# Aggregations response in logstash Elastic search filter

**URL:** <https://discuss.elastic.co/t/aggregations-response-in-logstash-elastic-search-filter/133907>\
**Category:** Logstash\
**Created:** [May 30, 2018, 3:29pm UTC](https://discuss.elastic.co/t/aggregations-response-in-logstash-elastic-search-filter/133907 "2018-05-30T15:29:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![UdaySingh\_Ghadage](https://avatars.discourse-cdn.com/v4/letter/u/ecae2f/32.png) [@UdaySingh\_Ghadage](https://discuss.elastic.co/u/UdaySingh_Ghadage)\
**Post date:** [May 30, 2018, 3:29pm UTC](https://discuss.elastic.co/t/aggregations-response-in-logstash-elastic-search-filter/133907/1 "2018-05-30T15:29:36Z")

</div>

Hi,  
Can you please let me know how my elastic search filter plugin configuration should be:

My query in Query.JSON:

{  
"size": 0,  
"\_source": {  
"excludes": []  
},  
"aggs": {  
"2": {  
"filters": {  
"filters": {  
"JobId:96": {  
"query\_string": {  
"query": "tags:Jobs AND JobId:96",  
"analyze\_wildcard": true,  
"default\_field": "\*"  
}  
}  
}  
},  
"aggs": {  
"StatusTopHits": {  
"top\_hits": {  
"docvalue\_fields": [  
"Status.keyword"  
],  
"\_source": "Status",  
"size": 1,  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
}  
}  
}

In logstash i have configuration as  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index=\> "logstash\_jobs\_\*"  
query\_template =\> "\config\Query.JSON"  
aggregation\_fields =\> { "StatusTopHits" =\> "LastStatus"} // even if i dont add this line its same issue  
fields =\> { "Status" =\> "LastStatus"}  
}  
I am getting null value in LastStatus field.

If i execute query on Kibana i get below resposne with Status 'Completed'. I want to read Status value. Why I am getting nil value from logstash elastic filter?

{  
"took": 8,  
"timed\_out": false,  
"\_shards": {  
"total": 270,  
"successful": 270,  
"skipped": 0,  
"failed": 0  
},  
"hits": {  
"total": 224557,  
"max\_score": 0,  
"hits": []  
},  
"aggregations": {  
"2": {  
"buckets": {  
"JobId:96": {  
"doc\_count": 18,  
"StatusTopHits": {  
"hits": {  
"total": 18,  
"max\_score": null,  
"hits": [  
{  
"\_index": "logstash\_jobs\_in-2018.05.30",  
"\_type": "doc",  
"_id": "kwVEsGMBbXg210lQERu_",  
"\_score": null,  
"\_source": {  
"Status": "Completed"  
},  
"fields": {  
"Status.keyword": [  
"Completed"  
]  
},  
"sort": [  
1527664228390  
]  
}  
]  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2018, 3:29pm UTC](https://discuss.elastic.co/t/aggregations-response-in-logstash-elastic-search-filter/133907/2 "2018-06-27T15:29:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
