# How to get the one record from each aggregation group?

**URL:** <https://discuss.elastic.co/t/how-to-get-the-one-record-from-each-aggregation-group/159773>\
**Category:** Kibana\
**Created:** [December 6, 2018, 4:58pm UTC](https://discuss.elastic.co/t/how-to-get-the-one-record-from-each-aggregation-group/159773 "2018-12-06T16:58:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sudhakar\_katakara](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@sudhakar\_katakara](https://discuss.elastic.co/u/sudhakar_katakara)\
**Post date:** [December 6, 2018, 4:58pm UTC](https://discuss.elastic.co/t/how-to-get-the-one-record-from-each-aggregation-group/159773/1 "2018-12-06T16:58:35Z")

</div>

We want to get the first record (based on inserted time in ascending order) from each aggregation group. We monitor the servers and events are inserted to elastic search from different sources on same device.

Let us assume that we have two servers(A & B) and 10 events are inserted per each device from different sources. How to get the first record(based one timestamp) from each device.

When I apply the below query, its getting two records from same device(A). I want to get the first event(one from device A and second from device B) from each device. Can anyone help on this?

GET test\_elastalert1/\_search

{

"sort" : [{ "time" : "asc" }] ,

"size": 2,

"query": {

"bool": {

"must": [{"match": {"event\_sev": "Critical"}},

{"range" : {"time" : {"gte" : "now-8h" , "lt" : "now" , "format": "yyyy-MM-dd HH:mm:ss"}}}]

}

} ,

"aggs": {

"Group\_By\_host": {

"terms": {

"field": "Hostname.keyword"

}

}

}

}

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 6, 2018, 6:21pm UTC](https://discuss.elastic.co/t/how-to-get-the-one-record-from-each-aggregation-group/159773/2 "2018-12-06T18:21:39Z")

</div>

you could use the top\_hit aggregation to get just the 'top' record from your bucket

---

<div class="post-metadata">

**Author:** ![sudhakar\_katakara](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@sudhakar\_katakara](https://discuss.elastic.co/u/sudhakar_katakara)\
**Post date:** [December 6, 2018, 6:58pm UTC](https://discuss.elastic.co/t/how-to-get-the-one-record-from-each-aggregation-group/159773/3 "2018-12-06T18:58:23Z")

</div>

Thanks peter for your reply. I used below query to get results. but those are displaying under the aggregation section. How can we get them in main hits section?

"aggs": {  
"Group\_By\_host": {  
"terms": {  
"field": "Hostname.keyword"

```
},
        "aggs": {
            "group_docs": {
                "top_hits": {
                    "size": 1,
                    "sort": [
                        {
                            "time": {
                                "order": "asc"
                            }
                        }
                    ]
                }
            }
        }

```

}

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2019, 7:06pm UTC](https://discuss.elastic.co/t/how-to-get-the-one-record-from-each-aggregation-group/159773/4 "2019-01-03T19:06:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
