# Difficulty trying to find a way to use facets

**URL:** https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456
**Category:** Elasticsearch
**Created:** [April 4, 2013, 9:03pm UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456 "2013-04-04T21:03:50Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)
#### Post date: [April 4, 2013, 9:03pm UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/1 "2013-04-04T21:03:50Z")

</div>

Hi all,

I'm using ES to store maillogs. In that, I'm trying to use ES to generate  
statistics for ex, per domain bandwidth usage etc.

For ex, if I have a document which has fields like:

- @fields.from: [abc@domain.com](mailto:abc@domain.com)
- @fields.size: 1024

Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want the  
summation of size for a particular domain. How do I accomplish that?

I had a look at statistical facet but I'm not sure how will I use it to do  
per domain summation of @fields.size field.  
Any help is highly appreciated. Thanks

--  
Regards,  
Abhijeet Rastogi (shadyabhi)

> **[Abhijeet's Blog](https://blog.abhijeetr.com/)**
>
> I write about problems that I solve

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [April 5, 2013, 2:03am UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/2 "2013-04-05T02:03:24Z")

</div>

It's a question of mapping and analysis.

Define a mapping for faceting (multifield type is the best option) and apply to "from" field a custom analyzer: [http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/).

Define this custom analyzer first when creating your index. I think you should use a pattern tokenizer: [http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
And a pattern replace token filter: [http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern\_replace-tokenfilter/](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)

Have a look at [http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/). It may help you on how to define an analyzer and try it (analyze API).

My 2 cents

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a écrit :

Hi all,

I'm using ES to store maillogs. In that, I'm trying to use ES to generate statistics for ex, per domain bandwidth usage etc.

For ex, if I have a document which has fields like:

- @fields.from: [abc@domain.com](mailto:abc@domain.com)
- @fields.size: 1024

Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want the summation of size for a particular domain. How do I accomplish that?

I had a look at statistical facet but I'm not sure how will I use it to do per domain summation of @fields.size field.  
Any help is highly appreciated. Thanks

## -- Regards, Abhijeet Rastogi (shadyabhi) [http://blog.abhijeetr.com](http://blog.abhijeetr.com)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)
#### Post date: [April 5, 2013, 4:44am UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/3 "2013-04-05T04:44:27Z")

</div>

How is this about mapping and analyzers? I forgot to mention but both these  
fields I specified are non-analyzed. So, I already have these fields with  
me in ES.

On Fri, Apr 5, 2013 at 7:33 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> It's a question of mapping and analysis.
> 
> Define a mapping for faceting (multifield type is the best option) and  
> apply to "from" field a custom analyzer:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/)  
> .
> 
> Define this custom analyzer first when creating your index. I think you  
> should use a pattern tokenizer:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
> And a pattern replace token filter:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)
> 
> Have a look at  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/).  
> It may help you on how to define an analyzer and try it (analyze API).
> 
> My 2 cents
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> écrit :
> 
> Hi all,
> 
> I'm using ES to store maillogs. In that, I'm trying to use ES to generate  
> statistics for ex, per domain bandwidth usage etc.
> 
> For ex, if I have a document which has fields like:
> 
> - @fields.from: [abc@domain.com](mailto:abc@domain.com)
> - @fields.size: 1024
> 
> Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want  
> the summation of size for a particular domain. How do I accomplish that?
> 
> I had a look at statistical facet but I'm not sure how will I use it to do  
> per domain summation of @fields.size field.  
> Any help is highly appreciated. Thanks
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Abhijeet Rastogi (shadyabhi)  
[http://blog.abhijeetr.com](http://blog.abhijeetr.com)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)
#### Post date: [April 5, 2013, 9:30am UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/4 "2013-04-05T09:30:14Z")

</div>

Hi David,

I'm clueless as to how to proceed as I am not sure how'll I apply mapping  
for faceting. I'll try to be more precise so that may be you can more  
explicit about it. I would really appreciate it.

Suppose, I've this data.

curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "First  
Line", "email\_id": "[abc@domain.com](mailto:abc@domain.com)", "size": 1024}'  
curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
"Second Line", "email\_id": "[def@domain.com](mailto:def@domain.com)", "size": 2048}'  
curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Third  
Line", "email\_id": "[ghi@domain.com](mailto:ghi@domain.com)", "size": 3096}'  
curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
"Fourth Line", "email\_id": "[abc@domainname.com](mailto:abc@domainname.com)", "size": 1024}'  
curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Fifth  
Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 2048}'  
curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Fifth  
Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 3096}'

I want a facet query that'll give me stats like sum of size field for each  
domains (in this example [domain.com](http://domain.com) and [domainname.com](http://domainname.com)) or perhaps as a  
bonus for each email id too.

On Fri, Apr 5, 2013 at 7:33 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> It's a question of mapping and analysis.
> 
> Define a mapping for faceting (multifield type is the best option) and  
> apply to "from" field a custom analyzer:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/)  
> .
> 
> Define this custom analyzer first when creating your index. I think you  
> should use a pattern tokenizer:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
> And a pattern replace token filter:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)
> 
> Have a look at  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/).  
> It may help you on how to define an analyzer and try it (analyze API).
> 
> My 2 cents
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> écrit :
> 
> Hi all,
> 
> I'm using ES to store maillogs. In that, I'm trying to use ES to generate  
> statistics for ex, per domain bandwidth usage etc.
> 
> For ex, if I have a document which has fields like:
> 
> - @fields.from: [abc@domain.com](mailto:abc@domain.com)
> - @fields.size: 1024
> 
> Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want  
> the summation of size for a particular domain. How do I accomplish that?
> 
> I had a look at statistical facet but I'm not sure how will I use it to do  
> per domain summation of @fields.size field.  
> Any help is highly appreciated. Thanks
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Abhijeet Rastogi (shadyabhi)  
[http://blog.abhijeetr.com](http://blog.abhijeetr.com)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [April 5, 2013, 5:10pm UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/5 "2013-04-05T17:10:23Z")

</div>

Hi,

Here is a full gist to do it: [Extract domain name and compute size with terms stat facet · GitHub](https://gist.github.com/dadoonet/5320947)

Hope this helps

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr | @scrutmydocs

Le 5 avr. 2013 à 11:30, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a écrit :

> Hi David,
> 
> I'm clueless as to how to proceed as I am not sure how'll I apply mapping for faceting. I'll try to be more precise so that may be you can more explicit about it. I would really appreciate it.
> 
> Suppose, I've this data.
> 
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "First Line", "email\_id": "[abc@domain.com](mailto:abc@domain.com)", "size": 1024}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Second Line", "email\_id": "[def@domain.com](mailto:def@domain.com)", "size": 2048}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Third Line", "email\_id": "[ghi@domain.com](mailto:ghi@domain.com)", "size": 3096}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Fourth Line", "email\_id": "[abc@domainname.com](mailto:abc@domainname.com)", "size": 1024}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 2048}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" : "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 3096}'
> 
> I want a facet query that'll give me stats like sum of size field for each domains (in this example [domain.com](http://domain.com) and [domainname.com](http://domainname.com)) or perhaps as a bonus for each email id too.
> 
> On Fri, Apr 5, 2013 at 7:33 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:  
> It's a question of mapping and analysis.
> 
> Define a mapping for faceting (multifield type is the best option) and apply to "from" field a custom analyzer: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/).
> 
> Define this custom analyzer first when creating your index. I think you should use a pattern tokenizer: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
> And a pattern replace token filter: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)
> 
> Have a look at [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/). It may help you on how to define an analyzer and try it (analyze API).
> 
> My 2 cents
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a écrit :
> 
> Hi all,
> 
> I'm using ES to store maillogs. In that, I'm trying to use ES to generate statistics for ex, per domain bandwidth usage etc.
> 
> For ex, if I have a document which has fields like:
> 
> - @fields.from: [abc@domain.com](mailto:abc@domain.com)
> - @fields.size: 1024
> 
> Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want the summation of size for a particular domain. How do I accomplish that?
> 
> I had a look at statistical facet but I'm not sure how will I use it to do per domain summation of @fields.size field.  
> Any help is highly appreciated. Thanks
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)
#### Post date: [April 5, 2013, 8:29pm UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/6 "2013-04-05T20:29:02Z")

</div>

Thanks a lot for your awesome reply David. I now understand most part of it.  
One thing though, this method doesn't save the actual value for email\_id.  
What I mean is, I can't use term queries to search for these email\_ids.

Is there a way around it?

On Fri, Apr 5, 2013 at 10:40 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Hi,
> 
> Here is a full gist to do it: [Extract domain name and compute size with terms stat facet · GitHub](https://gist.github.com/dadoonet/5320947)
> 
> Hope this helps
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> 
> Le 5 avr. 2013 à 11:30, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> écrit :
> 
> Hi David,
> 
> I'm clueless as to how to proceed as I am not sure how'll I apply mapping  
> for faceting. I'll try to be more precise so that may be you can more  
> explicit about it. I would really appreciate it.
> 
> Suppose, I've this data.
> 
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> "First Line", "email\_id": "[abc@domain.com](mailto:abc@domain.com)", "size": 1024}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> "Second Line", "email\_id": "[def@domain.com](mailto:def@domain.com)", "size": 2048}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> "Third Line", "email\_id": "[ghi@domain.com](mailto:ghi@domain.com)", "size": 3096}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> "Fourth Line", "email\_id": "[abc@domainname.com](mailto:abc@domainname.com)", "size": 1024}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 2048}'  
> curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 3096}'
> 
> I want a facet query that'll give me stats like sum of size field for each  
> domains (in this example [domain.com](http://domain.com) and [domainname.com](http://domainname.com)) or perhaps as a  
> bonus for each email id too.
> 
> On Fri, Apr 5, 2013 at 7:33 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> 
> > It's a question of mapping and analysis.
> > 
> > Define a mapping for faceting (multifield type is the best option) and  
> > apply to "from" field a custom analyzer:  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/)  
> > .
> > 
> > Define this custom analyzer first when creating your index. I think you  
> > should use a pattern tokenizer:  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
> > And a pattern replace token filter:  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)
> > 
> > Have a look at  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/).  
> > It may help you on how to define an analyzer and try it (analyze API).
> > 
> > My 2 cents
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> > écrit :
> > 
> > Hi all,
> > 
> > I'm using ES to store maillogs. In that, I'm trying to use ES to generate  
> > statistics for ex, per domain bandwidth usage etc.
> > 
> > For ex, if I have a document which has fields like:
> > 
> > - @fields.from: [abc@domain.com](mailto:abc@domain.com)
> > - @fields.size: 1024
> > 
> > Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want  
> > the summation of size for a particular domain. How do I accomplish that?
> > 
> > I had a look at statistical facet but I'm not sure how will I use it to  
> > do per domain summation of @fields.size field.  
> > Any help is highly appreciated. Thanks
> > 
> > --  
> > Regards,  
> > Abhijeet Rastogi (shadyabhi)  
> > [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Abhijeet Rastogi (shadyabhi)  
[http://blog.abhijeetr.com](http://blog.abhijeetr.com)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)
#### Post date: [April 6, 2013, 12:04am UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/7 "2013-04-06T00:04:25Z")

</div>

Interesting solution by David. If you want to preserve the value of the  
entire email\_id, you can use a multi-field where one field is not analyzed  
(or uses the keyword analyzer) and the other one uses the email analyzer  
created by David.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

--  
Ivan

On Fri, Apr 5, 2013 at 1:29 PM, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com)wrote:

> Thanks a lot for your awesome reply David. I now understand most part of  
> it.  
> One thing though, this method doesn't save the actual value for email\_id.  
> What I mean is, I can't use term queries to search for these email\_ids.
> 
> Is there a way around it?
> 
> On Fri, Apr 5, 2013 at 10:40 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> 
> > Hi,
> > 
> > Here is a full gist to do it: [Extract domain name and compute size with terms stat facet · GitHub](https://gist.github.com/dadoonet/5320947)
> > 
> > Hope this helps
> > 
> > --  
> > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> > | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> > 
> > Le 5 avr. 2013 à 11:30, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> > écrit :
> > 
> > Hi David,
> > 
> > I'm clueless as to how to proceed as I am not sure how'll I apply mapping  
> > for faceting. I'll try to be more precise so that may be you can more  
> > explicit about it. I would really appreciate it.
> > 
> > Suppose, I've this data.
> > 
> > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > "First Line", "email\_id": "[abc@domain.com](mailto:abc@domain.com)", "size": 1024}'  
> > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > "Second Line", "email\_id": "[def@domain.com](mailto:def@domain.com)", "size": 2048}'  
> > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > "Third Line", "email\_id": "[ghi@domain.com](mailto:ghi@domain.com)", "size": 3096}'  
> > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > "Fourth Line", "email\_id": "[abc@domainname.com](mailto:abc@domainname.com)", "size": 1024}'  
> > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 2048}'  
> > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 3096}'
> > 
> > I want a facet query that'll give me stats like sum of size field for  
> > each domains (in this example [domain.com](http://domain.com) and [domainname.com](http://domainname.com)) or perhaps  
> > as a bonus for each email id too.
> > 
> > On Fri, Apr 5, 2013 at 7:33 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> > 
> > > It's a question of mapping and analysis.
> > > 
> > > Define a mapping for faceting (multifield type is the best option) and  
> > > apply to "from" field a custom analyzer:  
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/)  
> > > .
> > > 
> > > Define this custom analyzer first when creating your index. I think you  
> > > should use a pattern tokenizer:  
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
> > > And a pattern replace token filter:  
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)
> > > 
> > > Have a look at  
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/).  
> > > It may help you on how to define an analyzer and try it (analyze API).
> > > 
> > > My 2 cents
> > > 
> > > --  
> > > David 😉  
> > > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > > 
> > > Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> > > écrit :
> > > 
> > > Hi all,
> > > 
> > > I'm using ES to store maillogs. In that, I'm trying to use ES to  
> > > generate statistics for ex, per domain bandwidth usage etc.
> > > 
> > > For ex, if I have a document which has fields like:
> > > 
> > > - @fields.from: [abc@domain.com](mailto:abc@domain.com)
> > > - @fields.size: 1024
> > > 
> > > Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just want  
> > > the summation of size for a particular domain. How do I accomplish that?
> > > 
> > > I had a look at statistical facet but I'm not sure how will I use it to  
> > > do per domain summation of @fields.size field.  
> > > Any help is highly appreciated. Thanks
> > > 
> > > --  
> > > Regards,  
> > > Abhijeet Rastogi (shadyabhi)  
> > > [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > Regards,  
> > Abhijeet Rastogi (shadyabhi)  
> > [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)
#### Post date: [April 8, 2013, 8:13pm UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/8 "2013-04-08T20:13:01Z")

</div>

Thanks Ivan for pointing to the right direction. multi-field is the  
solution I wanted. 🙂

On Sat, Apr 6, 2013 at 5:34 AM, Ivan Brusic [ivan@brusic.com](mailto:ivan@brusic.com) wrote:

> Interesting solution by David. If you want to preserve the value of the  
> entire email\_id, you can use a multi-field where one field is not analyzed  
> (or uses the keyword analyzer) and the other one uses the email analyzer  
> created by David.
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/mapping/multi-field-type/)
> 
> --  
> Ivan
> 
> On Fri, Apr 5, 2013 at 1:29 PM, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com)wrote:
> 
> > Thanks a lot for your awesome reply David. I now understand most part of  
> > it.  
> > One thing though, this method doesn't save the actual value for email\_id.  
> > What I mean is, I can't use term queries to search for these email\_ids.
> > 
> > Is there a way around it?
> > 
> > On Fri, Apr 5, 2013 at 10:40 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> > 
> > > Hi,
> > > 
> > > Here is a full gist to do it: [Extract domain name and compute size with terms stat facet · GitHub](https://gist.github.com/dadoonet/5320947)
> > > 
> > > Hope this helps
> > > 
> > > --  
> > > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> > > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> > > | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> > > 
> > > Le 5 avr. 2013 à 11:30, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> > > écrit :
> > > 
> > > Hi David,
> > > 
> > > I'm clueless as to how to proceed as I am not sure how'll I apply  
> > > mapping for faceting. I'll try to be more precise so that may be you can  
> > > more explicit about it. I would really appreciate it.
> > > 
> > > Suppose, I've this data.
> > > 
> > > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > > "First Line", "email\_id": "[abc@domain.com](mailto:abc@domain.com)", "size": 1024}'  
> > > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > > "Second Line", "email\_id": "[def@domain.com](mailto:def@domain.com)", "size": 2048}'  
> > > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > > "Third Line", "email\_id": "[ghi@domain.com](mailto:ghi@domain.com)", "size": 3096}'  
> > > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > > "Fourth Line", "email\_id": "[abc@domainname.com](mailto:abc@domainname.com)", "size": 1024}'  
> > > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > > "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 2048}'  
> > > curl -X POST "[http://localhost:9200/facets\_test/logs](http://localhost:9200/facets_test/logs)" -d '{"title" :  
> > > "Fifth Line", "email\_id": "[def@domainname.com](mailto:def@domainname.com)", "size": 3096}'
> > > 
> > > I want a facet query that'll give me stats like sum of size field for  
> > > each domains (in this example [domain.com](http://domain.com) and [domainname.com](http://domainname.com)) or perhaps  
> > > as a bonus for each email id too.
> > > 
> > > On Fri, Apr 5, 2013 at 7:33 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> > > 
> > > > It's a question of mapping and analysis.
> > > > 
> > > > Define a mapping for faceting (multifield type is the best option) and  
> > > > apply to "from" field a custom analyzer:  
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/custom-analyzer/)  
> > > > .
> > > > 
> > > > Define this custom analyzer first when creating your index. I think you  
> > > > should use a pattern tokenizer:  
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-tokenizer/)  
> > > > And a pattern replace token filter:  
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern_replace-tokenfilter/)
> > > > 
> > > > Have a look at  
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/index-modules/analysis/pattern-analyzer/).  
> > > > It may help you on how to define an analyzer and try it (analyze API).
> > > > 
> > > > My 2 cents
> > > > 
> > > > --  
> > > > David 😉  
> > > > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > > > 
> > > > Le 4 avr. 2013 à 23:03, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a  
> > > > écrit :
> > > > 
> > > > Hi all,
> > > > 
> > > > I'm using ES to store maillogs. In that, I'm trying to use ES to  
> > > > generate statistics for ex, per domain bandwidth usage etc.
> > > > 
> > > > For ex, if I have a document which has fields like:
> > > > 
> > > > - @fields.from: [abc@domain.com](mailto:abc@domain.com)
> > > > - @fields.size: 1024
> > > > 
> > > > Now, there can be many email addresses like [abc@domain.com](mailto:abc@domain.com). I just  
> > > > want the summation of size for a particular domain. How do I accomplish  
> > > > that?
> > > > 
> > > > I had a look at statistical facet but I'm not sure how will I use it to  
> > > > do per domain summation of @fields.size field.  
> > > > Any help is highly appreciated. Thanks
> > > > 
> > > > --  
> > > > Regards,  
> > > > Abhijeet Rastogi (shadyabhi)  
> > > > [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > 
> > > --  
> > > Regards,  
> > > Abhijeet Rastogi (shadyabhi)  
> > > [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > Regards,  
> > Abhijeet Rastogi (shadyabhi)  
> > [http://blog.abhijeetr.com](http://blog.abhijeetr.com)
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Abhijeet Rastogi (shadyabhi)  
[http://blog.abhijeetr.com](http://blog.abhijeetr.com)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:42am UTC](https://discuss.elastic.co/t/difficulty-trying-to-find-a-way-to-use-facets/11456/9 "2017-07-06T02:42:10Z")

</div>


