# Filter output of term facet - not input

**URL:** <https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806>\
**Category:** Elasticsearch\
**Created:** [February 19, 2013, 6:39pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806 "2013-02-19T18:39:07Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ripplekhera](https://avatars.discourse-cdn.com/v4/letter/r/aeb1de/32.png) [@ripplekhera](https://discuss.elastic.co/u/ripplekhera)\
**Post date:** [February 19, 2013, 6:39pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/1 "2013-02-19T18:39:07Z")

</div>

I've read the elasticsearch api docs and done a lot of googling but still  
cannot find a solution. I need to only output filtered items from the  
faceted term search. So posting here.

Here is some sample data:  
{  
id: 1e27202c54a0a600e06257c0ae341e8e  
interaction\_type: bitly  
url:  
created\_at: 2013-02-08T15:18:34.000Z  
epoch: 1360336714000  
tags: [  
userid\_5114575ae4b0cb71b6654320,  
username\_testuser1,  
microsoft  
]  
geo\_latitude: 51.900002  
geo\_longitude: 8.3833  
geo\_city: Gütersloh  
geo\_country\_code: DE  
geo\_country: Germany  
geo\_region\_code: 07  
geo\_region: Nordrhein-Westfalen  
}  
{  
id: 1e27202c2e7aac00e062d233dde576aa  
interaction\_type: bitly  
url:  
created\_at: 2013-02-08T15:18:28.000Z  
epoch: 1360336708000  
tags: [  
userid\_5114575ae4b0cb71b6654321,  
username\_testuser2,  
kinect  
]  
geo\_latitude: 23.051201  
geo\_longitude: 112.459702  
geo\_city: Zhaoqing  
geo\_country\_code: CN  
geo\_country: China  
geo\_region\_code: 30  
geo\_region: Guangdong  
}

I want to find the number of occurrences for a bunch of user-ids for a  
range of times. I came up with a filtered and faceted query like so:

{  
"query": {  
"range": {  
"created\_at": { "from": "now-10d", "to": "now"}  
}  
},  
"from": 0,  
"size": 0,  
"facets": {  
"tag\_facet": {  
"terms": {"field": "tags"},  
"facet\_filter": {  
"or": [  
{ "term": { "tags": "userid\_5114575ae4b0cb71b6654321" } },  
{ "term": { "tags": "userid\_5114575ae4b0cb71b6654320" } }  
]  
}  
}  
}  
}

The result I get is :

facets: {  
tag\_facet: {  
\_type: terms  
missing: 0  
total: 1947503  
other: 305  
terms: [  
{term: username\_testuser1,count: 539453}  
{term: userid\_5114575ae4b0cb71b6654320,count: 539453}  
{term: iphone,count: 245888}  
{term: microsoft,count: 193543}  
{term: userid\_50f06636e4b0560131c8730c,count: 107155}  
{term: kinect,count: 101051}  
]  
}

The result I get also includes counts for other tags like username\_testuser1,  
microsoft, kinect etc. I dont want those results, only the counts for x  
number of user-ids using [or] filters, where I will limit x to not more  
than 10.

Any guidance on how to solve this? There could be 1000s of results and I  
dont want to iterate through them in the app layer to find the two items  
that are needed.

Thanks!  
-Ripple

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [February 19, 2013, 6:56pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/2 "2013-02-19T18:56:30Z")

</div>

The facet filters will filter out which results to facet on, not filter out  
the facets that are returned.

In your example, your first document has  
tags: [  
userid\_5114575ae4b0cb71b6654320,  
username\_testuser1,  
microsoft  
]

Since this document passed the filter, all those values will be used for  
the facet. You would need to iterate through them in the app layer.

--  
Ivan

On Tue, Feb 19, 2013 at 10:39 AM, ripplekhera [ripplekhera@gmail.com](mailto:ripplekhera@gmail.com) wrote:

> I've read the elasticsearch api docs and done a lot of googling but still  
> cannot find a solution. I need to only output filtered items from the  
> faceted term search. So posting here.
> 
> Here is some sample data:  
> {  
> id: 1e27202c54a0a600e06257c0ae341e8e  
> interaction\_type: bitly  
> url:  
> created\_at: 2013-02-08T15:18:34.000Z  
> epoch: 1360336714000  
> tags: [  
> userid\_5114575ae4b0cb71b6654320,  
> username\_testuser1,  
> microsoft  
> ]  
> geo\_latitude: 51.900002  
> geo\_longitude: 8.3833  
> geo\_city: Gütersloh  
> geo\_country\_code: DE  
> geo\_country: Germany  
> geo\_region\_code: 07  
> geo\_region: Nordrhein-Westfalen  
> }  
> {  
> id: 1e27202c2e7aac00e062d233dde576aa  
> interaction\_type: bitly  
> url:  
> created\_at: 2013-02-08T15:18:28.000Z  
> epoch: 1360336708000  
> tags: [  
> userid\_5114575ae4b0cb71b6654321,  
> username\_testuser2,  
> kinect  
> ]  
> geo\_latitude: 23.051201  
> geo\_longitude: 112.459702  
> geo\_city: Zhaoqing  
> geo\_country\_code: CN  
> geo\_country: China  
> geo\_region\_code: 30  
> geo\_region: Guangdong  
> }
> 
> I want to find the number of occurrences for a bunch of user-ids for a  
> range of times. I came up with a filtered and faceted query like so:
> 
> {  
> "query": {  
> "range": {  
> "created\_at": { "from": "now-10d", "to": "now"}  
> }  
> },  
> "from": 0,  
> "size": 0,  
> "facets": {  
> "tag\_facet": {  
> "terms": {"field": "tags"},  
> "facet\_filter": {  
> "or": [  
> { "term": { "tags": "userid\_5114575ae4b0cb71b6654321" } },  
> { "term": { "tags": "userid\_5114575ae4b0cb71b6654320" } }  
> ]  
> }  
> }  
> }  
> }
> 
> The result I get is :
> 
> facets: {  
> tag\_facet: {  
> \_type: terms  
> missing: 0  
> total: 1947503  
> other: 305  
> terms: [  
> {term: username\_testuser1,count: 539453}  
> {term: userid\_5114575ae4b0cb71b6654320,count: 539453}  
> {term: iphone,count: 245888}  
> {term: microsoft,count: 193543}  
> {term: userid\_50f06636e4b0560131c8730c,count: 107155}  
> {term: kinect,count: 101051}  
> ]  
> }
> 
> The result I get also includes counts for other tags like username\_testuser1,  
> microsoft, kinect etc. I dont want those results, only the counts for x  
> number of user-ids using [or] filters, where I will limit x to not more  
> than 10.
> 
> Any guidance on how to solve this? There could be 1000s of results and I  
> dont want to iterate through them in the app layer to find the two items  
> that are needed.
> 
> Thanks!  
> -Ripple
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![ripplekhera](https://avatars.discourse-cdn.com/v4/letter/r/aeb1de/32.png) [@ripplekhera](https://discuss.elastic.co/u/ripplekhera)\
**Post date:** [February 19, 2013, 9:16pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/3 "2013-02-19T21:16:39Z")

</div>

Oh well. I had a feeling it couldn't be done. Thanks for verifying my  
thoughts.

On Tuesday, February 19, 2013 10:56:30 AM UTC-8, Ivan Brusic wrote:

> The facet filters will filter out which results to facet on, not filter  
> out the facets that are returned.
> 
> In your example, your first document has  
> tags: [  
> userid\_5114575ae4b0cb71b6654320,  
> username\_testuser1,  
> microsoft  
> ]
> 
> Since this document passed the filter, all those values will be used for  
> the facet. You would need to iterate through them in the app layer.
> 
> --  
> Ivan
> 
> On Tue, Feb 19, 2013 at 10:39 AM, ripplekhera \<[rippl...@gmail.com](mailto:rippl...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > I've read the elasticsearch api docs and done a lot of googling but still  
> > cannot find a solution. I need to only output filtered items from the  
> > faceted term search. So posting here.
> > 
> > Here is some sample data:  
> > {  
> > id: 1e27202c54a0a600e06257c0ae341e8e  
> > interaction\_type: bitly  
> > url:  
> > created\_at: 2013-02-08T15:18:34.000Z  
> > epoch: 1360336714000  
> > tags: [  
> > userid\_5114575ae4b0cb71b6654320,  
> > username\_testuser1,  
> > microsoft  
> > ]  
> > geo\_latitude: 51.900002  
> > geo\_longitude: 8.3833  
> > geo\_city: Gütersloh  
> > geo\_country\_code: DE  
> > geo\_country: Germany  
> > geo\_region\_code: 07  
> > geo\_region: Nordrhein-Westfalen  
> > }  
> > {  
> > id: 1e27202c2e7aac00e062d233dde576aa  
> > interaction\_type: bitly  
> > url:  
> > created\_at: 2013-02-08T15:18:28.000Z  
> > epoch: 1360336708000  
> > tags: [  
> > userid\_5114575ae4b0cb71b6654321,  
> > username\_testuser2,  
> > kinect  
> > ]  
> > geo\_latitude: 23.051201  
> > geo\_longitude: 112.459702  
> > geo\_city: Zhaoqing  
> > geo\_country\_code: CN  
> > geo\_country: China  
> > geo\_region\_code: 30  
> > geo\_region: Guangdong  
> > }
> > 
> > I want to find the number of occurrences for a bunch of user-ids for a  
> > range of times. I came up with a filtered and faceted query like so:
> > 
> > {  
> > "query": {  
> > "range": {  
> > "created\_at": { "from": "now-10d", "to": "now"}  
> > }  
> > },  
> > "from": 0,  
> > "size": 0,  
> > "facets": {  
> > "tag\_facet": {  
> > "terms": {"field": "tags"},  
> > "facet\_filter": {  
> > "or": [  
> > { "term": { "tags": "userid\_5114575ae4b0cb71b6654321" } },  
> > { "term": { "tags": "userid\_5114575ae4b0cb71b6654320" } }  
> > ]  
> > }  
> > }  
> > }  
> > }
> > 
> > The result I get is :
> > 
> > facets: {  
> > tag\_facet: {  
> > \_type: terms  
> > missing: 0  
> > total: 1947503  
> > other: 305  
> > terms: [  
> > {term: username\_testuser1,count: 539453}  
> > {term: userid\_5114575ae4b0cb71b6654320,count: 539453}  
> > {term: iphone,count: 245888}  
> > {term: microsoft,count: 193543}  
> > {term: userid\_50f06636e4b0560131c8730c,count: 107155}  
> > {term: kinect,count: 101051}  
> > ]  
> > }
> > 
> > The result I get also includes counts for other tags like username\_testuser1,  
> > microsoft, kinect etc. I dont want those results, only the counts for x  
> > number of user-ids using [or] filters, where I will limit x to not more  
> > than 10.
> > 
> > Any guidance on how to solve this? There could be 1000s of results and I  
> > dont want to iterate through them in the app layer to find the two items  
> > that are needed.
> > 
> > Thanks!  
> > -Ripple
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![roytmana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roytmana/32/44855_2.png) [@roytmana](https://discuss.elastic.co/u/roytmana)\
**Post date:** [February 19, 2013, 9:43pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/4 "2013-02-19T21:43:40Z")

</div>

Maybe I am missing something but why not add filter on user to your query then you will limit your resultset and facets will only have the user you want

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![mattweber](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattweber/32/44940_2.png) [@mattweber](https://discuss.elastic.co/u/mattweber)\
**Post date:** [February 19, 2013, 10:09pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/5 "2013-02-19T22:09:25Z")

</div>

Actually you have two options:

1. Use you can exclude tags you don't want counted (ie. microsoft,  
kinect, etc)
2. Use a regex pattern for the terms you want included.

#2 would be my choice because it looks like you can do a basic  
expression such as "username\_.\*$" or even looking for your specific  
users "userid\_5114575ae4b0cb71b6654321|userid\_5114575ae4b0cb71b6654320"

See the section on excluding terms and regex patterns here:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Hope this helps.

Thanks,  
Matt Weber

On Tue, Feb 19, 2013 at 1:43 PM, AlexR [roytmana@gmail.com](mailto:roytmana@gmail.com) wrote:

> Maybe I am missing something but why not add filter on user to your query then you will limit your resultset and facets will only have the user you want
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![ripplekhera](https://avatars.discourse-cdn.com/v4/letter/r/aeb1de/32.png) [@ripplekhera](https://discuss.elastic.co/u/ripplekhera)\
**Post date:** [February 21, 2013, 10:31pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/6 "2013-02-21T22:31:52Z")

</div>

Matt, thank you very much for the regex suggestion. It is awesome. This is  
a sample of my resulted query. I think providing both a query filter and  
facet filter might be overkill so I might remove it, but it works:

{  
"size" : 0,  
"query" : {  
"filtered" : {  
"query" : {  
"bool" : {  
"must" : {  
"range" : {"created\_at" : {"from" : "now-30d","to" : "now",  
"include\_lower" : true,  
"include\_upper" : true  
}  
}  
}  
}  
},  
"filter" : {  
"or" : {  
"filters" : [ {"term" : {"tags" :  
"userid\_50fd9f5373e13056e76f9e7f"}},  
{"term" : {"tags" : "userid\_51007ef3e4b0a99e8714a9e9"}},  
{"term" : {"tags" : "userid\_50e228cae4b05800e6ea1ef2"}},  
{"term" : {"tags" : "userid\_50fdaee7e4b05ced2d76710e"}},  
{"term" : {"tags" : "userid\_50c6dfdee4b030a63367a6e7"}},  
{"term" : {"tags" : "userid\_50f4680ce4b080e3535795dc"}},  
{"term" : {"tags" : "userid\_50ddf00ae4b000084a2dc057"}},  
{"term" : { "tags" : "userid\_50c6e080e4b030a63367a6e9" }},  
{"term" : {"tags" : "userid\_50f06636e4b0560131c8730c" }} ]  
}  
}  
}  
},  
"fields" : ["id", "tags"],  
"facets" : {  
"usageFacet" : {  
"terms" : {  
"field" : "tags",  
"size" : 9,  
"regex" : "userid\_.\*$"  
},  
"facet\_filter" : {  
"or" : {  
"filters" : [ {"term" : {"tags" :  
"userid\_50fd9f5373e13056e76f9e7f"}},  
{"term" : {"tags" : "userid\_51007ef3e4b0a99e8714a9e9"}},  
{"term" : {"tags" : "userid\_50e228cae4b05800e6ea1ef2"}},  
{"term" : {"tags" : "userid\_50fdaee7e4b05ced2d76710e"}},  
{"term" : {"tags" : "userid\_50c6dfdee4b030a63367a6e7"}},  
{"term" : {"tags" : "userid\_50f4680ce4b080e3535795dc"}},  
{"term" : {"tags" : "userid\_50ddf00ae4b000084a2dc057"}},  
{"term" : { "tags" : "userid\_50c6e080e4b030a63367a6e9" }},  
{"term" : {"tags" : "userid\_50f06636e4b0560131c8730c" }} ]  
}  
}  
}  
}  
}

Another option could have been to use the query facet. But this one serves  
better.  
The query facet is available at :

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On Tuesday, February 19, 2013 2:09:25 PM UTC-8, Matt Weber wrote:

> Actually you have two options:
> 
> 1. Use you can exclude tags you don't want counted (ie. microsoft,  
> kinect, etc)
> 2. Use a regex pattern for the terms you want included.
> 
> #2 would be my choice because it looks like you can do a basic  
> expression such as "username\_.\*$" or even looking for your specific  
> users "userid\_5114575ae4b0cb71b6654321|userid\_5114575ae4b0cb71b6654320"
> 
> See the section on excluding terms and regex patterns here:
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/terms-facet.html)
> 
> Hope this helps.
> 
> Thanks,  
> Matt Weber
> 
> On Tue, Feb 19, 2013 at 1:43 PM, AlexR \<[royt...@gmail.com](mailto:royt...@gmail.com) \<javascript:\>\>  
> wrote:
> 
> > Maybe I am missing something but why not add filter on user to your  
> > query then you will limit your resultset and facets will only have the user  
> > you want
> > 
> > --  
> > You received this message because you are subscribed to the Google  
> > Groups "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send  
> > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![mattweber](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattweber/32/44940_2.png) [@mattweber](https://discuss.elastic.co/u/mattweber)\
**Post date:** [February 21, 2013, 10:49pm UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/7 "2013-02-21T22:49:08Z")

</div>

Yea, lose the facet filter. Move it up as another "must" clause to  
your boolean query filter and don't use an "or" filter, use a  
TermsFilter as that will give you better performance.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On Thu, Feb 21, 2013 at 2:31 PM, ripplekhera [ripplekhera@gmail.com](mailto:ripplekhera@gmail.com) wrote:

> Matt, thank you very much for the regex suggestion. It is awesome. This is a  
> sample of my resulted query. I think providing both a query filter and facet  
> filter might be overkill so I might remove it, but it works:
> 
> {  
> "size" : 0,  
> "query" : {  
> "filtered" : {  
> "query" : {  
> "bool" : {  
> "must" : {  
> "range" : {"created\_at" : {"from" : "now-30d","to" : "now",  
> "include\_lower" : true,  
> "include\_upper" : true  
> }  
> }  
> }  
> }  
> },  
> "filter" : {  
> "or" : {  
> "filters" : [ {"term" : {"tags" :  
> "userid\_50fd9f5373e13056e76f9e7f"}},  
> {"term" : {"tags" : "userid\_51007ef3e4b0a99e8714a9e9"}},  
> {"term" : {"tags" : "userid\_50e228cae4b05800e6ea1ef2"}},  
> {"term" : {"tags" : "userid\_50fdaee7e4b05ced2d76710e"}},  
> {"term" : {"tags" : "userid\_50c6dfdee4b030a63367a6e7"}},  
> {"term" : {"tags" : "userid\_50f4680ce4b080e3535795dc"}},  
> {"term" : {"tags" : "userid\_50ddf00ae4b000084a2dc057"}},  
> {"term" : { "tags" : "userid\_50c6e080e4b030a63367a6e9" }},  
> {"term" : {"tags" : "userid\_50f06636e4b0560131c8730c" }} ]  
> }  
> }  
> }  
> },  
> "fields" : ["id", "tags"],  
> "facets" : {  
> "usageFacet" : {  
> "terms" : {  
> "field" : "tags",  
> "size" : 9,  
> "regex" : "userid\_.\*$"  
> },  
> "facet\_filter" : {  
> "or" : {  
> "filters" : [ {"term" : {"tags" :  
> "userid\_50fd9f5373e13056e76f9e7f"}},  
> {"term" : {"tags" : "userid\_51007ef3e4b0a99e8714a9e9"}},  
> {"term" : {"tags" : "userid\_50e228cae4b05800e6ea1ef2"}},  
> {"term" : {"tags" : "userid\_50fdaee7e4b05ced2d76710e"}},  
> {"term" : {"tags" : "userid\_50c6dfdee4b030a63367a6e7"}},  
> {"term" : {"tags" : "userid\_50f4680ce4b080e3535795dc"}},  
> {"term" : {"tags" : "userid\_50ddf00ae4b000084a2dc057"}},  
> {"term" : { "tags" : "userid\_50c6e080e4b030a63367a6e9" }},  
> {"term" : {"tags" : "userid\_50f06636e4b0560131c8730c" }} ]  
> }  
> }  
> }  
> }  
> }
> 
> Another option could have been to use the query facet. But this one serves  
> better.  
> The query facet is available at :  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/query-facet.html)
> 
> On Tuesday, February 19, 2013 2:09:25 PM UTC-8, Matt Weber wrote:
> 
> > Actually you have two options:
> > 
> > 1. Use you can exclude tags you don't want counted (ie. microsoft,  
> > kinect, etc)
> > 2. Use a regex pattern for the terms you want included.
> > 
> > #2 would be my choice because it looks like you can do a basic  
> > expression such as "username\_.\*$" or even looking for your specific  
> > users "userid\_5114575ae4b0cb71b6654321|userid\_5114575ae4b0cb71b6654320"
> > 
> > See the section on excluding terms and regex patterns here:
> > 
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/terms-facet.html)
> > 
> > Hope this helps.
> > 
> > Thanks,  
> > Matt Weber
> > 
> > On Tue, Feb 19, 2013 at 1:43 PM, AlexR [royt...@gmail.com](mailto:royt...@gmail.com) wrote:
> > 
> > > Maybe I am missing something but why not add filter on user to your  
> > > query then you will limit your resultset and facets will only have the user  
> > > you want
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![ripplekhera](https://avatars.discourse-cdn.com/v4/letter/r/aeb1de/32.png) [@ripplekhera](https://discuss.elastic.co/u/ripplekhera)\
**Post date:** [February 22, 2013, 1:48am UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/8 "2013-02-22T01:48:48Z")

</div>

Once again more thanks. Refined it further:

{  
"size" : 0,  
"query" : {  
"bool" : {  
"must" : [ {  
"range" : {  
"created\_at" : {  
"from" : "now-30d",  
"to" : "now",  
"include\_lower" : true,  
"include\_upper" : true  
}  
}  
}, {  
"terms" : {  
"tags" : [ "userid\_511a8b7ae4b041a03f7fb05a",  
"userid\_511bd133e4b051c4e5f5a6a9", "userid\_511bd195e4b051c4e5f5a6ab",  
"userid\_511bd223e4b051c4e5f5a6ae", "userid\_5123f4a4e4b0f7e78834fd1a",  
"userid\_51149015e4b02131feaf81bd", "userid\_511d8916e4b075a52833d23e",  
"userid\_511e6e3fe4b075a52833d243", "userid\_511d89a8e4b075a52833d23f",  
"userid\_5112ea0e4f7ecb3372000003" ]  
}  
} ]  
}  
},  
"fields" : ["id", "tags"],  
"facets" : {  
"usage\_facet" : {  
"terms" : {  
"field" : "tags",  
"size" : 10,  
"regex" : "userid\_.\*$"  
}  
}  
}  
}

On Thursday, February 21, 2013 2:49:08 PM UTC-8, Matt Weber wrote:

> Yea, lose the facet filter. Move it up as another "must" clause to  
> your boolean query filter and don't use an "or" filter, use a  
> TermsFilter as that will give you better performance.  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/terms-filter.html)
> 
> On Thu, Feb 21, 2013 at 2:31 PM, ripplekhera \<[rippl...@gmail.com](mailto:rippl...@gmail.com)\<javascript:\>\>  
> wrote:
> 
> > Matt, thank you very much for the regex suggestion. It is awesome. This  
> > is a  
> > sample of my resulted query. I think providing both a query filter and  
> > facet  
> > filter might be overkill so I might remove it, but it works:
> > 
> > {  
> > "size" : 0,  
> > "query" : {  
> > "filtered" : {  
> > "query" : {  
> > "bool" : {  
> > "must" : {  
> > "range" : {"created\_at" : {"from" : "now-30d","to" : "now",  
> > "include\_lower" : true,  
> > "include\_upper" : true  
> > }  
> > }  
> > }  
> > }  
> > },  
> > "filter" : {  
> > "or" : {  
> > "filters" : [ {"term" : {"tags" :  
> > "userid\_50fd9f5373e13056e76f9e7f"}},  
> > {"term" : {"tags" : "userid\_51007ef3e4b0a99e8714a9e9"}},  
> > {"term" : {"tags" : "userid\_50e228cae4b05800e6ea1ef2"}},  
> > {"term" : {"tags" : "userid\_50fdaee7e4b05ced2d76710e"}},  
> > {"term" : {"tags" : "userid\_50c6dfdee4b030a63367a6e7"}},  
> > {"term" : {"tags" : "userid\_50f4680ce4b080e3535795dc"}},  
> > {"term" : {"tags" : "userid\_50ddf00ae4b000084a2dc057"}},  
> > {"term" : { "tags" : "userid\_50c6e080e4b030a63367a6e9" }},  
> > {"term" : {"tags" : "userid\_50f06636e4b0560131c8730c" }} ]  
> > }  
> > }  
> > }  
> > },  
> > "fields" : ["id", "tags"],  
> > "facets" : {  
> > "usageFacet" : {  
> > "terms" : {  
> > "field" : "tags",  
> > "size" : 9,  
> > "regex" : "userid\_.\*$"  
> > },  
> > "facet\_filter" : {  
> > "or" : {  
> > "filters" : [ {"term" : {"tags" :  
> > "userid\_50fd9f5373e13056e76f9e7f"}},  
> > {"term" : {"tags" : "userid\_51007ef3e4b0a99e8714a9e9"}},  
> > {"term" : {"tags" : "userid\_50e228cae4b05800e6ea1ef2"}},  
> > {"term" : {"tags" : "userid\_50fdaee7e4b05ced2d76710e"}},  
> > {"term" : {"tags" : "userid\_50c6dfdee4b030a63367a6e7"}},  
> > {"term" : {"tags" : "userid\_50f4680ce4b080e3535795dc"}},  
> > {"term" : {"tags" : "userid\_50ddf00ae4b000084a2dc057"}},  
> > {"term" : { "tags" : "userid\_50c6e080e4b030a63367a6e9" }},  
> > {"term" : {"tags" : "userid\_50f06636e4b0560131c8730c" }} ]  
> > }  
> > }  
> > }  
> > }  
> > }
> > 
> > Another option could have been to use the query facet. But this one  
> > serves  
> > better.  
> > The query facet is available at :
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/query-facet.html)
> 
> > On Tuesday, February 19, 2013 2:09:25 PM UTC-8, Matt Weber wrote:
> > 
> > > Actually you have two options:
> > > 
> > > 1. Use you can exclude tags you don't want counted (ie. microsoft,  
> > > kinect, etc)
> > > 2. Use a regex pattern for the terms you want included.
> > > 
> > > #2 would be my choice because it looks like you can do a basic  
> > > expression such as "username\_.\*$" or even looking for your specific  
> > > users "userid\_5114575ae4b0cb71b6654321|userid\_5114575ae4b0cb71b6654320"
> > > 
> > > See the section on excluding terms and regex patterns here:
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/terms-facet.html)
> 
> > > Hope this helps.
> > > 
> > > Thanks,  
> > > Matt Weber
> > > 
> > > On Tue, Feb 19, 2013 at 1:43 PM, AlexR [royt...@gmail.com](mailto:royt...@gmail.com) wrote:
> > > 
> > > > Maybe I am missing something but why not add filter on user to your  
> > > > query then you will limit your resultset and facets will only have  
> > > > the user  
> > > > you want
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it,  
> > > > send  
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google  
> > Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send  
> > an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:50am UTC](https://discuss.elastic.co/t/filter-output-of-term-facet-not-input/10806/9 "2017-07-06T02:50:09Z")

</div>


