# ElasticSearch Aggs Query

**URL:** <https://discuss.elastic.co/t/elasticsearch-aggs-query/45250>\
**Category:** Elasticsearch\
**Created:** [March 23, 2016, 4:06pm UTC](https://discuss.elastic.co/t/elasticsearch-aggs-query/45250 "2016-03-23T16:06:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rakesh76](https://avatars.discourse-cdn.com/v4/letter/r/839c29/32.png) [@rakesh76](https://discuss.elastic.co/u/rakesh76)\
**Post date:** [March 23, 2016, 4:06pm UTC](https://discuss.elastic.co/t/elasticsearch-aggs-query/45250/1 "2016-03-23T16:06:45Z")

</div>

I have a following elasticsearch query and result. I want something like group by with count(\*) =1 in sql statement

```
{
 "size": 0,
  "aggs": {
    "group_by_RequestID": {
      "terms": {
        "field": "RequestID"
      } 
  }
}
}

{
  "took": 1,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 12,
    "max_score": 0,
    "hits": []
  },
  "aggregations": {
    "group_by_RequestID": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "20160209 132857.249_5420_1_ATL",
          "doc_count": 2
        },
        {
          "key": "20160209 132857.249_5420_1_DEN1100",
          "doc_count": 2
        },
        {
          "key": "20160209 132857.249_5420_1_LAS",
          "doc_count": 2
        },
        {
          "key": "20160209 132857.249_5420_1_PHX1300",
          "doc_count": 2
        },
        {
          "key": "20160209 132857.249_5420_1_PHX1400",
          "doc_count": 2
        },
        {
          "key": "20160209 132857.249_5420_1_SFO",
          "doc_count": 2
        }
      ]
    }
  }
}

```

I want my result to be back where "doc\_count": 1, can you guide me how to get that result ?

---

<div class="post-metadata">

**Author:** ![SKumarMN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skumarmn/32/27537_2.png) [@SKumarMN](https://discuss.elastic.co/u/SKumarMN)\
**Post date:** [March 23, 2016, 4:08pm UTC](https://discuss.elastic.co/t/elasticsearch-aggs-query/45250/2 "2016-03-23T16:08:57Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/1.5/search-aggregations-metrics-top-hits-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.5/search-aggregations-metrics-top-hits-aggregation.html)

Try top hits Query

---

<div class="post-metadata">

**Author:** ![rakesh76](https://avatars.discourse-cdn.com/v4/letter/r/839c29/32.png) [@rakesh76](https://discuss.elastic.co/u/rakesh76)\
**Post date:** [March 23, 2016, 5:23pm UTC](https://discuss.elastic.co/t/elasticsearch-aggs-query/45250/3 "2016-03-23T17:23:18Z")

</div>

Thanks for your reply. As I am new to elasticsearch so trying to figure it out exact query..

```
POST test/_search?search_type=count
{
"aggs": {
    "group_by_RequestID": {
        "terms": {
            "field": "RequestID"
        },
        "aggs": {
            "group_by_RequestID_docs": {
                "top_hits": {
                    "size": 1
                }
            }
        }
    }
}
}

```

but it's not giving correct answer. I want only those records where there is only 1 records for RequestID

Thanks again..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:05pm UTC](https://discuss.elastic.co/t/elasticsearch-aggs-query/45250/4 "2017-07-05T23:05:46Z")

</div>


