# Discrete value aggregations on a URL field

**URL:** <https://discuss.elastic.co/t/discrete-value-aggregations-on-a-url-field/19751>\
**Category:** Elasticsearch\
**Created:** [September 12, 2014, 7:18am UTC](https://discuss.elastic.co/t/discrete-value-aggregations-on-a-url-field/19751 "2014-09-12T07:18:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ali\_Kheyrollahi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ali_kheyrollahi/32/945_2.png) [@Ali\_Kheyrollahi](https://discuss.elastic.co/u/Ali_Kheyrollahi)\
**Post date:** [September 12, 2014, 7:18am UTC](https://discuss.elastic.co/t/discrete-value-aggregations-on-a-url-field/19751/1 "2014-09-12T07:18:18Z")

</div>

Hi,

I am trying to find numbers of discrete value per URL in a day and the  
result is not what I expect.  
So let's say I have an index which contains such document:

{  
"date": ...,  
"url": ....,  
"other"...  
}

And basically I am trying to group by url for a particular date:

{  
"query":  
{  
"range":{"date": {"gte":"2014-09-08", "lte":"2014-09-09"}}  
},  
"aggregations":  
{  
"mt\_agg":  
{  
"terms": {"field": "url"}  
}  
}  
}

Result is bizarre, I mean it breaks my URL into its segments and aggregates  
on that. Do I need to use Hash of the URL (I prefer not to)? Here is the  
result:

```
"aggregations": {
    "shabash": {
        "buckets": [
            {
                "key": "http",
                "doc_count": 903
            },
            {
                "key": "rss",
                "doc_count": 638
            },
            {
                "key": "service",
                "doc_count": 381
            },
            {
                "key": "zzzzzzz.fff",
                "doc_count": 337
            },
            {
                "key": "e",
                "doc_count": 153
            },
            {
                "key": "xxx.com",
                "doc_count": 153
            },
            {
                "key": "www.yyy",
                "doc_count": 153
            },
            {
                "key": "fa",
                "doc_count": 127
            },
            {
                "key": "feed",
                "doc_count": 119
            },
            {
                "key": "www.nnnnnnn.com",
                "doc_count": 71
            }
        ]
    }
}

```

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ac784f35-d8ee-4fe5-979f-de1ca7446da0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ac784f35-d8ee-4fe5-979f-de1ca7446da0%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ali\_Kheyrollahi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ali_kheyrollahi/32/945_2.png) [@Ali\_Kheyrollahi](https://discuss.elastic.co/u/Ali_Kheyrollahi)\
**Post date:** [September 12, 2014, 7:23am UTC](https://discuss.elastic.co/t/discrete-value-aggregations-on-a-url-field/19751/2 "2014-09-12T07:23:51Z")

</div>

OK, it seems that I need to use not\_analyzed on the field. Is that correct?

On Friday, 12 September 2014 08:18:19 UTC+1, Ali Kheyrollahi wrote:

> Hi,
> 
> I am trying to find numbers of discrete value per URL in a day and the  
> result is not what I expect.  
> So let's say I have an index which contains such document:
> 
> {  
> "date": ...,  
> "url": ....,  
> "other"...  
> }
> 
> And basically I am trying to group by url for a particular date:
> 
> {  
> "query":  
> {  
> "range":{"date": {"gte":"2014-09-08", "lte":"2014-09-09"}}  
> },  
> "aggregations":  
> {  
> "mt\_agg":  
> {  
> "terms": {"field": "url"}  
> }  
> }  
> }
> 
> Result is bizarre, I mean it breaks my URL into its segments and  
> aggregates on that. Do I need to use Hash of the URL (I prefer not to)?  
> Here is the result:
> 
> ```
> "aggregations": {
> "shabash": {
> "buckets": [
> {
> "key": "http",
> "doc_count": 903
> },
> {
> "key": "rss",
> "doc_count": 638
> },
> {
> "key": "service",
> "doc_count": 381
> },
> {
> "key": "zzzzzzz.fff",
> "doc_count": 337
> },
> {
> "key": "e",
> "doc_count": 153
> },
> {
> "key": "xxx.com",
> "doc_count": 153
> },
> {
> "key": "www.yyy",
> "doc_count": 153
> },
> {
> "key": "fa",
> "doc_count": 127
> },
> {
> "key": "feed",
> "doc_count": 119
> },
> {
> "key": "www.nnnnnnn.com",
> "doc_count": 71
> }
> ]
> }
> }
> 
> ```

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e453b450-3329-476c-9102-852af3180745%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e453b450-3329-476c-9102-852af3180745%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 12, 2014, 8:54am UTC](https://discuss.elastic.co/t/discrete-value-aggregations-on-a-url-field/19751/3 "2014-09-12T08:54:26Z")

</div>

On Friday, September 12, 2014 at 09:23 CEST,  
Ali Kheyrollahi [aliostad@gmail.com](mailto:aliostad@gmail.com) wrote:

> On Friday, 12 September 2014 08:18:19 UTC+1, Ali Kheyrollahi wrote:
> 
> > I am trying to find numbers of discrete value per URL in a day and  
> > the result is not what I expect.

[...]

> > Result is bizarre, I mean it breaks my URL into its segments  
> > and aggregates on that. Do I need to use Hash of the URL (I prefer  
> > not to)?
> 
> OK, it seems that I need to use not\_analyzed on the field. Is that  
> correct?

Yes.

--  
Magnus Bäck | Software Engineer, Development Tools  
[magnus.back@sonymobile.com](mailto:magnus.back@sonymobile.com) | Sony Mobile Communications

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/20140912085425.GA9172%40seldlx20533.corpusers.net](https://groups.google.com/d/msgid/elasticsearch/20140912085425.GA9172%40seldlx20533.corpusers.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:02am UTC](https://discuss.elastic.co/t/discrete-value-aggregations-on-a-url-field/19751/4 "2017-07-06T01:02:48Z")

</div>


