# Can’t filter Rollup index results

**URL:** <https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775>\
**Category:** Kibana\
**Created:** [March 30, 2021, 11:06am UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775 "2021-03-30T11:06:35Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [March 30, 2021, 11:06am UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/1 "2021-03-30T11:06:35Z")

</div>

I have a rollup index with some values, e.g. `customer`. I've created a Kibana dashboard from it. When I try to filter the dashboard with `customer : some-customer`, I get an error. When I do a [custom query](https://gist.github.com/a8bef790b940cc1cf16d5d1675be987b), I can filter by customer, but the trick is that I have to hit the `/[index]/_rollup_search` endpoint. Is this the reason the Kibana dashboard doesn't work? Is there something I can make it work?

Both Kibana and Elasticsearch are at v7.9.1.

Kibana gives me a [log output](https://gist.github.com/a4eb37577b4fb845e607317bef6a4b0d) saying there was a 400 error, but Elasticsearch is silent.

Here is some additional information:

- Mappings of the rollup index: [here](https://gist.github.com/rokcarl/6ccd0db96d5bbce37125cdf60c7029a7).
- The exact query is what I wrote above: `customer : some-customer` . This is KQL, as far as I'm aware. I don't see the underlying Elasticsearch query that Kibana does.

I've tried debugging this while being on Visualize and I get more info here. If I filter for `app : some-app` , you can see the [video here](https://user-images.githubusercontent.com/42874/109116635-27d85280-7741-11eb-91cb-6fb877390aec.gif), I get the following in my chrome debugger tools:

```auto
{"statusCode":400,"error":"Bad Request","message":"[illegal_argument_exception] Unsupported Query in search request: [match]","attributes":{"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"Unsupported Query in search request: [match]"}],"type":"illegal_argument_exception","reason":"Unsupported Query in search request: [match]"}}}

```

Additionally, I have a problem doing an average of `credits` , [video here](https://user-images.githubusercontent.com/42874/109116643-2ad34300-7741-11eb-9027-cfecf32aeb52.gif), but a sum works okay. The error is:

```auto
{"statusCode":500,"error":"Internal Server Error","message":"[aggregation_execution_exception] Invalid aggregation order path [1]. The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets.","attributes":{"error":{"root_cause":[{"type":"aggregation_execution_exception","reason":"Invalid aggregation order path [1]. The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets."}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"stat_rollups","node":"UQqa5Uz0Ti2QrLk0cxX8NQ","reason":{"type":"aggregation_execution_exception","reason":"Invalid aggregation order path [1]. The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets.","caused_by":{"type":"illegal_argument_exception","reason":"The provided aggregation [1] either does not exist, or is a pipeline aggregation and cannot be used to sort the buckets."}}}]}}}

```

So I'm guessing this is a bug in Kibana?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [April 1, 2021, 2:45pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/2 "2021-04-01T14:45:14Z")

</div>

I think the issue here is that you KQL is generating a `match` query when you use unquoted values after the colon, and `match` queries are [not allowed on rollup indices](https://www.elastic.co/guide/en/elasticsearch/reference/current/rollup-search-limitations.html#_limited_querying_components).

You can generate a valid query by adding double quotes around your term, and then KQL will send a `terms` query instead. Alternatively, you can avoid KQL on rollup indices and only use the filter bar.

---

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [April 1, 2021, 7:26pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/3 "2021-04-01T19:26:25Z")

</div>

That didn't work. I tried double quotes, single quotes, no quotes. I tried Lucene search with double quotes, single quotes, no quotes. All the same, doesn't work.

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [April 1, 2021, 7:30pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/4 "2021-04-01T19:30:31Z")

</div>

But you didn't try using the filter bar that generates different queries, and you didn't try using the query DSL directly from the filter bar? Like I sent in the previous link, rollups support a very limited set of queries.

---

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [April 1, 2021, 8:11pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/5 "2021-04-01T20:11:43Z")

</div>

Which filter bar? And how would I use the query DSL directly from it?

Check [my video](https://user-images.githubusercontent.com/42874/113348443-dc642600-9336-11eb-88ca-d381b2a9faa1.gif) to see where I've done it.

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [April 1, 2021, 8:14pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/6 "2021-04-01T20:14:44Z")

</div>

You see the "add filter" button underneath where you're typing? It's a structured editor that supports different options than KQL, and also supports typing DSL queries in JSON form

---

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [April 1, 2021, 8:23pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/7 "2021-04-01T20:23:30Z")

</div>

Gotcha. I tried that as well, doesn't seem to work, check out the [new video](https://user-images.githubusercontent.com/42874/113349699-bb9cd000-9338-11eb-9b1a-089e4ab7eac1.gif).

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [April 1, 2021, 8:44pm UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/8 "2021-04-01T20:44:37Z")

</div>

I had to create a test rollup, and like I suspected you can only do this using the Query DSL in the filter editor. Here are the steps I followed.

1. Add the filter to the filter bar that says "Add filter". You have to type the value manually:

 ![Screen Shot 2021-04-01 at 4.41.40 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/0/30c471f72dd39569b6750e681683ee87a1da4ab1.png)

1. Run this query in the last few minors (7.11 and greater, I think), you will see a more obvious error:

![Screen Shot 2021-04-01 at 4.40.43 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c4f54c8833660c3e759771fae4db7e0c5e839bf.png)

1. Click "Edit as query DSL" and change to `term` instead of match\_phrase:

 ![Screen Shot 2021-04-01 at 4.41.51 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5bd52bce9d43e2d425ea315b18ccc8c795903b22.png)

---

<div class="post-metadata">

**Author:** ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Post date:** [April 2, 2021, 5:41am UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/9 "2021-04-02T05:41:57Z")

</div>

Wow, thanks for helping, this works! It works for the visualize app and for dashboards, great. It's not perfect yet as other people from the company will need to know about this glitch and modify the DSL, which makes it unintuitive, but at least we can get the data.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2021, 5:42am UTC](https://discuss.elastic.co/t/can-t-filter-rollup-index-results/268775/10 "2021-04-30T05:42:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
