# Help with aggregations

**URL:** <https://discuss.elastic.co/t/help-with-aggregations/109012>\
**Category:** Elasticsearch\
**Created:** [November 24, 2017, 10:26am UTC](https://discuss.elastic.co/t/help-with-aggregations/109012 "2017-11-24T10:26:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sergios](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sergios](https://discuss.elastic.co/u/sergios)\
**Post date:** [November 24, 2017, 10:26am UTC](https://discuss.elastic.co/t/help-with-aggregations/109012/1 "2017-11-24T10:26:34Z")

</div>

Hello,

I'm trying to build a query to get something like:

```
SELECT * FROM 'my_index' WHERE field1 = 'value1' GROUP BY 'field2' ORDER BY 'timestamp' DESC LIMIT 1

```

Is this possible to do in Elasticsearch? I have tried to use sub-aggregations, but I can't seem to find a way to get the documents in the buckets..

Thanks in advance

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 24, 2017, 11:01am UTC](https://discuss.elastic.co/t/help-with-aggregations/109012/2 "2017-11-24T11:01:10Z")

</div>

What did you do so far?

Could you provide a full recreation script as described in

> [@About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21):
>
> The heart of the free and open Elastic Stack Elasticsearch is a distributed, RESTful search and analytics engine capable of addressing a growing number of use cases. As the heart of the Elastic Stack, it centrally stores your data for lightning fast search, fine‑tuned relevancy, and powerful analytics that scale with ease. warning PLEASE READ THIS SECTION IF IT'S YOUR FIRST POST Some useful links: [elasticsearch reference guide](http://www.elastic.co/guide/en/elasticsearch/reference/current/index.html)[elasticsearch user guide](http://www.elastic.co/guide/en/elasticsearch/guide/current/index.html)[elasticsearch plugins](https://www.elastic.co/guide/en/elasticsearch/plugins/current/index.html)[elasticsearch cl…](https://www.elastic.co/guide/en/elasticsearch/client/index.html)

It will help to better understand what you are doing.  
Please, try to keep the example as simple as possible.

---

<div class="post-metadata">

**Author:** ![sergios](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@sergios](https://discuss.elastic.co/u/sergios)\
**Post date:** [November 27, 2017, 9:14am UTC](https://discuss.elastic.co/t/help-with-aggregations/109012/3 "2017-11-27T09:14:56Z")

</div>

I was trying to build from here:

```auto
   GET /my_index/_search
   query: {
        match: {
            'foo': 'bar'
        }
   },  
   aggs: {
       'agg1': {
           terms: {
               field: 'some_field.keyword'
           }
       }
   }

```

But I didn't get anywhere. Because this way the results I get are from all documents that match 'foo' = 'bar', an array of buckets for each value of 'some\_field'. And the buckets only give me the possible values of 'some\_field' and the document count. For each bucket I want to get the whole document with the most recent timestamp, i.e., order by timestamp desc, and limiting to 1 document per possible value of 'some\_field'.  
Is aggregations the best way to get this? It seems I only get the document count with the buckets. Is there any other approach that might be better to do this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 27, 2017, 9:51am UTC](https://discuss.elastic.co/t/help-with-aggregations/109012/4 "2017-11-27T09:51:20Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

May be Top Hits would help: [https://www.elastic.co/guide/en/elasticsearch/reference/6.0/search-aggregations-metrics-top-hits-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/search-aggregations-metrics-top-hits-aggregation.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2017, 10:04am UTC](https://discuss.elastic.co/t/help-with-aggregations/109012/5 "2017-12-25T10:04:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
