How to filter range on cardinality aggregations ES v1.3.4 please?


First, thx you for very good ELK !

Anyone help me for how to filter range on cardinality aggregations please ?

ok please look my query working example:

curl -XGET 'http://localhost:9200/logstash-2014.10.20/_search?search_type=count&pretty=true' -d
'{ "size":9999999, "aggs": { "distinct_ip_src": { "cardinality": { "field": "IP_SRC"}}}}'
"took" : 34,
"timed_out" : false,
"_shards" : {
"total" : 5,
"successful" : 5,
"failed" : 0
"hits" : {
"total" : 12975,
"max_score" : 0.0,
"hits" : [ ]
"aggregations" : {
"distinct_ip_src" : {
"value" : 10

But now, how to filter like a range distinct_ip_src.value (10 here) please ?

query not working: (no hits reply)
curl -XGET 'http://localhost:9200/logstash-2014.10.20/_search?search_type=count&pretty=true' -d
'{ "size":9999999, "aggs": { "distinct_ip_src": { "cardinality": { "field": "IP_SRC"}}},"post_filter",{"query": {"range":{"distinct_ip_src.value":{"gt":9}}}}}'
Tryed only "value": not work
Tryed only "_value": not work
Tryed only "term": not work
size:0 : not better work
Tryed removing "search_type=count": not work

Best Regards

