# Can i use \_source field inside aggregations?

**URL:** <https://discuss.elastic.co/t/can-i-use--source-field-inside-aggregations/74773>\
**Category:** Elasticsearch\
**Created:** [February 11, 2017, 7:36pm UTC](https://discuss.elastic.co/t/can-i-use--source-field-inside-aggregations/74773 "2017-02-11T19:36:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [February 11, 2017, 7:36pm UTC](https://discuss.elastic.co/t/can-i-use--source-field-inside-aggregations/74773/1 "2017-02-11T19:36:10Z")

</div>

Hi,

I have documents with some many fields, i want to find the count of documents that are inserted after certain hour which can be done by using range query but among all documents fields i want only Timestamp field should be displayed .

I used the following query

```
 {
      "_source": [
        "fields.Timestamp"
      ],
      "aggs": {
        "last_5_mins": {
          "filter": {
            "range": {
              "fields.Timestamp": {
                "gt": "2017-02-10T10:07:04.4367673Z"
              }
            }
          }
        }
      }
    }

```

When i saw the output i didnt get the Timestamp for the matched documents rather i got for the documents that are not matched with my query.

MY output:

```
"hits": {
    "total": 6,
    "max_score": 1,
    "hits": [
      {
        "_index": "matrix",
        "_type": "neo",
        "_id": "5",
        "_score": 1,
        "_source": {
       }
      },
      {
        "_index": "matrix",
        "_type": "neo",
        "_id": "2",
        "_score": 1,
        "_source": {
          "fields": {
            "Timestamp": "2017-02-10T10:07:04.4367673Z"
          }
        }
      },
      {
        "_index": "matrix",
        "_type": "neo",
        "_id": "4",
        "_score": 1,
        "_source": {
          "fields": {
            "Timestamp": "2017-02-10T10:07:04.4836472Z"
          }
        }
      },
      {
        "_index": "matrix",
        "_type": "neo",
        "_id": "6",
        "_score": 1,
        "_source": {

        }
      },
      {
        "_index": "matrix",
        "_type": "neo",
        "_id": "1",
        "_score": 1,
        "_source": {
          "fields": {
            "Timestamp": "2017-02-10T10:07:04.4367673Z"
          }
        }
      },
      {
        "_index": "matrix",
        "_type": "neo",
        "_id": "3",
        "_score": 1,
        "_source": {
          "fields": {
            "Timestamp": "2017-02-10T10:07:12.1147415Z"
          }
        }
      }
    ]
  },
  "aggregations": {
    "last_5_mins": {
      "doc_count": 2
    }
  }
}

```

How can i get the timestamp for the matched documents?  
Thanks..

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [February 14, 2017, 3:09am UTC](https://discuss.elastic.co/t/can-i-use--source-field-inside-aggregations/74773/2 "2017-02-14T03:09:57Z")

</div>

I'm not sure you even need an aggregation. A regular query will also include a `total` (in my test document I have the attribute _timestamp_ at the root level):

```
{
  "_source": [
    "timestamp"
  ],
  "query": {
    "range": {
      "timestamp": {
        "gte": "now-5m",
        "lte": "now"
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2017, 3:10am UTC](https://discuss.elastic.co/t/can-i-use--source-field-inside-aggregations/74773/3 "2017-03-14T03:10:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
