# Aggs not working on the current date

**URL:** <https://discuss.elastic.co/t/aggs-not-working-on-the-current-date/151874>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 10, 2018, 3:07pm UTC](https://discuss.elastic.co/t/aggs-not-working-on-the-current-date/151874 "2018-10-10T15:07:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexgohberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexgohberg/32/36077_2.png) [@alexgohberg](https://discuss.elastic.co/u/alexgohberg)\
**Post date:** [October 10, 2018, 3:07pm UTC](https://discuss.elastic.co/t/aggs-not-working-on-the-current-date/151874/1 "2018-10-10T15:07:22Z")

</div>

> Hey all  
> Im trying to aggregate the message field when im trying the next query in DEV TOOLS its working fine:

```
GET filebeat-6.3.2-2018.10.09/_search
{
    "aggs" : {
        "message.keyword" : {
            "terms" : { "field" : "message.keyword" }
        }
    }
}

```

The result is:

```
   aggregations": {
        "message.keyword": {
          "doc_count_error_upper_bound": 141454,
          "sum_other_doc_count": 21714432,
          "buckets": [
            {
              "key": "",
              "doc_count": 2175665
            }

```

> But when im changing the date to the current one its not returning any results for the aggregation:

```
GET filebeat-6.3.2-2018.10.10/_search
{
    "aggs" : {
        "message.keyword" : {
            "terms" : { "field" : "message.keyword" }
        }
    }
}

```

The result is:

```
    "aggregations": {
    "message.keyword": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": []
    }
  }

```

I checked everything what could think about and all looks ok moreover i have events if i search discover for today filebeat index.

Please help as im trying to solve it moreover than 4 days.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 11, 2018, 11:38am UTC](https://discuss.elastic.co/t/aggs-not-working-on-the-current-date/151874/2 "2018-10-11T11:38:46Z")

</div>

a couple of things

- have you checked the index names? Are they the same?
- do you have sufficient permissions in case you are using security?
- have you left out the query and checked if there are any documents in it?

--Alex

---

<div class="post-metadata">

**Author:** ![alexgohberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexgohberg/32/36077_2.png) [@alexgohberg](https://discuss.elastic.co/u/alexgohberg)\
**Post date:** [October 25, 2018, 11:57am UTC](https://discuss.elastic.co/t/aggs-not-working-on-the-current-date/151874/3 "2018-10-25T11:57:55Z")

</div>

Issue was fixed by add to the filebeat template mapping for message.keyword

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2018, 11:57am UTC](https://discuss.elastic.co/t/aggs-not-working-on-the-current-date/151874/4 "2018-11-22T11:57:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
