# Facet: histogram with nested term count possible?

**URL:** <https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957>\
**Category:** Elasticsearch\
**Created:** [February 28, 2013, 7:23pm UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957 "2013-02-28T19:23:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Sanwald\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_sanwald_2/32/881_2.png) [@Paul\_Sanwald\_2](https://discuss.elastic.co/u/Paul_Sanwald_2)\
**Post date:** [February 28, 2013, 7:23pm UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/1 "2013-02-28T19:23:07Z")

</div>

Hi,  
I have an index of timestamped docs in elasticsearch, and I need to  
generate a list of top 10 term counts, for each day. Since I am lazy, I am  
trying to do this in elasticsearch as opposed to rolling up my sleeves and  
coding it myself. Following the faceting search visualization tutorial,  
I've got a nice date\_histogram, and from the earlier example, term counts  
are easy to do. Is this any way to nest a terms facet inside a  
date\_histogram facet, in such a way that the terms will be only given for a  
given date?

If there is no way to do this, and I'm going to code it by hand anyways,  
are there benefits/is it possible for me to write an elasticsearch plugin  
to do this kind of thing?

If it makes my question clearer, here's the two facets I'd like to nest  
(they are in parallel below, but I ultimately want to nest them):

{  
"query": {  
"query\_string": {  
"query": "T\*"  
}  
},  
"facets": {  
"published\_on": {  
"date\_histogram": {  
"field": "timestamp",  
"interval": "day"  
}  
},  
"term\_count": {  
"terms": {  
"field": "subject"  
}  
}  
}  
}

Ideally I would like something like

{  
"time": "1006300800000",  
"count": 130,  
"terms": [  
{  
"term": "re",  
"count": 1302  
},  
{  
"term": "fw",  
"count": 389  
}  
]  
}

Thanks for your help!

--paul

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 28, 2013, 7:41pm UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/2 "2013-02-28T19:41:41Z")

</div>

Not yet but with the facet refactoring, it will be possible in a next version.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 28 févr. 2013 à 20:23, Paul Sanwald [paul@redowlanalytics.com](mailto:paul@redowlanalytics.com) a écrit :

Hi,  
I have an index of timestamped docs in elasticsearch, and I need to generate a list of top 10 term counts, for each day. Since I am lazy, I am trying to do this in elasticsearch as opposed to rolling up my sleeves and coding it myself. Following the faceting search visualization tutorial, I've got a nice date\_histogram, and from the earlier example, term counts are easy to do. Is this any way to nest a terms facet inside a date\_histogram facet, in such a way that the terms will be only given for a given date?

If there is no way to do this, and I'm going to code it by hand anyways, are there benefits/is it possible for me to write an elasticsearch plugin to do this kind of thing?

If it makes my question clearer, here's the two facets I'd like to nest (they are in parallel below, but I ultimately want to nest them):

{  
"query": {  
"query\_string": {  
"query": "T\*"  
}  
},  
"facets": {  
"published\_on": {  
"date\_histogram": {  
"field": "timestamp",  
"interval": "day"  
}  
},  
"term\_count": {  
"terms": {  
"field": "subject"  
}  
}  
}  
}

Ideally I would like something like

{  
"time": "1006300800000",  
"count": 130,  
"terms": [  
{  
"term": "re",  
"count": 1302  
},  
{  
"term": "fw",  
"count": 389  
}  
]  
}

Thanks for your help!

## --paul

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Paul\_Sanwald\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_sanwald_2/32/881_2.png) [@Paul\_Sanwald\_2](https://discuss.elastic.co/u/Paul_Sanwald_2)\
**Post date:** [February 28, 2013, 8:07pm UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/3 "2013-02-28T20:07:32Z")

</div>

Great news! What's the ETA of the next version release? Is there anything I  
can do to help?

--paul

On Thursday, February 28, 2013 2:41:41 PM UTC-5, David Pilato wrote:

> Not yet but with the facet refactoring, it will be possible in a next  
> version.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 28 févr. 2013 à 20:23, Paul Sanwald \<[pa...@redowlanalytics.com](mailto:pa...@redowlanalytics.com)\<javascript:\>\>  
> a écrit :
> 
> Hi,  
> I have an index of timestamped docs in elasticsearch, and I need to  
> generate a list of top 10 term counts, for each day. Since I am lazy, I am  
> trying to do this in elasticsearch as opposed to rolling up my sleeves and  
> coding it myself. Following the faceting search visualization tutorial,  
> I've got a nice date\_histogram, and from the earlier example, term counts  
> are easy to do. Is this any way to nest a terms facet inside a  
> date\_histogram facet, in such a way that the terms will be only given for a  
> given date?
> 
> If there is no way to do this, and I'm going to code it by hand anyways,  
> are there benefits/is it possible for me to write an elasticsearch plugin  
> to do this kind of thing?
> 
> If it makes my question clearer, here's the two facets I'd like to nest  
> (they are in parallel below, but I ultimately want to nest them):
> 
> {  
> "query": {  
> "query\_string": {  
> "query": "T\*"  
> }  
> },  
> "facets": {  
> "published\_on": {  
> "date\_histogram": {  
> "field": "timestamp",  
> "interval": "day"  
> }  
> },  
> "term\_count": {  
> "terms": {  
> "field": "subject"  
> }  
> }  
> }  
> }
> 
> Ideally I would like something like
> 
> {  
> "time": "1006300800000",  
> "count": 130,  
> "terms": [  
> {  
> "term": "re",  
> "count": 1302  
> },  
> {  
> "term": "fw",  
> "count": 389  
> }  
> ]  
> }
> 
> Thanks for your help!
> 
> --paul
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [February 28, 2013, 8:15pm UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/4 "2013-02-28T20:15:32Z")

</div>

Considering the beta for 0.90 just come out, it might be a while before the  
next release.

[http://elasticsearch-users.115913.n3.nabble.com/Facets-Refactor-td4030599.html](http://elasticsearch-users.115913.n3.nabble.com/Facets-Refactor-td4030599.html)

On Thu, Feb 28, 2013 at 12:07 PM, Paul Sanwald [paul@redowlanalytics.com](mailto:paul@redowlanalytics.com)wrote:

> Great news! What's the ETA of the next version release? Is there anything  
> I can do to help?
> 
> --paul
> 
> On Thursday, February 28, 2013 2:41:41 PM UTC-5, David Pilato wrote:
> 
> > Not yet but with the facet refactoring, it will be possible in a next  
> > version.
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 28 févr. 2013 à 20:23, Paul Sanwald [pa...@redowlanalytics.com](mailto:pa...@redowlanalytics.com) a  
> > écrit :
> > 
> > Hi,  
> > I have an index of timestamped docs in elasticsearch, and I need to  
> > generate a list of top 10 term counts, for each day. Since I am lazy, I am  
> > trying to do this in elasticsearch as opposed to rolling up my sleeves and  
> > coding it myself. Following the faceting search visualization tutorial,  
> > I've got a nice date\_histogram, and from the earlier example, term counts  
> > are easy to do. Is this any way to nest a terms facet inside a  
> > date\_histogram facet, in such a way that the terms will be only given for a  
> > given date?
> > 
> > If there is no way to do this, and I'm going to code it by hand anyways,  
> > are there benefits/is it possible for me to write an elasticsearch plugin  
> > to do this kind of thing?
> > 
> > If it makes my question clearer, here's the two facets I'd like to nest  
> > (they are in parallel below, but I ultimately want to nest them):
> > 
> > {  
> > "query": {  
> > "query\_string": {  
> > "query": "T\*"  
> > }  
> > },  
> > "facets": {  
> > "published\_on": {  
> > "date\_histogram": {  
> > "field": "timestamp",  
> > "interval": "day"  
> > }  
> > },  
> > "term\_count": {  
> > "terms": {  
> > "field": "subject"  
> > }  
> > }  
> > }  
> > }
> > 
> > Ideally I would like something like
> > 
> > {  
> > "time": "1006300800000",  
> > "count": 130,  
> > "terms": [  
> > {  
> > "term": "re",  
> > "count": 1302  
> > },  
> > {  
> > "term": "fw",  
> > "count": 389  
> > }  
> > ]  
> > }
> > 
> > Thanks for your help!
> > 
> > --paul
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to elasticsearc...@\*\*[googlegroups.com](http://googlegroups.com).
> > 
> > For more options, visit [https://groups.google.com/\*\*groups/opt\_out](https://groups.google.com/**groups/opt_out)[https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out)  
> > .
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Boaz\_Leskes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/boaz_leskes/32/723_2.png) [@Boaz\_Leskes](https://discuss.elastic.co/u/Boaz_Leskes)\
**Post date:** [March 1, 2013, 8:16am UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/5 "2013-03-01T08:16:55Z")

</div>

Hi Paul,

We ran into a similar issue and I created plugin that can do it. Check out  
FacetedDateHistogram: [GitHub - bleskes/elasticfacets: A set of facets and related tools for ElasticSearch](https://github.com/bleskes/elasticfacets#faceted-date-histogram)

Hope it helps,  
Boaz

On Thursday, February 28, 2013 8:23:07 PM UTC+1, Paul Sanwald wrote:

> Hi,  
> I have an index of timestamped docs in elasticsearch, and I need to  
> generate a list of top 10 term counts, for each day. Since I am lazy, I am  
> trying to do this in elasticsearch as opposed to rolling up my sleeves and  
> coding it myself. Following the faceting search visualization tutorial,  
> I've got a nice date\_histogram, and from the earlier example, term counts  
> are easy to do. Is this any way to nest a terms facet inside a  
> date\_histogram facet, in such a way that the terms will be only given for a  
> given date?
> 
> If there is no way to do this, and I'm going to code it by hand anyways,  
> are there benefits/is it possible for me to write an elasticsearch plugin  
> to do this kind of thing?
> 
> If it makes my question clearer, here's the two facets I'd like to nest  
> (they are in parallel below, but I ultimately want to nest them):
> 
> {  
> "query": {  
> "query\_string": {  
> "query": "T\*"  
> }  
> },  
> "facets": {  
> "published\_on": {  
> "date\_histogram": {  
> "field": "timestamp",  
> "interval": "day"  
> }  
> },  
> "term\_count": {  
> "terms": {  
> "field": "subject"  
> }  
> }  
> }  
> }
> 
> Ideally I would like something like
> 
> {  
> "time": "1006300800000",  
> "count": 130,  
> "terms": [  
> {  
> "term": "re",  
> "count": 1302  
> },  
> {  
> "term": "fw",  
> "count": 389  
> }  
> ]  
> }
> 
> Thanks for your help!
> 
> --paul

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Paul\_Sanwald\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_sanwald_2/32/881_2.png) [@Paul\_Sanwald\_2](https://discuss.elastic.co/u/Paul_Sanwald_2)\
**Post date:** [March 8, 2013, 1:00am UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/6 "2013-03-08T01:00:29Z")

</div>

Boaz,  
I am using your plugin and it helps immensely. many thanks!

On Friday, March 1, 2013 3:16:55 AM UTC-5, Boaz Leskes wrote:

> Hi Paul,
> 
> We ran into a similar issue and I created plugin that can do it. Check out  
> FacetedDateHistogram:  
> [GitHub - bleskes/elasticfacets: A set of facets and related tools for ElasticSearch](https://github.com/bleskes/elasticfacets#faceted-date-histogram)
> 
> Hope it helps,  
> Boaz
> 
> On Thursday, February 28, 2013 8:23:07 PM UTC+1, Paul Sanwald wrote:
> 
> > Hi,  
> > I have an index of timestamped docs in elasticsearch, and I need to  
> > generate a list of top 10 term counts, for each day. Since I am lazy, I am  
> > trying to do this in elasticsearch as opposed to rolling up my sleeves and  
> > coding it myself. Following the faceting search visualization tutorial,  
> > I've got a nice date\_histogram, and from the earlier example, term counts  
> > are easy to do. Is this any way to nest a terms facet inside a  
> > date\_histogram facet, in such a way that the terms will be only given for a  
> > given date?
> > 
> > If there is no way to do this, and I'm going to code it by hand anyways,  
> > are there benefits/is it possible for me to write an elasticsearch plugin  
> > to do this kind of thing?
> > 
> > If it makes my question clearer, here's the two facets I'd like to nest  
> > (they are in parallel below, but I ultimately want to nest them):
> > 
> > {  
> > "query": {  
> > "query\_string": {  
> > "query": "T\*"  
> > }  
> > },  
> > "facets": {  
> > "published\_on": {  
> > "date\_histogram": {  
> > "field": "timestamp",  
> > "interval": "day"  
> > }  
> > },  
> > "term\_count": {  
> > "terms": {  
> > "field": "subject"  
> > }  
> > }  
> > }  
> > }
> > 
> > Ideally I would like something like
> > 
> > {  
> > "time": "1006300800000",  
> > "count": 130,  
> > "terms": [  
> > {  
> > "term": "re",  
> > "count": 1302  
> > },  
> > {  
> > "term": "fw",  
> > "count": 389  
> > }  
> > ]  
> > }
> > 
> > Thanks for your help!
> > 
> > --paul

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Srikanth\_gone](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@Srikanth\_gone](https://discuss.elastic.co/u/Srikanth_gone)\
**Post date:** [March 9, 2013, 10:58am UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/7 "2013-03-09T10:58:44Z")

</div>

HI David,

from java, i want fetch data..

Settings settings = ImmutableSettings.settingsBuilder()  
.put("http.enabled", "false")  
.put("transport.tcp.port", "9300-9400")  
.put("discovery.zen.ping.multicast.enabled", "false")  
.put("discovery.zen.ping.unicast.hosts", "localhost").build();

```
      Node node = NodeBuilder.nodeBuilder().client(true).settings(settings).clusterName("elasticsearch").node();
      client = node.client();

```

SearchResponse response = client.prepareSearch().execute().actionGet();

SearchHit[] results = response.getHits().getHits();  
System.out.println(results);  
for (SearchHit hit : results) {  
System.out.println(hit.getId()); //prints out the id of the document  
result = hit.getSource(); //the retrieved document  
System.out.println(result.keySet());  
}

its working fine.. fetch data all types..

but i am not able to search specific text..

i did like this..

SearchResponse response = client.prepareSearch("\_river")//"dc\_demo\_group\_idx","dc\_demo\_idx","dc\_demo\_user\_idx","dc\_rule\_metadata\_idx","dc\_lookup\_data\_idx","dc\_demo\_user\_idx","dc\_provider\_idx","dc\_topic\_idx"  
.setTypes("dc\_user\_river")  
.setSearchType(SearchType.DFS\_QUERY\_THEN\_FETCH)  
.setQuery(QueryBuilders.termQuery("firstName", "a"))  
.setFrom(0).setSize(60).setExplain(false)  
.execute()  
.actionGet();

respose is :

true{  
"took" : 0,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 1,  
"successful" : 1,  
"failed" : 0  
},  
"hits" : {  
"total" : 0,  
"max\_score" : null,  
"hits" : []  
}  
}  
[Lorg.elasticsearch.search.internal.InternalSearchHit;@1b84276

how to get the actual content

can you please help me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:47am UTC](https://discuss.elastic.co/t/facet-histogram-with-nested-term-count-possible/10957/8 "2017-07-06T02:47:23Z")

</div>


