# Has\_child issue with filtered query and aggs

**URL:** <https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725>\
**Category:** Elasticsearch\
**Created:** [January 21, 2016, 3:59am UTC](https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725 "2016-01-21T03:59:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MrMSilvey](https://avatars.discourse-cdn.com/v4/letter/m/3be4f8/32.png) [@MrMSilvey](https://discuss.elastic.co/u/MrMSilvey)\
**Post date:** [January 21, 2016, 3:59am UTC](https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725/1 "2016-01-21T03:59:10Z")

</div>

I am a beginner. There is a such a thing as too much information, so I will try to be specific.

I have 2 tables/types in an index. table 1 is parent. table 2 is child mapped to parent.  
I am basically trying to convert an SQL join with aggregations. Maybe 2 queries is better?  
In any case here is my attempt to query the parent/child.  
POST /my\_index/table1/\_search  
{  
"has\_child":{  
"type": "table2",  
"fields": ["name","color","acc\_id","time\_hr"],  
"filtered" : {  
"query" : { "match": { "acc\_id" : 60}},  
"filter" : {  
"bool":{  
"must":{"range":{"time\_hr" : { "gte": 1417300000, "lt": 1418000000}}},  
}  
},  
"aggs":{  
"count":{ "sum": {"field": "count"}},  
"total\_time":{ "sum": {"field": "cost"}}  
}  
}  
}  
}  
Here's the error:  
"error": {  
"root\_cause": [  
{  
"type": "search\_parse\_exception",  
"reason": "failed to parse search source. unknown search element [has\_child]",

Hopefully a simple answer to get me moving. I tried to do my research. Much to learn.

---

<div class="post-metadata">

**Author:** ![MrMSilvey](https://avatars.discourse-cdn.com/v4/letter/m/3be4f8/32.png) [@MrMSilvey](https://discuss.elastic.co/u/MrMSilvey)\
**Post date:** [January 25, 2016, 12:08pm UTC](https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725/2 "2016-01-25T12:08:42Z")

</div>

This post can be deleted.

---

<div class="post-metadata">

**Author:** ![bleskes](https://avatars.discourse-cdn.com/v4/letter/b/71c47a/32.png) [@bleskes](https://discuss.elastic.co/u/bleskes)\
**Post date:** [January 25, 2016, 12:48pm UTC](https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725/3 "2016-01-25T12:48:23Z")

</div>

Heya,

You miss a "query" element around your has\_child query. Like so:

```
POST /my_index/table1/_search
{
  "query": {
    "has_child": {
      "type": "table2",
      "fields": [
        "name",
        "color",
        "acc_id",
        "time_hr"
      ],
      "filtered": {
        "query": {
          "match": {
            "acc_id": 60
          }
        },
        "filter": {
          "bool": {
            "must": {
              "range": {
                "time_hr": {
                  "gte": 1417300000,
                  "lt": 1418000000
                }
              }
            }
          }
        }
      },
      "aggs": {
        "count": {
          "sum": {
            "field": "count"
          }
        },
        "total_time": {
          "sum": {
            "field": "cost"
          }
        }
      }
    }
  }
} 

```

In general I can recommend using Sense - it's autocomplete features greatly help in getting the structure right. See [https://www.elastic.co/guide/en/sense/current/introduction.html](https://www.elastic.co/guide/en/sense/current/introduction.html)

---

<div class="post-metadata">

**Author:** ![MrMSilvey](https://avatars.discourse-cdn.com/v4/letter/m/3be4f8/32.png) [@MrMSilvey](https://discuss.elastic.co/u/MrMSilvey)\
**Post date:** [January 25, 2016, 12:51pm UTC](https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725/4 "2016-01-25T12:51:14Z")

</div>

Thank You very much.

I, however ended up denormalizing the data between the 2 tables.

I will try Sense!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:21pm UTC](https://discuss.elastic.co/t/has-child-issue-with-filtered-query-and-aggs/39725/5 "2017-07-05T23:21:58Z")

</div>


