# Nested terms with date\_histogram subaggregation

**URL:** <https://discuss.elastic.co/t/nested-terms-with-date-histogram-subaggregation/81967>\
**Category:** Elasticsearch\
**Created:** [April 11, 2017, 11:20am UTC](https://discuss.elastic.co/t/nested-terms-with-date-histogram-subaggregation/81967 "2017-04-11T11:20:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomr/32/48260_2.png) [@tomr](https://discuss.elastic.co/u/tomr)\
**Post date:** [April 11, 2017, 11:20am UTC](https://discuss.elastic.co/t/nested-terms-with-date-histogram-subaggregation/81967/1 "2017-04-11T11:20:47Z")

</div>

i have some nested fields and timestamps in documents a bit like:

```
{
  "@timestamp": timestamp
  "field":[
    {
      "key":"keyname",
      "doc_count":count
    },...
  ]
}

```

I'm trying to do a nested terms agg on field.key, with a date\_histogram subagg on @timestamp, and sum agg on field.doc\_count under that. The terms agg works great. the date\_histogram agg shows correct times on its buckets, but every bucket is empty. Here's how it looks so far. I'm leaving the sum agg out for now - I expect that to be easy once I've nailed the date\_histogram.

```
  "aggs": {
    "1": {
      "nested": {
        "path": "field"
      },
      "aggs": {
        "2": {
          "terms": {
            "field": "field.key"
          },
          "aggs": {
            "3": {
              "date_histogram": {
                "field": "@timestamp",
                "interval": "hour",
                "min_doc_count": 0,
                "extended_bounds": {
                  "max": "now/h",
                  "min": "now/h-1d"
                }
              }
            }
          }
        }
      }
    }
  }

```

Responses currently appear thus:

```
"aggregations": {
  "1": {
    "doc_count": 2551,
    "2": {
      "doc_count_error_upper_bound": 32,
      "sum_other_doc_count": 1280,
      "buckets": [
        {
          "key": "key1",
          "doc_count": 351,
          "date_histogram": {
            "buckets": [
              {
                "key_as_string": "2017-04-10T10:00:00.000Z",
                "key": 1491818400000,
                "doc_count": 0
              },
              {
                "key_as_string": "2017-04-10T11:00:00.000Z",
                "key": 1491822000000,
                "doc_count": 0
              },  
              <snip>

```

If I put it the other way around, with the nested and terms aggs underneath the date histogram, all is well. But I really want to aggregate on terms first if possible so that I get the top ten keys from the period, then count them per-interval (rather than a more erratic number of keys and a noisy graph).

---

<div class="post-metadata">

**Author:** ![tomr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomr/32/48260_2.png) [@tomr](https://discuss.elastic.co/u/tomr)\
**Post date:** [April 11, 2017, 1:09pm UTC](https://discuss.elastic.co/t/nested-terms-with-date-histogram-subaggregation/81967/2 "2017-04-11T13:09:34Z")

</div>

I think I've cracked it using a reverse\_nested aggregation, and putting the date\_histogram within that:

```
  "aggs": {
    "1": {
      "nested": {
        "path": "field"
      },
      "aggs": {
        "2": {
          "terms": {
            "field": "field.key"
          },
          "aggs": {
            "3": {
              "reverse_nested": {},
              "aggs": {
                "4": {
                  "date_histogram": {
                    "field": "@timestamp",
                    "extended_bounds": {
                      "max": "now/h",
                      "min": "now/h-1d"
                    },
                    "interval": "hour",
                    "min_doc_count": 0
                  }
                }
              }
            }
          }
        }
      }
    }
  },
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2017, 1:20pm UTC](https://discuss.elastic.co/t/nested-terms-with-date-histogram-subaggregation/81967/3 "2017-05-09T13:20:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
