# Distinct key value pairs

**URL:** <https://discuss.elastic.co/t/distinct-key-value-pairs/15759>\
**Category:** Elasticsearch\
**Created:** [February 12, 2014, 4:13pm UTC](https://discuss.elastic.co/t/distinct-key-value-pairs/15759 "2014-02-12T16:13:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![atoomkern](https://avatars.discourse-cdn.com/v4/letter/a/858c86/32.png) [@atoomkern](https://discuss.elastic.co/u/atoomkern)\
**Post date:** [February 12, 2014, 4:13pm UTC](https://discuss.elastic.co/t/distinct-key-value-pairs/15759/1 "2014-02-12T16:13:11Z")

</div>

I would like to be able to search all fields for a certain string and get  
all distinct matching key value pairs as a result. It should also be  
possible to add filters/queries to constrain the results. The original data  
consists of millions of documents and a few thousand possible keys so I  
simplified the data into the example below.

_Mapping_

{  
"example\_index": {  
"example\_type": {  
"properties": {  
"name": {"type":"string"},  
"description": {"type":"string"},  
"gender": {"type":"string"}  
}  
}  
}  
}

_Data_

{  
"name": "John",  
"job": "pilot",  
"gender": "male"  
},  
{  
"name": "Eric",  
"job": "pilot",  
"gender": "male"  
},  
{  
"name": "Marie",  
"job": "ceo",  
"gender": "female"  
}

_Needed results_

For example searching all fields for “ma” should return:

{  
"gender": "male", _(1x)_  
"gender": "female",  
"name": "Marie"  
}

Searching all fields for “ma” in combination with the query “job”: ”pilot”,  
should return only:

{  
"gender": "male" _(1x)_  
}

_Aggregation_

With the aggregation framework this would partly be possible with the  
following code:

{  
"from" : "0",  
"size" : "0",  
"query": {  
"match" : {  
"job": "pilot"  
}  
},  
"aggs" : {  
"test" : {  
"terms" : {  
"field" : "\_all",  
"include" : "._ma._"  
}  
}  
}  
}

But it only returns the unique values without the keys.

Does anyone have a suggestion to get the needed distinct key value pairs  
with the aggregation framework or an other option in Elasticsearch?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/33dd2dda-ddb3-4b41-b7f1-fa62aee76ef9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/33dd2dda-ddb3-4b41-b7f1-fa62aee76ef9%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Binh\_Ly](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@Binh\_Ly](https://discuss.elastic.co/u/Binh_Ly)\
**Post date:** [February 13, 2014, 3:08pm UTC](https://discuss.elastic.co/t/distinct-key-value-pairs/15759/2 "2014-02-13T15:08:32Z")

</div>

Not that I would recommend this for millions of documents, but you can  
script the term values for the terms aggregation. For example, below will  
produce a count of the distinct combinations of gender and job.

{  
"aggs": {  
"t1": {  
"terms": {  
"script": "doc['gender'].value + doc['job'].value"  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0b8e9117-800c-4e1b-a916-f74127dcb377%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0b8e9117-800c-4e1b-a916-f74127dcb377%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [February 13, 2014, 4:38pm UTC](https://discuss.elastic.co/t/distinct-key-value-pairs/15759/3 "2014-02-13T16:38:47Z")

</div>

Check if nested docs

[http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-nested-type.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-nested-type.html)

match your requirements.

Jörg

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoF7k2OOFWJ1YMR1fTo8R8C6bc4bWXHk5UBUJfzjg\_q-Xw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoF7k2OOFWJ1YMR1fTo8R8C6bc4bWXHk5UBUJfzjg_q-Xw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:50am UTC](https://discuss.elastic.co/t/distinct-key-value-pairs/15759/4 "2017-07-06T01:50:27Z")

</div>


