# Aggregation terms and @timestamp

**URL:** <https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319>\
**Category:** Elasticsearch\
**Created:** [July 8, 2020, 10:21am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319 "2020-07-08T10:21:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [July 8, 2020, 10:21am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319/1 "2020-07-08T10:21:49Z")

</div>

Dears,

Second my problem.  
Is there any way/method to filter doc by timestamp inside aggregation?  
or  
Is there any way/method to filter aggregated doc by timestamp?

My aggregation looks like:

```auto
GET /log-2020.07.07/_search?size=0
{
  "aggs": {
    "rc": {
      "terms": {"field": "ci.rc.keyword","size": 10}
      }
  }
}

```

Regards,  
Dan

---

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [July 8, 2020, 10:28am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319/2 "2020-07-08T10:28:33Z")

</div>

From my point of view such query should looks like:

```auto
POST /logs-2020.07.07/_search?size=0
{
  "query": {
  "bool": {
    "filter": [
      {
        "range": {
          "@timestamp": {
            "gte": "2020-07-07T00:00:01",
            "lte": "2020-07-07T23:59:59"
          }
        }
      }
    ]
  }
  }, 
  "aggs": {
    "rc": {
      "terms": {"field": "ci.rc.keyword","size": 10}
      }
  }
}

```

Am I right?

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [July 8, 2020, 10:34am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319/3 "2020-07-08T10:34:19Z")

</div>

Could you add a query to the search that does the filtering?

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [July 8, 2020, 10:41am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319/4 "2020-07-08T10:41:22Z")

</div>

I think so!

---

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [July 8, 2020, 10:41am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319/5 "2020-07-08T10:41:35Z")

</div>

I have to add timestamp condition to such query:

```auto
GET /log-2020.07.07/_search?size=0
{
  "query": {
    "bool": {
      "should": [
        {
          "query_string": {
            "default_field": "ci.rc",
            "query": "(1??) or (2??)"
          }
        },
        {
          "query_string": {
            "default_field": "ci.rc",
            "query": "(9??)"
          }
        },
        {
          "bool": {
            "must": [
              {
                "regexp": {
                  "ci.rc": "0[0-9]{2}"
                }
              },
              {
                "regexp": {
                  "ci.mti": "[0-9]{2}[3|5|7|9][0-9]{1}"
                }
              }
            ]
          }
        }
      ]
      }
    },
    "aggs": {
      "rc": {
        "terms": {"field": "ci.rc.keyword","size": 10}
      }
    }
  }

```

I try to write query which will:  
count docs which have codes 1?? or 2?? in ci.rc  
and  
count docs which have codes 9?? in ci.rc  
and  
count docs which have codes 0?? in ci.rc and have codes "[0-9]{2}[3|5|7|9][0-9]{1}" in rc.mti

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 10:41am UTC](https://discuss.elastic.co/t/aggregation-terms-and-timestamp/240319/6 "2020-08-05T10:41:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
