# Detect terms values occurring in different buckets

**URL:** <https://discuss.elastic.co/t/detect-terms-values-occurring-in-different-buckets/231779>\
**Category:** Elasticsearch\
**Created:** [May 8, 2020, 6:12pm UTC](https://discuss.elastic.co/t/detect-terms-values-occurring-in-different-buckets/231779 "2020-05-08T18:12:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [May 8, 2020, 6:12pm UTC](https://discuss.elastic.co/t/detect-terms-values-occurring-in-different-buckets/231779/1 "2020-05-08T18:12:14Z")

</div>

Hi,  
I need to solve the following problem.  
I have an index with some operations performed by users. I need to detect the users that performs two or more update operations on a same element (value) but only if those operations where performed at least with one hour of difference.  
So, I thought in a date\_histogram aggregation

```
GET index_lab/_search
{
  "size": 0, 
  "query": {
   "bool": {"must": [{"terms": {"event.module": ["labs-app"]}},
                     {"terms": {"composed_action": ["update"]}},
                     {"terms": {"appuser": ["tester_1","tester_2"]}},
                     {"range": {
                       "@timestamp": {
                         "gte": "now-24h",
                         "lte": "now"
                       }
                     }}
          ]}},
          "aggs": {
            "intervals": {
              "date_histogram": {
                "field": "@timestamp",
                "interval": "hour"
              }, "aggs": {
                "results": {
                  "terms": {
                    "field": "value"
                  
                  }
                }
              }
            }
          }
 }

```

Which returns something like this

```
"key_as_string" : "2020-05-08T10:00:00.000Z",
  "key" : 1588932000000,
  "doc_count" : 67,
  "scree" : {
    "doc_count_error_upper_bound" : 0,
    "sum_other_doc_count" : 55,
    "buckets" : [
      {
        "key" : "150713-5d",
        "doc_count" : 2
      },
      {
        "key" : "140249-e5",
        "doc_count" : 2
      },
      {
        "key" : "115801-46",
        "doc_count" : 1
      },
      {
        "key" : "116089-88",
        "doc_count" : 1
      }
    ]
  }
},
{
  "key_as_string" : "2020-05-08T11:00:00.000Z",
  "key" : 1588935600000,
  "doc_count" : 43,
  "scree" : {
    "doc_count_error_upper_bound" : 0,
    "sum_other_doc_count" : 32,
    "buckets" : [
      {
        "key" : "147973-7b",
        "doc_count" : 2
      },
      {
        "key" : "140249-e5",
        "doc_count" : 1
      },
      {
        "key" : "140250-86",
        "doc_count" : 1
      }
    ]
  }
}

```

How can I detect which values (keys of the second aggregation) are in more than one parent bucket? (in the example value 140249-e5)  
I can solve this processing the query with python, but I want to know if it is possible to solve only with a aggregation

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 6:12pm UTC](https://discuss.elastic.co/t/detect-terms-values-occurring-in-different-buckets/231779/2 "2020-06-05T18:12:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
