# Aggregations: How to get a only the entries with latest status 'nok' and nothing else

**URL:** <https://discuss.elastic.co/t/aggregations-how-to-get-a-only-the-entries-with-latest-status-nok-and-nothing-else/16372>\
**Category:** Elasticsearch\
**Created:** [March 14, 2014, 8:50am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-a-only-the-entries-with-latest-status-nok-and-nothing-else/16372 "2014-03-14T08:50:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sven\_Beauprez](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@Sven\_Beauprez](https://discuss.elastic.co/u/Sven_Beauprez)\
**Post date:** [March 14, 2014, 8:50am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-a-only-the-entries-with-latest-status-nok-and-nothing-else/16372/1 "2014-03-14T08:50:57Z")

</div>

Suppose I have following mapping for documents  
\_timestamp: ES timestamp enabled  
mod\_id : string (a unique ID for a module, not the same as \_id field from  
ES)  
status\_code : integer (similar as to HTTP codes where 200 is ok and all  
else is nok)

With following aggregation, I get for all modules (buckets) an aggregation  
of the status codes, with the latest submitted status code on top:

"aggs": {  
"by\_module": {  
"terms": {  
"field": "mod\_id"  
},  
"aggs": {  
"by\_status": {  
"terms": {  
"field": "status\_code",  
"order": {  
"max\_time": "desc"  
}  
},  
"aggs": {  
"max\_time": {  
"max": {  
"field": "\_timestamp"  
}  
}  
}  
}  
}  
}  
}

result:  
"aggregations": {  
"by\_module": {  
"buckets": [  
{  
"key": "ModuleUniqueID12",  
"doc\_count": 4,  
"by\_status": {  
"buckets": [  
{  
"key": 503,  
"doc\_count": 2,  
"max\_time": {  
"value": 1394750966731  
}  
},  
{  
"key": 200,  
"doc\_count": 2,  
"max\_time": {  
"value": 1394745749862  
}  
}  
]  
}  
},  
{  
"key": "ModuleUniqueID1",  
"doc\_count": 2,  
"by\_status": {  
"buckets": [  
{  
"key": 200,  
"doc\_count": 2,  
"max\_time": {  
"value": 1394729958485  
}  
}  
]  
}  
},

```
        ... //and so on
    ]
  }

```

}

What I want now is only the documents where the latest (-\> this is the hard  
part) entries for a module contains a status\_code that is not ok, ie. and  
the above resultset I would only get the document with mod\_id  
"ModuleUniqueID12", because the latest entry added to ES has a status\_code  
of 503.

Can this be filtered combined with the 'max\_time' aggregation metric for  
example? Any other ways? How would I use the 'max\_time' metric in a script?

thnx!

Sven

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/601181d2-6888-47f6-bf95-6b7708a587b3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/601181d2-6888-47f6-bf95-6b7708a587b3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Sven\_Beauprez](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@Sven\_Beauprez](https://discuss.elastic.co/u/Sven_Beauprez)\
**Post date:** [March 14, 2014, 10:31am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-a-only-the-entries-with-latest-status-nok-and-nothing-else/16372/2 "2014-03-14T10:31:09Z")

</div>

It might be related to [Issues · elastic/elasticsearch · GitHub](http://github.com/elasticsearch/elasticsearch/issues/4404but) it seems that that is not yet implemented. So a solution that works  
with 1.0 version would be welcome.

regards,

Sven

On Friday, March 14, 2014 9:50:57 AM UTC+1, Sven Beauprez wrote:

> Suppose I have following mapping for documents  
> \_timestamp: ES timestamp enabled  
> mod\_id : string (a unique ID for a module, not the same as \_id field from  
> ES)  
> status\_code : integer (similar as to HTTP codes where 200 is ok and all  
> else is nok)
> 
> With following aggregation, I get for all modules (buckets) an aggregation  
> of the status codes, with the latest submitted status code on top:
> 
> "aggs": {  
> "by\_module": {  
> "terms": {  
> "field": "mod\_id"  
> },  
> "aggs": {  
> "by\_status": {  
> "terms": {  
> "field": "status\_code",  
> "order": {  
> "max\_time": "desc"  
> }  
> },  
> "aggs": {  
> "max\_time": {  
> "max": {  
> "field": "\_timestamp"  
> }  
> }  
> }  
> }  
> }  
> }  
> }
> 
> result:  
> "aggregations": {  
> "by\_module": {  
> "buckets": [  
> {  
> "key": "ModuleUniqueID12",  
> "doc\_count": 4,  
> "by\_status": {  
> "buckets": [  
> {  
> "key": 503,  
> "doc\_count": 2,  
> "max\_time": {  
> "value": 1394750966731  
> }  
> },  
> {  
> "key": 200,  
> "doc\_count": 2,  
> "max\_time": {  
> "value": 1394745749862  
> }  
> }  
> ]  
> }  
> },  
> {  
> "key": "ModuleUniqueID1",  
> "doc\_count": 2,  
> "by\_status": {  
> "buckets": [  
> {  
> "key": 200,  
> "doc\_count": 2,  
> "max\_time": {  
> "value": 1394729958485  
> }  
> }  
> ]  
> }  
> },
> 
> ```
> ... //and so on
> ]
> }
> 
> ```
> 
> }
> 
> What I want now is only the documents where the latest (-\> this is the  
> hard part) entries for a module contains a status\_code that is not ok, ie.  
> and the above resultset I would only get the document with mod\_id  
> "ModuleUniqueID12", because the latest entry added to ES has a status\_code  
> of 503.
> 
> Can this be filtered combined with the 'max\_time' aggregation metric for  
> example? Any other ways? How would I use the 'max\_time' metric in a script?
> 
> thnx!
> 
> Sven

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/322f9d73-9743-4380-b5e8-c26c997de5cd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/322f9d73-9743-4380-b5e8-c26c997de5cd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-a-only-the-entries-with-latest-status-nok-and-nothing-else/16372/3 "2017-07-06T01:43:11Z")

</div>


