# ElasticSearch - Filter Buckets

**URL:** <https://discuss.elastic.co/t/elasticsearch-filter-buckets/259758>\
**Category:** Elasticsearch\
**Created:** [December 28, 2020, 7:11pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-buckets/259758 "2020-12-28T19:11:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![FuSsA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fussa/32/81483_2.png) [@FuSsA](https://discuss.elastic.co/u/FuSsA)\
**Post date:** [December 28, 2020, 7:11pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-buckets/259758/1 "2020-12-28T19:11:28Z")

</div>

Hey ES community,

My elasticSearch query is like:

```
{
    "size": 0,
    "aggs": {
        "group_by_id": {
            "terms": {
                "field": "Infos.InstanceInfo.ID.keyword",
                "size": 1000
            },
            "aggs": {
                "tops": {
                    "top_hits": {
                        "size": 100,
                        "sort": {
                            "Infos.InstanceInfo.StartTime": "asc"
                        }
                    }
                }
            }
        }
    }
}

```

It works fine, I have a result of this form:

```
aggregations
=========>group_by_id
==============>buckets
                {key:id1}
                ===============>docs
                {doc1.Status:"KO"}
                {doc2.Status:"KO"}
                
                {key:id2}
                ===============>docs
                {doc1.Status:"KO"}
                {doc2.Status:"OK"}
                
                {key:id3}
                ===============>docs
                {doc1.Status:"KO"}
                {doc2.Status:"OK"}

```

I'm trying to add a filter, so when "KO" the result must be only ids having all docs "KO", id1 for our exemple:

```
aggregations
=========>group_by_id
==============>buckets
                {key:id1}
                ===============>docs
                {doc1.Status:"KO"}
                {doc2.Status:"KO"}

```

And a second query with an "OK" filter, to display all the ids having at least one doc with "OK", ids 2 & 3 for our example, the result should be like this:

```
aggregations
=========>group_by_id
==============>buckets
                {key:id2}
                ===============>docs
                {doc1.Status:"KO"}
                {doc2.Status:"OK"}
                
                {key:id3}
                ===============>docs
                {doc1.Status:"KO"}
                {doc2.Status:"OK"}

```

Fields " **Startime**" & " **Status**" are at the same level " **Infos.InstanceInfo.** [...]" .

Any idea?

Thanks you in advance

---

<div class="post-metadata">

**Author:** ![FuSsA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fussa/32/81483_2.png) [@FuSsA](https://discuss.elastic.co/u/FuSsA)\
**Post date:** [December 29, 2020, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-buckets/259758/2 "2020-12-29T15:47:29Z")

</div>

Can the expected result be achieved by a request?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2021, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-buckets/259758/3 "2021-01-26T15:47:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
