# Elasticsearch query to match a field n number of times before giving result

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-to-match-a-field-n-number-of-times-before-giving-result/185036>\
**Category:** Elasticsearch\
**Created:** [June 10, 2019, 5:22pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-a-field-n-number-of-times-before-giving-result/185036 "2019-06-10T17:22:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elasticgeek](https://avatars.discourse-cdn.com/v4/letter/e/839c29/32.png) [@Elasticgeek](https://discuss.elastic.co/u/Elasticgeek)\
**Post date:** [June 10, 2019, 5:22pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-a-field-n-number-of-times-before-giving-result/185036/1 "2019-06-10T17:22:48Z")

</div>

I want to process the result if a field is occurring 'n' number of times while running a query. I am not referring to the count attribute where we get the total number but I want to get a result only if a particular field is occuring n number of times. Ideally i would do this outside the query but was wondering if there is a way to let the query itself handle this.

---

<div class="post-metadata">

**Author:** ![whatgeorgemade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whatgeorgemade/32/103246_2.png) [@whatgeorgemade](https://discuss.elastic.co/u/whatgeorgemade)\
**Post date:** [June 10, 2019, 6:00pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-a-field-n-number-of-times-before-giving-result/185036/2 "2019-06-10T18:00:09Z")

</div>

Can you give some examples of documents you're matching against, as well as which would and would not match? That way there are some concrete scenarios.

---

<div class="post-metadata">

**Author:** ![Elasticgeek](https://avatars.discourse-cdn.com/v4/letter/e/839c29/32.png) [@Elasticgeek](https://discuss.elastic.co/u/Elasticgeek)\
**Post date:** [June 10, 2019, 6:52pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-a-field-n-number-of-times-before-giving-result/185036/3 "2019-06-10T18:52:00Z")

</div>

Okay,

Consider the following:  
{  
"User": "John",  
"Action": "Failed login"  
"Timestamp": "2019-05-16 23:59:55"  
}  
.  
.  
.  
{  
"User": "John",  
"Action": "Logged in"  
"Timestamp": "2019-05-16 23:59:59"  
}

A user John tries to login but is unable to do so. In which case the first document applies. I can query and check for match and get the total hits for that user's 'Failed login'. That will give me the total number of times that user tried to login unsuccessfully. However, what i want is to check if the user is trying to login 'n' number of times before being successful.  
Is there a way to check that directly in the query itself. I want to avoid writing any additional code.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2019, 6:52pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-a-field-n-number-of-times-before-giving-result/185036/4 "2019-07-08T18:52:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
