# Agggregation question

**URL:** <https://discuss.elastic.co/t/agggregation-question/105559>\
**Category:** Elasticsearch\
**Created:** [October 27, 2017, 11:38am UTC](https://discuss.elastic.co/t/agggregation-question/105559 "2017-10-27T11:38:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [October 27, 2017, 11:38am UTC](https://discuss.elastic.co/t/agggregation-question/105559/1 "2017-10-27T11:38:04Z")

</div>

Hi All,

I have the below aggregation and I wonder if it is possible to do the aggregation only when the hdr\_subject has 10 or more documents in that time frame. Is it possible to apply a filter of some sort?

```
{
  "size": 0,
  "aggs": {
    "2": {
      "terms": {
        "field": "hdr_subject.keyword",
        "size": 10,
        "order": {
          "_count": "desc"
        }
      },
      "aggs": {
        "3": {
          "terms": {
            "field": "ip",
            "size": 10,
            "order": {
              "_count": "desc"
            }
          }
        }
      }
    }
  },
  "version": true,
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "program:GW AND EnvID:p-xxxxn AND action:P6_ACCEPT_DEFAULT AND _exists_:hdr_subject AND cm_score: [0 TO 90] AND NOT dkim:pass*"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": 1509086400000,
              "lte": 1509086731668,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": [
        {
          "bool": {
            "minimum_should_match": 1,
            "should": [
              {
                "match_phrase": {
                  "hdr_from": "gruppiotthon"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "gruppiajandek.hu"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "telekom.hu"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "szallas.hu"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "hvg.hu"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "kreativhobby.hu"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "spartoo.hu"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "vizionet.cz"
                }
              },
              {
                "match_phrase": {
                  "hdr_from": "forum-media.hu"
                }
              }
            ]
          }
        }
      ]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [October 27, 2017, 2:24pm UTC](https://discuss.elastic.co/t/agggregation-question/105559/2 "2017-10-27T14:24:21Z")

</div>

it is as simple as "min\_doc\_count": 10,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2017, 2:24pm UTC](https://discuss.elastic.co/t/agggregation-question/105559/3 "2017-11-24T14:24:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
