# Aggregates filters

**URL:** <https://discuss.elastic.co/t/aggregates-filters/21005>\
**Category:** Elasticsearch\
**Created:** [December 1, 2014, 12:49pm UTC](https://discuss.elastic.co/t/aggregates-filters/21005 "2014-12-01T12:49:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Gardam](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@Robert\_Gardam](https://discuss.elastic.co/u/Robert_Gardam)\
**Post date:** [December 1, 2014, 12:49pm UTC](https://discuss.elastic.co/t/aggregates-filters/21005/1 "2014-12-01T12:49:09Z")

</div>

I have a query that i'm trying to run against ES 1.3.4 and i'm not able to  
use the filters buckets.

Here is my query. It's actually pulled straight from the documentation with  
some small changes.

{  
"aggs" : {  
"messages" : {  
"filters" : {  
"filters" : {  
"errors" : { "term" : { "request" : " blah.json" }},  
"warnings" : { "term" : { "domain" : "blah" }}  
}  
},  
"aggs" : {  
"monthly" : {  
"histogram" : {  
"field" : "timestamp",  
"interval" : "1M"  
}  
}  
}  
}

}  
}

I get back quite a few errors, but this one seems most likely to be the  
most important.

SearchParseException[[logstash-2014.12.01.12][2]: from[-1],size[-1]: Parse  
Failure [Could not find aggregator type [filters] in [messages]]]; }]",  
"status": 400

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/62353474-16e9-4c5d-9a26-b552e3617ccc%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/62353474-16e9-4c5d-9a26-b552e3617ccc%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [December 2, 2014, 8:37am UTC](https://discuss.elastic.co/t/aggregates-filters/21005/2 "2014-12-02T08:37:11Z")

</div>

Hi Robert,

The filters aggregation was added in version 1.4. As you are running 1.3.4,  
you will need to upgrade your Elasticsearch cluster if you want to make use  
of it

Colin

On Monday, 1 December 2014 12:49:09 UTC, Robert Gardam wrote:

> I have a query that i'm trying to run against ES 1.3.4 and i'm not able to  
> use the filters buckets.
> 
> Here is my query. It's actually pulled straight from the documentation  
> with some small changes.
> 
> {  
> "aggs" : {  
> "messages" : {  
> "filters" : {  
> "filters" : {  
> "errors" : { "term" : { "request" : " blah.json" }},  
> "warnings" : { "term" : { "domain" : "blah" }}  
> }  
> },  
> "aggs" : {  
> "monthly" : {  
> "histogram" : {  
> "field" : "timestamp",  
> "interval" : "1M"  
> }  
> }  
> }  
> }
> 
> }  
> }
> 
> I get back quite a few errors, but this one seems most likely to be the  
> most important.
> 
> SearchParseException[[logstash-2014.12.01.12][2]: from[-1],size[-1]: Parse  
> Failure [Could not find aggregator type [filters] in [messages]]]; }]",  
> "status": 400

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5ebb0af2-1224-4b8d-b6e9-dfbe054ade9d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5ebb0af2-1224-4b8d-b6e9-dfbe054ade9d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:46am UTC](https://discuss.elastic.co/t/aggregates-filters/21005/3 "2017-07-06T00:46:40Z")

</div>


