# Aggregating on two filter terms or more

**URL:** <https://discuss.elastic.co/t/aggregating-on-two-filter-terms-or-more/302385>\
**Category:** Kibana\
**Tags:** vega\
**Created:** [April 14, 2022, 2:07am UTC](https://discuss.elastic.co/t/aggregating-on-two-filter-terms-or-more/302385 "2022-04-14T02:07:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jack6128](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack6128/32/104376_2.png) [@Jack6128](https://discuss.elastic.co/u/Jack6128)\
**Post date:** [April 14, 2022, 2:07am UTC](https://discuss.elastic.co/t/aggregating-on-two-filter-terms-or-more/302385/1 "2022-04-14T02:07:04Z")

</div>

How can I aggregate on two filter terms (strings) or more based on values stored in the same value column?, at the moment I'm trying to make a dashboard warning lamp based on two alarm events e.g. "door-tamper-1" and "door-tamper-2" and I can easily creat an alarm button for one as follows:

```auto
{
  "$schema": "https://vega.github.io/schema/vega-lite/v4.json",
  "title": { 
    "font": "Arial",
    "fontSize": 15,
    "text": "Door Tamper"
  },
  "height": 100,
  "width": 100,
  "padding": 20,
  "autosize": "none",
  "data": {
    "name": "table",
    "url": {
      "%context%": true,
      "%timefield%": "event_time",
      "index": "event*",
      "body": {
        "aggs": {
          "categories": {
            "filter": {
              "term": {"event_name.keyword": "door-tamper-1" }},
            "aggs": {
              "names": { 
                "terms": {
                  "field": "event_name.keyword"
                }
              }
            }
          }
        }
      },
      "size": 0
    },
    "format": {"property": "aggregations.categories"}
  },
    
  "mark": "circle",
  "encoding": {
    "x": {"value": 31},
    "y": {"value": 30},
    "size": {"value": 2500},
    "shape": {"value": "circle"},
    "opacity": {"value": 1},
    "stroke": {"value": "black"},
    "strokeWidth": {"value": 5},
    "fill": {
      "condition": {"test": "datum.doc_count > 0", 
        "value": "red"},
        "value": "green"
    }
  }
}

```

This lights a door tamper alarm red on a kibana dashboard monitored by guards when someone opens door one, but I need to do it for two doors in the same rooms, events door-tamper-1 and door-tamper-2, that is either or being tampered with.

I tried the following, but obviously, it doesn't work, how would I go about this I have no clue...

```auto
{
  "$schema": "https://vega.github.io/schema/vega-lite/v4.json",
  "title": { 
    "font": "Arial",
    "fontSize": 15,
    "text": "Occupied"
  },
  "height": 100,
  "width": 100,
  "padding": 20,
  "autosize": "none",
  "data": {
    "name": "table",
    "url": {
      "%context%": true,
      "%timefield%": "event_time",
      "index": "event*",
      "body": {
        "aggs": {
          "categories": {
            "filter": {
              "term": {"or": [{"event_name.keyword": "door-tamper-1"},{"event_name.keyword": "door-tamper-2" }]},
            "aggs": {
              "names": { 
                "terms": {
                  "field": "event_name.keyword"
                }
              }
            }
          }
        }
      },
      "size": 0
    },
    "format": {"property": "aggregations.categories"}
  },
    
  "mark": "circle",
  "encoding": {
    "x": {"value": 31},
    "y": {"value": 30},
    "size": {"value": 2500},
    "shape": {"value": "circle"},
    "opacity": {"value": 1},
    "stroke": {"value": "black"},
    "strokeWidth": {"value": 5},
    "fill": {
      "condition": {"test": "datum.doc_count > 0", 
        "value": "red"},
        "value": "green"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [May 4, 2022, 2:58pm UTC](https://discuss.elastic.co/t/aggregating-on-two-filter-terms-or-more/302385/2 "2022-05-04T14:58:17Z")

</div>

I think you want to put the filter out of the aggregation in a `query` section. Something like:

```auto
GET your_index/_search
{
  "size": 0,
  "aggs": {
    "0": {
      "terms": {
        "field": "event_name.keyword"
      }
    }
  },
  "query": {
    "bool": {
      "should": [
        {"match_phrase": {"event_name.keyword": "door-tamper-1"}},
        {"match_phrase": {"event_name.keyword": "door-tamper-2"}},
      ],
      "minimum_should_match": 1
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2022, 2:58pm UTC](https://discuss.elastic.co/t/aggregating-on-two-filter-terms-or-more/302385/3 "2022-06-01T14:58:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
