# How to display 0 count field values in Elastic DSL Query

**URL:** <https://discuss.elastic.co/t/how-to-display-0-count-field-values-in-elastic-dsl-query/275137>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 7, 2021, 10:52am UTC](https://discuss.elastic.co/t/how-to-display-0-count-field-values-in-elastic-dsl-query/275137 "2021-06-07T10:52:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![prabhakar\_talari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhakar_talari/32/46469_2.png) [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Post date:** [June 7, 2021, 10:52am UTC](https://discuss.elastic.co/t/how-to-display-0-count-field-values-in-elastic-dsl-query/275137/1 "2021-06-07T10:52:11Z")

</div>

All,

I am trying to find out a way to display input field values in Elastic watcher which are having 0 count records.

For example my input fields and values are [hostname=sample.com](http://hostname=sample.com) and source=/tmp/sample/log

I am using aggregations for these two fields, if i have the records it will show in bucket results along with the count but if i don't have the records the bucket result is not showing these fields with doc\_count as 0. but i need the bucket results for dock\_count 0 as well.

Sample DSL Query

{  
"query": {  
"bool": {  
"must": ,  
"filter": [  
{  
"match\_all": {}  
},  
{  
"match\_phrase": {  
"host.name": "[sample.com](http://sample.com)"  
}  
},  
{  
"match\_phrase": {  
"log.file.path": "/tmp/sample.log"  
}  
},  
{  
"range": {  
"message.timestamp": {  
"gte": "now-15m"  
}  
}  
}  
],  
"should": ,  
"must\_not":   
}  
},  
"size": 0,  
"aggs": {  
"group": {  
"composite": {  
"sources": [  
{  
"host": {  
"terms": {  
"field": "host.name"  
}  
}  
},  
{  
"source": {  
"terms": {  
"field": "log.file.path"  
}  
}  
}  
]  
}  
}  
}  
}

## Query Output

{  
"took" : 303,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 45,  
"successful" : 45,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 10000,  
"relation" : "gte"  
},  
"max\_score" : null,  
"hits" :   
},  
"aggregations" : {  
"group" : {  
"after\_key" : {  
"host" : "[sample.com](http://sample.com)",  
"source" : "/tmp/sample.log"  
},  
"buckets" : [  
{  
"key" : {  
"host" : "[sample.com](http://sample.com)",  
"source" : "/tmp/sample.log"  
},  
"doc\_count" : 34971  
}  
]  
}  
}  
}

If i don't have the records my output is as below

{  
"took" : 587,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 45,  
"successful" : 45,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 0,  
"relation" : "eq"  
},  
"max\_score" : null,  
"hits" :   
},  
"aggregations" : {  
"group" : {  
"buckets" :   
}  
}  
}

Now, when ever i don't have records i need to get an alert along with my input values like below

host : [sample.com](http://sample.com) source : /tmp/sample.log count : 0

If i have single values for input i can hard code it in watcher output section but i have multiple values for input, could some one help are there any aggregation functions which does this job or should i go with scripting only please suggest your thoughts

Thanks,

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [June 29, 2021, 7:21pm UTC](https://discuss.elastic.co/t/how-to-display-0-count-field-values-in-elastic-dsl-query/275137/2 "2021-06-29T19:21:05Z")

</div>

We made a fix in this area for Kibana 7.13 - [[Alerting] Fixing Elasticsearch query rule to allow matching on 0 documents by ymao1 · Pull Request #97735 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/97735) - what version are you running?

---

<div class="post-metadata">

**Author:** ![prabhakar\_talari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhakar_talari/32/46469_2.png) [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Post date:** [June 30, 2021, 8:43am UTC](https://discuss.elastic.co/t/how-to-display-0-count-field-values-in-elastic-dsl-query/275137/3 "2021-06-30T08:43:32Z")

</div>

Thank you for the update. We are running at 7.11.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 8:43am UTC](https://discuss.elastic.co/t/how-to-display-0-count-field-values-in-elastic-dsl-query/275137/4 "2021-07-28T08:43:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
