# Group Values with Aggregation

**URL:** <https://discuss.elastic.co/t/group-values-with-aggregation/200255>\
**Category:** Elasticsearch\
**Created:** [September 19, 2019, 3:34pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255 "2019-09-19T15:34:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![code\_blue](https://avatars.discourse-cdn.com/v4/letter/c/7ea924/32.png) [@code\_blue](https://discuss.elastic.co/u/code_blue)\
**Post date:** [September 19, 2019, 3:34pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/1 "2019-09-19T15:34:18Z")

</div>

I am trying to write an aggregation query but not sure what I am missing here. I have the following structure across multiple documents. Some of the field names may not be present in documents.

```
{
	"CaptureData": [{
			
			"FieldName": "A",
			"FieldValue": [
				"xyz"
			]
		},
		{
		
			"FieldName": "B",
			"FieldValue": [
				"pqr"
			]
		}]
}

```

I am able to aggregate on different field names, but I want to also aggregate values for each field bucket. So I want to create a bucket for A and see list of values under A.

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [September 20, 2019, 10:15am UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/2 "2019-09-20T10:15:49Z")

</div>

How have you mapped your data? You will need to map `CaptureData` as a [nested field](https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html) in order to do this.

Once you have done that, you will be able to execute [a nested aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-nested-aggregation.html) on `CaptureData`. Inside that nested aggregation, you can use a [terms aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html) to get a set of buckets for `FieldName` and inside of that a terms aggregation on `FieldValue` to get a list of values under each `A`, `B`, etc.

---

<div class="post-metadata">

**Author:** ![code\_blue](https://avatars.discourse-cdn.com/v4/letter/c/7ea924/32.png) [@code\_blue](https://discuss.elastic.co/u/code_blue)\
**Post date:** [September 20, 2019, 1:55pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/3 "2019-09-20T13:55:06Z")

</div>

This is what I have in mapping:

```
  {
	"CaptureData": {
		"properties": {
			"FieldName": {
				"type": "text",
				"fields": {
					"keyword": {
						"type": "keyword",
						"ignore_above": 256
					}
				}
			},
			"FieldValue": {
				"type": "text",
				"fields": {
					"keyword": {
						"type": "keyword",
						"ignore_above": 256
					}
				}
			}
		}
	}
}
```

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [September 20, 2019, 2:22pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/4 "2019-09-20T14:22:19Z")

</div>

Alright, you did not map `CaptureData` as type `nested`. When creating the index apply the following mapping instead (the only difference is for `CaptureData`):

```auto
PUT my_index
{
  "mappings": {
    "properties": {
      "CaptureData": {
        "type": "nested",
        "properties": {
          "FieldName": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "FieldValue": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      }
    }
  }
}

```

Next, you can index a document like the one your shared in your original post:

```auto
PUT my_index/_doc/1
{
  "CaptureData": [
    {
      "FieldName": "A",
      "FieldValue": [
        "xyz"
      ]
    },
    {
      "FieldName": "B",
      "FieldValue": [
        "pqr"
      ]
    }
  ]
}

```

And execute the nested aggregation I mentioned earlier:

```auto
GET my_index/_search
{
  "size": 0,
  "aggs": {
    "my_nested": {
      "nested": {
        "path": "CaptureData"
      },
      "aggs": {
        "field_names": {
          "terms": {
            "field": "CaptureData.FieldName.keyword",
            "size": 10
          },
          "aggs": {
            "field_values": {
              "terms": {
                "field": "CaptureData.FieldValue.keyword",
                "size": 10
              }
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![code\_blue](https://avatars.discourse-cdn.com/v4/letter/c/7ea924/32.png) [@code\_blue](https://discuss.elastic.co/u/code_blue)\
**Post date:** [September 20, 2019, 3:01pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/5 "2019-09-20T15:01:58Z")

</div>

Getting the following error:

Root mapping definition has unsupported parameters: [CaptureData : {type=nested, properties={FieldValue={type=text, fields={keyword={ignore\_above=256, type=keyword}}}, FieldName={type=text, fields={keyword={ignore\_above=256, type=keyword}

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [September 20, 2019, 3:14pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/6 "2019-09-20T15:14:00Z")

</div>

What version of Elasticsearch are you using? If you're still on version 6, the request would be:

```auto
PUT my_index
{
  "mappings": {
    "_doc": {
      "properties": {
        "CaptureData": {
          "type": "nested",
          "properties": {
            "FieldName": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "FieldValue": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![code\_blue](https://avatars.discourse-cdn.com/v4/letter/c/7ea924/32.png) [@code\_blue](https://discuss.elastic.co/u/code_blue)\
**Post date:** [September 23, 2019, 3:18pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/7 "2019-09-23T15:18:55Z")

</div>

Thanks a lot. this works. However it seems this doesn't work from Kibana when I am doing Sub Series Aggregation. Any idea what I might have to change as I want to make it work from Kibana as well.

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [September 23, 2019, 3:48pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/8 "2019-09-23T15:48:00Z")

</div>

Yeah, Kibana has very limited support for nested aggregations. You may want to take a look at [Vega visualizations](https://www.elastic.co/guide/en/kibana/current/vega-graph.html). Those allow you to visualize whatever Elasticsearch returns, including the response of a nested aggregation. There is however a bit of a learning curve to working with Vega.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2019, 3:48pm UTC](https://discuss.elastic.co/t/group-values-with-aggregation/200255/9 "2019-10-21T15:48:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
