# Aggregate query after filter

**URL:** <https://discuss.elastic.co/t/aggregate-query-after-filter/352428>\
**Category:** Kibana\
**Created:** [February 2, 2024, 4:47pm UTC](https://discuss.elastic.co/t/aggregate-query-after-filter/352428 "2024-02-02T16:47:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![akashmaharana93](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@akashmaharana93](https://discuss.elastic.co/u/akashmaharana93)\
**Post date:** [February 2, 2024, 4:47pm UTC](https://discuss.elastic.co/t/aggregate-query-after-filter/352428/1 "2024-02-02T16:47:18Z")

</div>

I want the count of documents post filter in a dataset. So I am invoking a DSL query to do this but not getting any result.

For ex : Count number of error messages in logs for a given date range.

My query for fetching error messages

```auto
GET /_search
{
  "query": {
    "bool": {
      "must": [
        {
          "wildcard": {
            "message.keyword": {
              "value": "*.*UAGE*"
            }
          }
        }
      ],
      "filter": [
        {"range": {
          "@timestamp": {
            "gte": "2024-01-04T00:00:00.000Z",
            "lte": "2024-01-04T23:59:59.000Z"
          }
        }}
      ]
    }
  }
}

```

But i can't able to count the number documents. Please help me here to write the query.

Thanks

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [February 2, 2024, 5:00pm UTC](https://discuss.elastic.co/t/aggregate-query-after-filter/352428/2 "2024-02-02T17:00:15Z")

</div>

> [@akashmaharana93](#):
>
> want the count of documents post filter in a dataset. So I am invoking a DSL query to do this but not getting any result.
> 
> For ex : Count number of error messages in logs for a given date range.
> 
> My query for fetching error messages
> 
> ```auto
> GET /_search
> {
> "query": {
> "bool": {
> "must": [
> {
> "wildcard": {
> "message.keyword": {
> "value": "*.*UAGE*"
> }
> }
> }
> ],
> "filter": [
> {"range": {
> "@timestamp": {
> "gte": "2024-01-04T00:00:00.000Z",
> "lte": "2024-01-04T23:59:59.000Z"
> }
> }}
> ]
> }
> }
> }
> 
> ```
> 
> But i can't able to count the number documents. Please help me here to write the query.
> 
> Thanks

Hi,

you can modify your query to get the count of documents:

```auto
GET /_search
{
  "query": {
    "bool": {
      "must": [
        {
          "wildcard": {
            "message.keyword": {
              "value": "*.*UAGE*"
            }
          }
        }
      ],
      "filter": [
        {"range": {
          "@timestamp": {
            "gte": "2024-01-04T00:00:00.000Z",
            "lte": "2024-01-04T23:59:59.000Z"
          }
        }}
      ]
    }
  },
  "size": 0
}

```

`"size": 0` is added at the end. This tells Elasticsearch to not return any documents in the response, just the metadata which includes the count of matching documents.

Regards

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [February 2, 2024, 5:29pm UTC](https://discuss.elastic.co/t/aggregate-query-after-filter/352428/3 "2024-02-02T17:29:38Z")

</div>

or just hit the `/_count` API endpoint

> **[Count API | Elasticsearch Guide \[8.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-count.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2024, 5:30pm UTC](https://discuss.elastic.co/t/aggregate-query-after-filter/352428/4 "2024-03-01T17:30:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
