# Aggregation return data that do not match query

**URL:** <https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184>\
**Category:** Elasticsearch\
**Created:** [July 12, 2023, 7:46am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184 "2023-07-12T07:46:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Edyta\_Szkiladz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edyta_szkiladz/32/121928_2.png) [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Post date:** [July 12, 2023, 7:46am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184/1 "2023-07-12T07:46:31Z")

</div>

I am trying to do aggregation on documents which contains categories field. Categories is an array of strings. Sample document:

```auto
{
  "_index": "test-v11",
  "_type": "_doc",
  "_id": "954961",
  "_version": 4,
  "_score": 1,
  "_source": {
    "id": 954961,
    "categories": [
      "Patent",
      "Trademark"
    ]
  },
  "fields": {
    "id": [
      "954961"
    ],
    "categories": [
      "Patent",
      "Trademark"
    ],
    "categories.keyword": [
      "Patent",
      "Trademark"
    ]
  }
}

```

When I try to aggregate items by categories in the result I see categories that do not match query. My request:

```auto
POST _search
{
   "aggs":{
      "termBucketAgg":{
         "terms":{
            "field":"categories.keyword",
            "shard_size":65,
            "size":10
         }
      }
   },
   "query":{
      "bool":{
         "must":[
            {
               "query_string":{
                  "fields":[
                     "categories"
                  ],
                  "query":"*trade*"
               }
            }
         ]
      }
   },
   "size":0
}

```

Response:

```auto
"aggregations" : {
    "termBucketAgg" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 806,
      "buckets" : [
        {
          "key" : "Patent",
          "doc_count" : 5436
        },
        {
          "key" : "Trademark",
          "doc_count" : 535
        }
		(...)
      ]
    }
  }

```

"Patent" do not match here, but probably I got it in the resposne because I have a document that have both categories. Any idea how to got only categories that match the query?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 12, 2023, 12:16pm UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184/2 "2023-07-12T12:16:47Z")

</div>

Welcome!

The way it works is that way:

- The query selects the documents which matches
- Then the aggregation aggregates ALL the values for ALL the documents which matched.

The aggregation does not filter the terms based on the query...

You can look at this may be: [Terms aggregation | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_filtering_values_4)

---

<div class="post-metadata">

**Author:** ![Edyta\_Szkiladz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edyta_szkiladz/32/121928_2.png) [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Post date:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184/3 "2023-07-17T09:41:06Z")

</div>

This solve my issue (include part):

```auto
POST _search
{
   "aggs":{
      "termBucketAgg":{
         "terms":{
            "field":"categories.keyword",
            "shard_size":65,
            "size":10,
            "include": ".*[cC][oO][nN].*"
         }
      }
   },
   "query":{
      "bool":{
         "must":[
            {
               "query_string":{
                  "fields":[
                     "categories"
                  ],
                  "query":"*con*"
               }
            }
         ]
      }
   },
   "size":0
}

```

---

<div class="post-metadata">

**Author:** ![Edyta\_Szkiladz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edyta_szkiladz/32/121928_2.png) [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Post date:** [July 17, 2023, 9:42am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184/4 "2023-07-17T09:42:32Z")

</div>

Thank you @dadoonet that helps me to find a solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2023, 9:42am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184/5 "2023-08-14T09:42:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
