# Elasticsearch group by having (aggs)

**URL:** <https://discuss.elastic.co/t/elasticsearch-group-by-having-aggs/46269>\
**Category:** Elasticsearch\
**Created:** [April 4, 2016, 5:09pm UTC](https://discuss.elastic.co/t/elasticsearch-group-by-having-aggs/46269 "2016-04-04T17:09:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rakesh76](https://avatars.discourse-cdn.com/v4/letter/r/839c29/32.png) [@rakesh76](https://discuss.elastic.co/u/rakesh76)\
**Post date:** [April 4, 2016, 5:09pm UTC](https://discuss.elastic.co/t/elasticsearch-group-by-having-aggs/46269/1 "2016-04-04T17:09:15Z")

</div>

I have following query.

```
POST test/_search?size=0
{
   "size": 0,
      "aggs": {
        "group_by_RequestID": {
          "terms": {
            "field": "RequestID"
          },
           "aggs": {
               "total_hits": {
                    "top_hits": {
                       "_source": {
                            "include": [
                                "_none"
                            ]
                        }
                }
            }
      }
    }
  }
}

```

Response:-

```
"aggregations": {
    "group_by_RequestID": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "20160209 132857.249_5420_1_DEN1100",
          "doc_count": 2,
          "total_hits": {
            "hits": {
              "total": 2,
              "max_score": 1,
              "hits": [
                {
                  "_index": "test",
                  "_type": "logs",
                  "_id": "20160209 132857.249_5420_1_DEN1100_Request",
                  "_score": 1,
                  "_source": {}
                },
                {
                  "_index": "test",
                  "_type": "logs",
                  "_id": "20160209 132857.249_5420_1_DEN1100_Response",
                  "_score": 1,
                  "_source": {}
                }
              ]
            }
          }
        },
        {
          "key": "20160209 132857.249_5420_1_SFO",
          "doc_count": 1,
          "total_hits": {
            "hits": {
              "total": 1,
              "max_score": 1,
              "hits": [
                {
                  "_index": "test",
                  "_type": "logs",
                  "_id": "20160209 132857.249_5420_1_SFO_Request",
                  "_score": 1,
                  "_source": {}
                }
              ]
            }
          } 

```

For each key I have Request and Response. my result should be the key where I don't have Response, so output should be "20160209 132857.249\_5420\_1\_SFO"

Also How can i get the number of key is missing Response.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:02pm UTC](https://discuss.elastic.co/t/elasticsearch-group-by-having-aggs/46269/2 "2017-07-05T23:02:31Z")

</div>


