# How to further filter data by applying conditions to grouped data

**URL:** <https://discuss.elastic.co/t/how-to-further-filter-data-by-applying-conditions-to-grouped-data/371502>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [December 5, 2024, 5:04am UTC](https://discuss.elastic.co/t/how-to-further-filter-data-by-applying-conditions-to-grouped-data/371502 "2024-12-05T05:04:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![leeheeseok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leeheeseok/32/139708_2.png) [@leeheeseok](https://discuss.elastic.co/u/leeheeseok)\
**Post date:** [December 5, 2024, 5:04am UTC](https://discuss.elastic.co/t/how-to-further-filter-data-by-applying-conditions-to-grouped-data/371502/1 "2024-12-05T05:04:23Z")

</div>

Hi, I am researching a way to filter data after grouping. For example, here is the data:

index: domain\_user\_search  
doc:

```auto
[
{
"domain_key": "PElvL8li",
"delete_yn": "Y",
"@timestamp": "2024-12-03T05:49:51.000Z"
},
{
"domain_key": "3zit1iG4",
"delete_yn": "N",
"@timestamp": "2024-12-03T05:47:56.000Z"
},
{
"domain_key": "MPfyjQrP",
"delete_yn": "N",
"@timestamp": "2024-12-03T05:47:56.000Z"
},
{
"domain_key": "vBYwrqvO",
"delete_yn": "N",
"@timestamp": "2024-12-03T05:46:56.000Z"
},
{
"domain_key": "PElvL8li",
"delete_yn": "N",
"@timestamp": "2024-12-03T05:45:51.000Z"
},
]

```

Data like this exists,

```auto
GET /domain_user_mapping/_search
{
  "size": 0,
  "aggs": {
    "group_by_domain_key": {
      "terms": {
        "field": "domain_key.keyword",
        "size": 3
      },
      "aggs": {
        "latest_doc": {
          "filter": {
            "match_all": {}
          },
          "aggs": {
            "sorted_docs": {
              "terms": {
                "field": "@timestamp",
                "size": 1,
                "order": {
                  "_key": "desc"
                }
              },
              "aggs": {
                "filtered_doc_content": {
                  "filter": {
                    "term": {
                      "delete_yn.keyword": "N"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}

```

If you search with a query like this:

```auto
"aggregations": {
    "group_by_domain_key": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 3,
      "buckets": [
        {
          "key": "PElvL8li",
          "doc_count": 2,
          "latest_doc": {
            "doc_count": 2,
            "sorted_docs": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 1,
              "buckets": [
                {
                  "key": 1733204991000,
                  "key_as_string": "2024-12-03T05:49:51.000Z",
                  "doc_count": 1,
                  "filtered_doc_content": {
                    "doc_count": 0
                  }
                }
              ]
            }
          }
        },
        {
          "key": "3zit1iG4",
          "doc_count": 1,
          "latest_doc": {
            "doc_count": 1,
            "sorted_docs": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": [
                {
                  "key": 1733204876000,
                  "key_as_string": "2024-12-03T05:47:56.000Z",
                  "doc_count": 1,
                  "filtered_doc_content": {
                    "doc_count": 1
                  }
                }
              ]
            }
          }
        },
        {
          "key": "MPfyjQrP",
          "doc_count": 1,
          "latest_doc": {
            "doc_count": 1,
            "sorted_docs": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": [
                {
                  "key": 1733204876000,
                  "key_as_string": "2024-12-03T05:47:56.000Z",
                  "doc_count": 1,
                  "filtered_doc_content": {
                    "doc_count": 1
                  }
                }
              ]
            }
          }
        }
      ]
    }

```

As the key is PElvL8li, the data whose delete\_yn is Y is the most recent, so the data is included and "PElvL8li","3zit1iG4","MPfyjQrP" is displayed.

What I want is that since delete\_yn is Y, it is excluded from the response data and I want to receive 3 data, "3zit1iG4","MPfyjQrP","vBYwrqvO".

The prerequisite is that the data whose delete\_yn is Y should be removed in advance and grouped based on the latest time, and the data whose delete\_yn is Y should be excluded after grouping based on the latest time.

Is this filtering possible with a query?

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [December 12, 2024, 9:54am UTC](https://discuss.elastic.co/t/how-to-further-filter-data-by-applying-conditions-to-grouped-data/371502/2 "2024-12-12T09:54:21Z")

</div>

Hey @leeheeseok :

Sure, filtering is possible in aggregations. You can just [issue a query](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html#change-agg-scope) with them.

In your example, something similar to:

```auto
{
  "size": 0,
  "query": {
    "term": {
      "delete_yn": {
        "value": "N"
      }
    }
   }
  "aggs": {
... you aggregations go here
   }
}

```

Aggregations are always run on the query results, so you can perform the query, check that your results are the ones that you should aggregate on, and then use the aggregation along with the query to perform the aggregations on the results.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2025, 9:55am UTC](https://discuss.elastic.co/t/how-to-further-filter-data-by-applying-conditions-to-grouped-data/371502/3 "2025-01-09T09:55:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
