# Getting count using aggregation

**URL:** <https://discuss.elastic.co/t/getting-count-using-aggregation/314837>\
**Category:** Elasticsearch\
**Created:** [September 21, 2022, 8:31am UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837 "2022-09-21T08:31:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 21, 2022, 8:31am UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837/1 "2022-09-21T08:31:33Z")

</div>

Hi Team,

```auto
{
  "query": {
    "bool": {
      "filter": [
        {
        "bool": {
          "should":{
          "range": {
            "@timestamp": {
              "gte": "now-15m"
            }
          }
          }
        }
        },
        {
          "bool": {
            "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "081"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "091"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "096"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "900"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "009"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "0068"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "153"
              }
            }
          ]
          }
        }
      ]
    }
  }, 
  "aggs": {
    "types_count": {
      "value_count": {
        "field": "ResponseCode.keyword"
      }
    
    }
  }
}

```

This query give me the total count of those who has this values(which i specified) in response code

I want those count result who has this set of response code value which i specified plus all the response code. In other words can i get two different count values one for specific set of values and other one is all the values

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [September 21, 2022, 12:57pm UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837/2 "2022-09-21T12:57:07Z")

</div>

Hi,

aggregation works on documents which meet the `query`. You have to use the following query instead.

```auto
{
  "query": {
    "range": {
            "@timestamp": {
              "gte": "now-15m"
            }
          }
  },
  "aggs": { ...

```

With this query, you can use [filters aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html) to make two buckets: one for specific set of values and the other for all values for ResponseCode.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 21, 2022, 5:41pm UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837/3 "2022-09-21T17:41:53Z")

</div>

Thank you @Tomo_M for replying me. I used filters aggregation and getting error.  
**Error**

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "parsing_exception",
        "reason" : "unknown query [query]",
        "line" : 76,
        "col" : 22
      }
    ],
    "type" : "parsing_exception",
    "reason" : "unknown query [query]",
    "line" : 76,
    "col" : 22,
    "caused_by" : {
      "type" : "named_object_not_found_exception",
      "reason" : "[76:22] unknown field [query]"
    }
  },
  "status" : 400
}

```

```auto
{
  "query": {
    "bool": {
      "filter": [
        { "range":
            {
              "@timestamp":
              {
                "gte": "2022-09-21T09:00:00.000Z",
              "lte": "2022-09-21T09:30:00.000Z",
              "format":"yyyy-MM-dd HH:mm:ss||strict_date_optional_time ||epoch_millis"
              }
            }
          }
      ]
    }
  }, 
  "aggs": {
    "messages": {
      "filters": {
        "filters": {
          "response_code":
          {
            "bool": {
               "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "081"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "091"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "096"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "900"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "009"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "0068"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "153"
              }
            }
          ]
            }
          },
          "without_response":
          {
            "query": {
              "bool": {
                "must": [
                  {
                    "match_all": {}
                  }
                ]
              }
            }
          }
        }
      }
    }
  }
}

```

But after sometime i made some changes i used `other_bucket_key`.

```auto
{
  "query": {
    "bool": {
      "filter": [
        { "range":
            {
              "@timestamp":
              {
                "gte": "2022-09-21T09:00:00.000Z",
              "lte": "2022-09-21T09:30:00.000Z",
              "format":"yyyy-MM-dd HH:mm:ss||strict_date_optional_time ||epoch_millis"
              }
            }
          }
      ]
    }
  }, 
  "aggs": {
    "messages": {
         "filters" : {
        "other_bucket_key": "other_messages",
        "filters": {
          "response_code":
          {
            "bool": {
               "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "081"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "091"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "096"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "900"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "009"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "0068"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "153"
              }
            }
          ]
            }
          }
        }
      }
    }
  }
}

```

**Result**

```auto
"aggregations" : {
    "messages" : {
      "buckets" : {
        "response_code" : {
          "doc_count" : 906
        },
        "other_messages" : {
          "doc_count" : 98155
        }
      }
    }
  }

```

I want `other_messages` count 906+98155=99061 so bucket `other_messages` should be 99061. You can check whether i am doing wrong in `query` part because i got the error.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [September 21, 2022, 7:03pm UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837/4 "2022-09-21T19:03:37Z")

</div>

Thank you for let me know the `other_bucket` solution.

As for your error message,

```auto
{
  "query": {
    "bool": {
      "filter": [
        { "range":
            {
              "@timestamp":
              {
                "gte": "2022-09-21T09:00:00.000Z",
              "lte": "2022-09-21T09:30:00.000Z",
              "format":"yyyy-MM-dd HH:mm:ss||strict_date_optional_time ||epoch_millis"
              }
            }
          }
      ]
    }
  }, 
  "aggs": {
    "messages": {
      "filters": {
        "filters": {
          "response_code":
          {
            "bool": {
               "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },...
          ]
            }
          },
          "without_response":
          {
              "bool": {
                "must": [
                  {
                    "match_all": {}
                  }
                ]
              }
          }
        }
      }
    }
  }
}

```

will work.

Or, more simple `without_response` clause:

```auto
"without_response":
          {
            "match_all": {}
          }

```

will also work.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 22, 2022, 8:19am UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837/5 "2022-09-22T08:19:59Z")

</div>

Thank you @Tomo_M

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2022, 8:20am UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837/6 "2022-10-20T08:20:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
