# Filter result in top-term-aggs

**URL:** <https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182>\
**Category:** Elasticsearch\
**Created:** [May 1, 2017, 8:20pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182 "2017-05-01T20:20:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [May 1, 2017, 8:20pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/1 "2017-05-01T20:20:29Z")

</div>

I want to filter out field from my results.

My query is,

```
       {  
       "size":0,
       "aggs":{  
          "top-terms-aggregation":{  
             "terms":{  
                "field":"client_ip.keyword",
                "size":5
             }
          }
       }
    }

```

which gives output as,

> ```
> {
> ........................
> ........................
> "buckets": [
> {
> "key": "10.107. **.**",
> "doc_count": ***
> },
> {
> "key": "10.162. **.**",
> "doc_count": ***
> },
> {
> "key": "10.15. **.**",
> "doc_count": ***
> },
> {
> "key": "10.2. **.**",
> "doc_count": ***
> },
> {
> "key": "10.196. **.**",
> "doc_count": **
> }
> ]
> }
> }
> }
> 
> ```

Now in the above output, I want to filter out "10.107. **.**"  
**So my result should contain top 5 ips but without "10.107.**. **"**

Please tell how to achieve this?  
Thank you.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [May 1, 2017, 8:36pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/2 "2017-05-01T20:36:01Z")

</div>

There are two ways. The "best" way is to use a `bool` query with a `must_not` that filters out documents with those IP addresses. The slower way is to use the [bucket\_selector](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-bucket-selector-aggregation.html) aggregation. That one is slower because it works on the results. The filtering one should be faster because it has to calculate less data. But they are not the same. They will produce slightly different results though, so use the one that works for you.

---

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [May 1, 2017, 8:42pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/3 "2017-05-01T20:42:07Z")

</div>

Thnaks a lot. I will try to do this.

---

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [May 1, 2017, 8:56pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/4 "2017-05-01T20:56:07Z")

</div>

I tried following, but getting error.

```
{
      "query": {
        "bool": {
          "must_not": {
            "client_ip": "10.107. **.**"
          }
        }
      },
      "size":0,
       "aggs":{
          "top-terms-aggregation":{  
             "terms":{  
                "field":"client_ip.keyword",
                "size":5
             }
          }
       }
    }

```

Error is,

```
 {
      "error": {
        "root_cause": [
          {
            "type": "parsing_exception",
            "reason": "[client_ip] query malformed, no start_object after query name",
            "line": 5,
            "col": 22
          }
        ],
        "type": "parsing_exception",
        "reason": "[client_ip] query malformed, no start_object after query name",
        "line": 5,
        "col": 22
      },
      "status": 400
    }
```

---

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [May 1, 2017, 9:03pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/5 "2017-05-01T21:03:50Z")

</div>

Solved.  
Thanks again.

---

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [May 1, 2017, 10:21pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/6 "2017-05-01T22:21:43Z")

</div>

Hey, how to add @timestamp range in this.  
I tried various ways, but didn't worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2017, 10:34pm UTC](https://discuss.elastic.co/t/filter-result-in-top-term-aggs/84182/7 "2017-05-29T22:34:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
