# ElasticSearch double nested sorting

**URL:** <https://discuss.elastic.co/t/elasticsearch-double-nested-sorting/52520>\
**Category:** Elasticsearch\
**Created:** [June 12, 2016, 3:42am UTC](https://discuss.elastic.co/t/elasticsearch-double-nested-sorting/52520 "2016-06-12T03:42:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raman\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raman_goyal/32/10267_2.png) [@Raman\_Goyal](https://discuss.elastic.co/u/Raman_Goyal)\
**Post date:** [June 12, 2016, 3:42am UTC](https://discuss.elastic.co/t/elasticsearch-double-nested-sorting/52520/1 "2016-06-12T03:42:16Z")

</div>

I have documents which look like this (here is example):

```
{
"user": "xyz",
"state": "FINISHED",
"finishedTime": 1465566467161,
"jobCounters": {
    "counterGroup": [
        {
            "counterGroupName": "org.apache.hadoop.mapreduce.FileSystemCounter",
            "counter": [
                {
                    "name": "FILE_BYTES_READ",
                    "mapCounterValue": 206509212380,
                    "totalCounterValue": 423273933523,
                    "reduceCounterValue": 216764721143
                },
                {
                    "name": "FILE_BYTES_WRITTEN",
                    "mapCounterValue": 442799895522,
                    "totalCounterValue": 659742824735,
                    "reduceCounterValue": 216942929213
                },
                {
                    "name": "HDFS_BYTES_READ",
                    "mapCounterValue": 207913352565,
                    "totalCounterValue": 207913352565,
                    "reduceCounterValue": 0
                },
                {
                    "name": "HDFS_BYTES_WRITTEN",
                    "mapCounterValue": 0,
                    "totalCounterValue": 89846725044,
                    "reduceCounterValue": 89846725044
                }
            ]
        },
        {
            "counterGroupName": "org.apache.hadoop.mapreduce.JobCounter",
            "counter": [
                {
                    "name": "TOTAL_LAUNCHED_MAPS",
                    "mapCounterValue": 0,
                    "totalCounterValue": 13394,
                    "reduceCounterValue": 0
                },
                {
                    "name": "TOTAL_LAUNCHED_REDUCES",
                    "mapCounterValue": 0,
                    "totalCounterValue": 720,
                    "reduceCounterValue": 0
                }
            ]
        }
    ]
}

```

}

Now I want to `sort` this data to get TOP 15 documents on the basis of `totalCounterValue` where `counter.name` is `FILE_BYTES_READ`. I have tried nested sorting on this but no matter which key name I write in `counter.name`, it is always sorting on the basis of `HDFS_BYTES_READ`. Can anyone please help me with my query.

```
{
"_source": true,
"size": 15,
"query": {
    "bool": {
        "must": [
            {
                "term": {
                    "state": {
                        "value": "FINISHED"
                    }
                }
            },
            {
                "range": {
                    "startedTime": {
                        "gte": "now - 4d",
                        "lte": "now"
                    }
                }
            }
        ]
    }
},
"sort": [
    {
        "jobCounters.counterGroup.counter.totalCounterValue": {
            "order": "desc",
            "nested_path": "jobCounters.counterGroup",
            "nested_filter": {
                "nested": {
                    "path": "jobCounters.counterGroup.counter",
                    "filter": {
                        "term": {
                            "jobCounters.counterGroup.counter.name": "file_bytes_read"
                        }
                    }
                }
            }
        }
    }
]

```

}

I followed nested sorting documentation of ElasticSearch and came up with this query, but I don't know why it is always sorting the `totalCounterValue` of `HDFS_BYTES_READ` irrespective of `jobCounters.counterGroup.counter.name`'s value.

---

<div class="post-metadata">

**Author:** ![Raman\_Goyal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raman_goyal/32/10267_2.png) [@Raman\_Goyal](https://discuss.elastic.co/u/Raman_Goyal)\
**Post date:** [June 12, 2016, 9:15am UTC](https://discuss.elastic.co/t/elasticsearch-double-nested-sorting/52520/2 "2016-06-12T09:15:47Z")

</div>

This is the mapping we are using for jobCounters:

```
"jobCounters": {
      	"type": "nested",
      	"include_in_parent": true,
        "properties" : {
          "counterGroup": {
           "type": "nested",
      		"include_in_parent": true,
            "properties": {
              "counterGroupName": {
                "type": "string",
        		"fields": {
   					"raw": { 
        				"type": "string",
        				"index": "not_analyzed"
    					}
    				}
              },
              "counter" : {
					"type": "nested",
      		  		"include_in_parent": true,
              		"properties": {
              			"reduceCounterValue": {
               				"type": "long"
            			},
            			"name": {
                			"type": "string",
        					"analyzer": "english",
							"fields": {
   								"raw": { 
        							"type": "string",
        							"index": "not_analyzed"
    							}
    						}
            			},
            			"totalCounterValue": {
               				"type": "long"
            			},
          				"mapCounterValue": {
               				"type": "long"
            			}                	
            		}                	
            	}                	 
            }
          }
        }
    }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:44pm UTC](https://discuss.elastic.co/t/elasticsearch-double-nested-sorting/52520/3 "2017-07-05T22:44:33Z")

</div>


