# Deep Aggregation Support

**URL:** <https://discuss.elastic.co/t/deep-aggregation-support/131720>\
**Category:** Elasticsearch\
**Created:** [May 14, 2018, 10:34am UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720 "2018-05-14T10:34:16Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 10:34am UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/1 "2018-05-14T10:34:16Z")

</div>

Hi.

I do have a question.

Does elasticsearch support deep aggregations? (nested aggregation in nested aggregation). To make agg of a nested object inside a nested object. Specifically to count docs.  
If so, please give me an example.

Thank you very much.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 14, 2018, 11:17am UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/2 "2018-05-14T11:17:28Z")

</div>

"Nested" can be a reserved word in elasticsearch. Do you mean in the formal sense of `nested` field types and the [nested type of aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search-aggregations-bucket-nested-aggregation.html) or the more general sense of nesting JSON expressions?

---

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 11:36am UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/3 "2018-05-14T11:36:41Z")

</div>

Let me give an example:  
Suppose you have a ES document like this:  
{  
IP:[{  
Address: ip,  
geoip: {  
Country: string  
}  
},  
{...}]  
}  
Both geoip and IP are nested objects

I want to count the ips (from the array field of nested objects IP), based on their country.  
USA: 5  
Great Britain:2

Is this doable?  
Thank you.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 14, 2018, 12:30pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/4 "2018-05-14T12:30:00Z")

</div>

Example mapping docs and query:

```
DELETE test
PUT test
{
  "mappings":{
	"doc":{
	  "properties": {
		"IP":{
		  "type":"nested",
		  "properties": {
			"address":{
			  "type":"ip"
			},
			"country":{
			  "type":"keyword"
			}
		  }
		}
	  }
	}
  }
}
POST test/doc/_bulk
{"index":{}}
{"IP":[{"address":["1.1.1.1","1.1.1.2"], "country":"c1"}]}
{"index":{}}
{"IP":[{"address":["2.2.2.2"], "country":"c2"}]}

POST test/_search
{
  "size":0,
  "aggs": {
	"byCountry": {
	  "nested": {
		"path": "IP"
	  },
	  "aggs": {
		"country": {
		  "terms": {
			"field": "IP.country"
		  },
		  "aggs":{
			"ipCount":{
			  "cardinality":{
				"field":"IP.address"
			  }
			}
		  }
		}
	  }
	}
  }
}
```

---

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 12:48pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/5 "2018-05-14T12:48:54Z")

</div>

Thank you for this reply but the IP nested object that has an geoip nested object that contains country keywork, like this:

> ```
> DELETE test
> PUT test
> {
> "mappings":{
> "doc":{
> "properties": {
> "IP":{
> "type":"nested",
> "properties": {
> "address":{
> "type":"ip"
> },
> "geoip":{
> "type":"nested",
> "properties": {
> "country":{
> "type":"keyword"
> }
> }
> }
> }
> }
> }
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 12:59pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/6 "2018-05-14T12:59:28Z")

</div>

I have this mapping because of geoip plugin, which makes a geoip nested object.

Or is there a way to make geoip plugin not to make a geoip nested object and instead to include the fields like you did there?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 14, 2018, 1:12pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/7 "2018-05-14T13:12:39Z")

</div>

I'm not familiar with the format of the geoip plugin but you can use an [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/master/pipeline.html) to manipulate JSON prior to indexing where required.

---

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 1:17pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/8 "2018-05-14T13:17:45Z")

</div>

Ok. Thank you

---

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 1:36pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/9 "2018-05-14T13:36:52Z")

</div>

Could you give me an example of using 2 pipelines in a row? Like these 2: geoip and ingest  
I am writting querries with kibana directly for ES.

Thank you for your help

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [May 14, 2018, 1:42pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/10 "2018-05-14T13:42:07Z")

</div>

> [@Robert\_George](#):
>
> Could you give me an example of using 2 pipelines in a row?

My understanding is a single `pipeline` can include multiple `processors` and the [geoip plugin](https://www.elastic.co/guide/en/elasticsearch/plugins/master/ingest-geoip.html) describes itself as a processor so should be configurable as one of a sequence of processors in a pipeline.

---

<div class="post-metadata">

**Author:** ![Robert\_George](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@Robert\_George](https://discuss.elastic.co/u/Robert_George)\
**Post date:** [May 14, 2018, 1:43pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/11 "2018-05-14T13:43:27Z")

</div>

Thank you. That's all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 1:43pm UTC](https://discuss.elastic.co/t/deep-aggregation-support/131720/12 "2018-06-11T13:43:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
