# Help with aggregation query

**URL:** <https://discuss.elastic.co/t/help-with-aggregation-query/204737>\
**Category:** Elasticsearch\
**Created:** [October 22, 2019, 10:17pm UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737 "2019-10-22T22:17:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Post date:** [October 22, 2019, 10:17pm UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737/1 "2019-10-22T22:17:12Z")

</div>

I've been trying to create a query to use with the API to match what I've configured in Kibana as shown in this screen cap, but without luck. I'm able to create a query, but not sure how to incorporate aggs into it. Can someone lead me down the right path? My query so far:

```auto
curl -s -XGET "http://localhost:9200/logstash-*/_search?pretty" -H 'Content-Type: application/json' -d'
  {
    "_source": [
     "cookie_blah"
   ],
    "from": 0,
     "query": {
      "bool": {
        "must": [
          {
            "range": {
              "@timestamp": {
                "gte": "now-4h",
                "lt": "now"
              }
            }
          },
          {
            "term": {
              "vhost": "blah.blah.com"
            }
          },
			 {
          "exists": {
              "field": "cookie_blah"
				  }
          },
          {
            "query_string": {
              "fields": [
                "request"
              ],
              "query": "\\/blah/blah/blah",
              "analyzer": "keyword"
            }
          }
        ]
      }
    },
    "size": 10000
  }'

```

From Kibana: (I basically want the top 50 values and counts for the "cookie\_blah" field.)

 ![32%20PM](https://us1.discourse-cdn.com/elastic/original/3X/8/8/8842545f7295ea49c35ebaae5f4aca7d45befbce.png)

Thanks!

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [October 23, 2019, 1:31am UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737/2 "2019-10-23T01:31:57Z")

</div>

You should be able to inspect the query for whatever viz you have. What version of Kibana are you using?

---

<div class="post-metadata">

**Author:** ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Post date:** [October 23, 2019, 2:03am UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737/3 "2019-10-23T02:03:27Z")

</div>

Thanks, version 5.6....

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [October 23, 2019, 2:11am UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737/4 "2019-10-23T02:11:14Z")

</div>

![kibanaquery](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf523228e9637701aa42aef488ef64ca1aa0d771.gif)

---

<div class="post-metadata">

**Author:** ![Chris\_Stone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_stone/32/21026_2.png) [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Post date:** [October 23, 2019, 3:42pm UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737/5 "2019-10-23T15:42:45Z")

</div>

That's beautiful! Thanks Glen 🙂

--Chris

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2019, 3:42pm UTC](https://discuss.elastic.co/t/help-with-aggregation-query/204737/6 "2019-11-20T15:42:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
