct or incorrect answers.
Count the number of filtered answers.
"size": 0,
"filter": {
"bool": {
"must_not": {
// Remove users who already have this award
"term": {"awards_users.award_id": 2}
"aggs": {
"users": {
"terms": {"field": "username"},
"aggs": {
"correct": {
"filter": {
"term": {"user_answers.answer.correct": true}
"aggs": {
"count": {
"value_count": {
"field": "user_answers.answer.id"
// Same for incorrect, but inverted correct value
Sample response
"key": "neon1024",
"doc_count": 1,
"correct": {
"doc_count": 1,
"count": {
"value": 7 // Expected 1 correct & 6 incorrect
This is the record which I am testing against, and I am expecting that 1 is returned instead of 7. There are 7 answers in total, 6 incorrect and 1 correct. This I have verified in my document index.
The problem
For some reason the actual filter seems to be being ignored, and leaving all possible related answers in the bucket. Hence the aggregation is seeing them all, rather than showing the expected value.
How can I use an aggregation to segregate my counts based on the value of the related answers values?
Thanks for reading my long question!
As suggested, you probably have your answers mapped as object, while you should be using nested type.
Using nested type, elasticsearch will store your answers as individual documents linked to the root one and will let you do expected aggregations on them. You'll have to use nested type aggregation in your query to achieve that.
So I'd say it would be best to map your document like this:
PUT /test
"mappings" : {
"your_type" : {
"properties" : {
"username" : {
"type" : "string",
"index" : "not_analyzed"
"user_answers" : {
"type" : "nested",
"properties" : {
"id" : {
"type" : "integer"
"answer" : {
"type" : "string"
"correct" : {
"type" : "boolean"
Test document:
PUT /test/your_type/1
"username": "neon1024",
"user_answers": [
"id": 1,
"answer": "answer1",
"correct": true
"id": 2,
"answer": "answer2",
"correct": true
"id": 3,
"answer": "answer3",
"correct": false
POST /test/_search?search_type=count
"aggs": {
"users": {
"terms": {
"field": "username"
"aggs": {
"DiveIn": {
"nested": {
"path": "user_answers"
"aggs": {
"CorrectVsIncorrect": {
"terms": {
"field": "user_answers.correct",
"size": 2
And Final result:
"took": 6,
"timed_out": false,
"_shards": {
"total": 5,
"successful": 5,
"failed": 0
"hits": {
"total": 1,
"max_score": 0,
"hits": []
"aggregations": {
"users": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": "neon1024",
"doc_count": 1,
"DiveIn": {
"doc_count": 3,
"CorrectVsIncorrect": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": "T",
"doc_count": 2
"key": "F",
"doc_count": 1
Where "key": "T" represents correct answers and "doc_count": 2 represents amount of them.

Limit aggregations to list of values

Can I limit aggregations to return only specific list of values? I have something like this:
{ "aggs" : {
"province" : {
"terms" : {
"field" : "province"
"query": {
"bool": {
//my query..
But let's say I know list of province for which I want make count ({'province1', 'province2', 'province3'}). Is it possible to restrict returned list of province without influence on my query results?
I want to get:
//list of hits..
"aggregations": {
"province": {
"buckets": [
"key": "province1",
"doc_count": 200
"key": "province2",
"doc_count": 162
"key": "province3",
"doc_count": 162
// even if there is more possible provinces
// I don't want to see them
Sure, just use term filters.
Here's an example. Let's say I have visit stats for a bunch of different IP addresses, but I only want to get counts of document for two of them, I could do this:
POST /test_index/_search?search_type=count
"aggregations": {
"ip": {
"terms": {
"field": "ip",
"size": 10,
"include": [
and get back something like:
"took": 4,
"timed_out": false,
"_shards": {
"total": 1,
"successful": 1,
"failed": 0
"hits": {
"total": 7,
"max_score": 0,
"hits": []
"aggregations": {
"ip": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": [
"key": "",
"doc_count": 3
"key": "",
"doc_count": 3
Here is some code I used to play around with it:
So your example might look like:
"aggs": {
"province": {
"terms": {
"field": "province",
"include": [
