# Combine term and bucket range query

**URL:** <https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215>\
**Category:** Elasticsearch\
**Created:** [July 25, 2023, 5:07pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215 "2023-07-25T17:07:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aelam](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@aelam](https://discuss.elastic.co/u/aelam)\
**Post date:** [July 25, 2023, 5:07pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215/1 "2023-07-25T17:07:34Z")

</div>

I'm attempting to extract records of http success/failure data per user using an elasticsearch aggregation.

I'm looking at two fields, "user.name" and "http.response.status\_code". My goal is to use a keyed range bucket aggregation for the http response codes to label the 200s as "success" and the 400s as "failure" ignoring all other codes. I then want to aggregate these on a per user basis so that my output would look something like:

```auto
      "buckets": [
        {
          "key": [
            "user1",
            "success"
          ],
          "key_as_string": "user2|success",
          "doc_count": 1766
        },
        {
          "key": [
            "user1",
            "failure"
          ],
          "key_as_string": "user1|failure",
          "doc_count": 245
        }
      ]

```

I've done both separately using a multiterm aggregation and a range bucket aggregation but is there a way to combine two different kinds of aggregations into one?

I can always resort to bucketing the ranges and dropping the excess values with a script, but I'd prefer to do it all within the query if possible.

Thanks in advance,  
Alex

---

<div class="post-metadata">

**Author:** ![Opster\_support](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opster_support/32/56687_2.png) [@Opster\_support](https://discuss.elastic.co/u/Opster_support)\
**Post date:** [July 25, 2023, 6:05pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215/2 "2023-07-25T18:05:05Z")

</div>

Yes, you can combine different kinds of aggregations into one. In your case, you can use a terms aggregation on the "user.name" field and then a sub-aggregation with a range aggregation on the "http.response.status\_code" field. Here is an example of how you can do it:

```shell
GET /_search
{
  "size": 0,
  "aggs": {
    "users": {
      "terms": {
        "field": "user.name"
      },
      "aggs": {
        "response_status": {
          "range": {
            "keyed": true,
            "field": "http.response.status_code",
            "ranges": [
              {
                "key": "success",
                "from": 200,
                "to": 300
              },
              {
                "key": "failure",
                "from": 400,
                "to": 500
              }
            ]
          }
        }
      }
    }
  }
}

```

This will give you a response where each user has a separate bucket, and within each user's bucket, there are sub-buckets for "success" and "failure" based on the HTTP response status code. Please note that the range is half-open, meaning it includes the "from" value and excludes the "to" value. So, for example, a status code of 200 will be included in the "success" range, but a status code of 300 will not.

Please replace the index name and run this query.

[OpsGPT.io](http://OpsGPT.io) helped with part of this answer 🙂

---

<div class="post-metadata">

**Author:** ![aelam](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@aelam](https://discuss.elastic.co/u/aelam)\
**Post date:** [July 25, 2023, 8:09pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215/3 "2023-07-25T20:09:43Z")

</div>

Exactly what I was looking for. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2023, 8:10pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215/4 "2023-08-22T20:10:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
