# Group by "field" OR group by missing "field"

**URL:** <https://discuss.elastic.co/t/group-by-field-or-group-by-missing-field/27321>\
**Category:** Elasticsearch\
**Created:** [August 13, 2015, 10:35am UTC](https://discuss.elastic.co/t/group-by-field-or-group-by-missing-field/27321 "2015-08-13T10:35:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vit](https://avatars.discourse-cdn.com/v4/letter/v/65b543/32.png) [@vit](https://discuss.elastic.co/u/vit)\
**Post date:** [August 13, 2015, 10:35am UTC](https://discuss.elastic.co/t/group-by-field-or-group-by-missing-field/27321/1 "2015-08-13T10:35:09Z")

</div>

I have a difficulties with elasticsearch.

Here is what I want to do:

Let's say unit of my index looks like this:

```
{
  transacId: "qwerty",
  amount: 150,
  userId: "adsf",
  client: "mobile",
  goal: "purchase"
}

```

I want to build different types of statistics of this data and elasticsearch does it really fast. The problem I have is that in my system user can add new field in transaction on demand. Let's say we have another row in the same index:

```
{
  transacId: "qrerty",
  amount: 200,
  userId: "adsf",
  client: "mobile",
  goal: "purchase",
  token_1: "game"
}

```

So now I want to group by token\_1.

```
{
  query: {
    match: {userId: "asdf"}
  },
  aggs: {
    token_1: {
      terms: {field: "token_1"},
      aggs: {sumAmt: {sum: {field: "amount"}}} 
    }
  }
}

```

Problem here that it will aggregate only documents with field token\_1. I know there is aggregation missing and I can do something like this:

```
{
  query: {
    match: {userId: "asdf"}
  },
  aggs: {
    token_1: {
      missing: {field: "token_1"},
      aggs: {sumAmt: {sum: {field: "amount"}}} 
    }
  }
}

```

But in this case it will aggregate only documents without field token\_1, what I want is to aggregate both types of documents in on query. I tried do this, but it also didn't work for me:

```
{
  query: {
    match: {userId: "asdf"}
  },
  aggs: {
    token_1: {
      missing: {field: "token_1"},
      aggs: {sumAmt: {sum: {field: "amount"}}} 
    },
    aggs: {
      token_1: {
        missing: {field: "token_1"},
        aggs: {sumAmt: {sum: {field: "amount"}}} 
      }
    }
  }
}

```

I think may be there is something like operator OR in aggregation, but I couldn't find anything. Help me, please.

---

<div class="post-metadata">

**Author:** ![dantuff](https://avatars.discourse-cdn.com/v4/letter/d/e79b87/32.png) [@dantuff](https://discuss.elastic.co/u/dantuff)\
**Post date:** [August 13, 2015, 11:38am UTC](https://discuss.elastic.co/t/group-by-field-or-group-by-missing-field/27321/2 "2015-08-13T11:38:34Z")

</div>

You would need two aggregations `missing_token_1` and `token_1`.

```
{
    "query": {
        "match": {
            "userId": "asdf"
        }
    },
    "aggs": {
        "missing_token_1": {
            "missing": {
                "field": "token_1"
            },
            "aggs": {
                "sumAmt": {
                    "sum": {
                        "field": "amount"
                    }
                }
            }
        },
        "token_1": {
            "terms": {
                "field": "token_1"
            },
            "aggs": {
                "sumAmt": {
                    "sum": {
                        "field": "amount"
                    }
                }
            }
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![vit](https://avatars.discourse-cdn.com/v4/letter/v/65b543/32.png) [@vit](https://discuss.elastic.co/u/vit)\
**Post date:** [August 13, 2015, 11:53am UTC](https://discuss.elastic.co/t/group-by-field-or-group-by-missing-field/27321/3 "2015-08-13T11:53:42Z")

</div>

Thank you. It works. I see my mistake was in adding "aggs" in the start of second aggregation. Anyway, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:55pm UTC](https://discuss.elastic.co/t/group-by-field-or-group-by-missing-field/27321/4 "2017-07-05T23:55:58Z")

</div>


