# Creating filters per aggregation similar to Facets

**URL:** <https://discuss.elastic.co/t/creating-filters-per-aggregation-similar-to-facets/19211>\
**Category:** Elasticsearch\
**Created:** [August 11, 2014, 10:18pm UTC](https://discuss.elastic.co/t/creating-filters-per-aggregation-similar-to-facets/19211 "2014-08-11T22:18:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeff\_Steinmetz](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@Jeff\_Steinmetz](https://discuss.elastic.co/u/Jeff_Steinmetz)\
**Post date:** [August 11, 2014, 10:18pm UTC](https://discuss.elastic.co/t/creating-filters-per-aggregation-similar-to-facets/19211/1 "2014-08-11T22:18:53Z")

</div>

Kibana provides a good example of date histograms, split out by each  
"query" entered at the top in the "Query" bar. It essentially creates  
multiple free text queries against "all".

I see it generates per facet filter, with a free text (query\_string)  
search.  
Since facets are to be depreciated, I am now only using aggregations (in a  
custom application - unrelated to Kibana). I have tried this with  
aggregations without success.  
I also realize there is something new coming in 1.4, but I assume with  
multiple aggregations, (vs. multiple filters to create multiple buckets) I  
can do this today.

Here is a oversimplified version of the date histogram aggregation I have  
(without the leading query section - consider it pseudo code)

The "filter" section is the part in question. Removing the filter works, I  
have tried all types of "filter" formats, looked for samples, etc. no luck.  
I have tried {"all" : "search term"}  
as well as:  
{"query\_string": { "all" : "search terrm" }}

I've tried a specific field name, etc. All attempts are not proving  
fruitful.

## Pseudo example using aggregations:

"aggregations" : {  
"0" : {  
"date\_histogram" : {  
"filter" : { "query\_string" : { "query" : "Intel" } },  
"field" : "created\_at",  
"interval" : "1d",  
"min\_doc\_count" : 0  
}  
},  
"1" : {  
"date\_histogram" : {  
"filter" : { "query\_string" : { "query" : "Samsung" } },  
"field" : "created\_at",  
"interval" : "1d",  
"min\_doc\_count" : 0,  
"pre\_zone" : "-02:00",  
"post\_zone" : "-03:30"  
}  
}  
}

## Here is the Facet version (which works - note Filtered/query/query\_string/query):

{  
"facets": {  
"0": {  
"date\_histogram": {  
"field": "created\_at",  
"interval": "3h"  
},  
"global": true,  
"facet\_filter": {  
"fquery": {  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "Intel"  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"terms": {  
"userid": [

"53d02d6aed9597f3c60000fa"  
]  
}  
},  
{  
"range": {  
"created\_at": {  
"from": "now-30d",  
"to": "now"  
}  
}  
}  
]  
}  
}  
}  
}  
}  
}  
},  
"1": {  
"date\_histogram": {  
"field": "created\_at",  
"interval": "3h"  
},  
"global": true,  
"facet\_filter": {  
"fquery": {  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "Samsung"  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"terms": {  
"userid": [

"53d02d6aed9597f3c60000fa"  
]  
}  
},  
{  
"range": {  
"created\_at": {  
"from": "now-30d",  
"to": "now"  
}  
}  
}  
]  
}  
}  
}  
}  
}  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3f2cbee2-1f7d-49cc-8451-3268dbef4804%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3f2cbee2-1f7d-49cc-8451-3268dbef4804%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [August 12, 2014, 1:37pm UTC](https://discuss.elastic.co/t/creating-filters-per-aggregation-similar-to-facets/19211/2 "2014-08-12T13:37:30Z")

</div>

Trying using a filter aggregation:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

The idea is that the filter is the outer most aggregation and the  
aggregation you actually want to filter is the sub-aggregation.

Cheers,

Ivan

On Mon, Aug 11, 2014 at 6:18 PM, Jeff Steinmetz \<[jeffrey.steinmetz@gmail.com](mailto:jeffrey.steinmetz@gmail.com)

> wrote:

> Kibana provides a good example of date histograms, split out by each  
> "query" entered at the top in the "Query" bar. It essentially creates  
> multiple free text queries against "all".
> 
> I see it generates per facet filter, with a free text (query\_string)  
> search.  
> Since facets are to be depreciated, I am now only using aggregations (in a  
> custom application - unrelated to Kibana). I have tried this with  
> aggregations without success.  
> I also realize there is something new coming in 1.4, but I assume with  
> multiple aggregations, (vs. multiple filters to create multiple buckets) I  
> can do this today.
> 
> Here is a oversimplified version of the date histogram aggregation I have  
> (without the leading query section - consider it pseudo code)
> 
> The "filter" section is the part in question. Removing the filter works,  
> I have tried all types of "filter" formats, looked for samples, etc. no  
> luck. I have tried {"all" : "search term"}  
> as well as:  
> {"query\_string": { "all" : "search terrm" }}
> 
> I've tried a specific field name, etc. All attempts are not proving  
> fruitful.
> 
> ## Pseudo example using aggregations:
> 
> "aggregations" : {  
> "0" : {  
> "date\_histogram" : {  
> "filter" : { "query\_string" : { "query" : "Intel" } },  
> "field" : "created\_at",  
> "interval" : "1d",  
> "min\_doc\_count" : 0  
> }  
> },  
> "1" : {  
> "date\_histogram" : {  
> "filter" : { "query\_string" : { "query" : "Samsung" } },  
> "field" : "created\_at",  
> "interval" : "1d",  
> "min\_doc\_count" : 0,  
> "pre\_zone" : "-02:00",  
> "post\_zone" : "-03:30"  
> }  
> }  
> }
> 
> ## Here is the Facet version (which works - note Filtered/query/query\_string/query):
> 
> {  
> "facets": {  
> "0": {  
> "date\_histogram": {  
> "field": "created\_at",  
> "interval": "3h"  
> },  
> "global": true,  
> "facet\_filter": {  
> "fquery": {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "query": "Intel"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [  
> {  
> "terms": {  
> "userid": [
> 
> "53d02d6aed9597f3c60000fa"  
> ]  
> }  
> },  
> {  
> "range": {  
> "created\_at": {  
> "from": "now-30d",  
> "to": "now"  
> }  
> }  
> }  
> ]  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> "1": {  
> "date\_histogram": {  
> "field": "created\_at",  
> "interval": "3h"  
> },  
> "global": true,  
> "facet\_filter": {  
> "fquery": {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "query": "Samsung"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [  
> {  
> "terms": {  
> "userid": [
> 
> "53d02d6aed9597f3c60000fa"  
> ]  
> }  
> },  
> {  
> "range": {  
> "created\_at": {  
> "from": "now-30d",  
> "to": "now"  
> }  
> }  
> }  
> ]  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/3f2cbee2-1f7d-49cc-8451-3268dbef4804%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3f2cbee2-1f7d-49cc-8451-3268dbef4804%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/3f2cbee2-1f7d-49cc-8451-3268dbef4804%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3f2cbee2-1f7d-49cc-8451-3268dbef4804%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQCxZ-UvGirHes9yk1JMjfk-2YxAPdAG-1T-hCsAD\_zZsw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQCxZ-UvGirHes9yk1JMjfk-2YxAPdAG-1T-hCsAD_zZsw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:09am UTC](https://discuss.elastic.co/t/creating-filters-per-aggregation-similar-to-facets/19211/3 "2017-07-06T01:09:12Z")

</div>


