# Complex nested aggregation query based on time

**URL:** <https://discuss.elastic.co/t/complex-nested-aggregation-query-based-on-time/19756>\
**Category:** Elasticsearch\
**Created:** [September 12, 2014, 12:52pm UTC](https://discuss.elastic.co/t/complex-nested-aggregation-query-based-on-time/19756 "2014-09-12T12:52:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christophe\_Vandeplas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophe_vandeplas/32/1291_2.png) [@Christophe\_Vandeplas](https://discuss.elastic.co/u/Christophe_Vandeplas)\
**Post date:** [September 12, 2014, 12:52pm UTC](https://discuss.elastic.co/t/complex-nested-aggregation-query-based-on-time/19756/1 "2014-09-12T12:52:42Z")

</div>

Hello there,

I am trying to write a rather complex aggregation

Let's say my json documents contains the following fields: timestamp,  
username, subject

The search should return documents where:

- two identical "subject" fields,
- by the same username,
- within an interval of X minutes.

Using nested aggregation I can group by username, and count the identical  
subjects (terms).  
However I can't find a way to also specify a time interval within the  
query. (the identical subjects should be within an interval of X minutes)

All pointers are welcome.

Thanks  
Christophe

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/2f90d46f-2330-4a0f-8658-8cbdf6824415%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/2f90d46f-2330-4a0f-8658-8cbdf6824415%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:02am UTC](https://discuss.elastic.co/t/complex-nested-aggregation-query-based-on-time/19756/2 "2017-07-06T01:02:46Z")

</div>


