# Filter terms aggregation in order to see only terms with more than 10 results

**URL:** <https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844>\
**Category:** Elasticsearch\
**Created:** [November 29, 2015, 8:28pm UTC](https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844 "2015-11-29T20:28:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [November 29, 2015, 8:28pm UTC](https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844/1 "2015-11-29T20:28:38Z")

</div>

I have ton of documents like this:

```
{ "ip" : "77.....", "event" : "buy", "time" : "11:00..."}
{"ip" : "75.....", "event" : "search", "time" : "11:01..."}

```

I would like to setup an alert if a client is generating too many events in a specified time window, so I am doing the following aggregation:

```
"aggs" : {
"ips_per_minute" : {
    "date_histogram" : {
        "field" : "time",
        "interval" : "1m"
    },
    "aggs": {
        "queries_per_ip": {
            "terms": {
                "field": "client"
            }
        }
    }
}

```

But it gives me ALL data, I would like to filter " IF COUNT(ips) \> 10 BY 1m"

---

<div class="post-metadata">

**Author:** ![mainec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mainec/32/5557_2.png) [@mainec](https://discuss.elastic.co/u/mainec)\
**Post date:** [November 29, 2015, 9:41pm UTC](https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844/2 "2015-11-29T21:41:18Z")

</div>

The min\_doc\_count parameter documented here

[https://www.elastic.co/guide/en/elasticsearch/reference/1.4/search-aggregations-bucket-terms-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.4/search-aggregations-bucket-terms-aggregation.html)

should help you solve your problem.

Hope this helps,  
Isabel

---

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [November 30, 2015, 9:17am UTC](https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844/3 "2015-11-30T09:17:11Z")

</div>

D'oh !

Ya this is exactly that I was looking for, many thanks.

Was looking for a so complicated solution (with pipeline & co') then I didn't read all the doc of terms aggregation...

---

<div class="post-metadata">

**Author:** ![mainec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mainec/32/5557_2.png) [@mainec](https://discuss.elastic.co/u/mainec)\
**Post date:** [December 2, 2015, 6:42am UTC](https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844/4 "2015-12-02T06:42:25Z")

</div>

No worries - glad it was the right solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:34pm UTC](https://discuss.elastic.co/t/filter-terms-aggregation-in-order-to-see-only-terms-with-more-than-10-results/35844/5 "2017-07-05T23:34:16Z")

</div>


