# Performing Terms Queries on Rolled-Up Data using Kibana

**URL:** <https://discuss.elastic.co/t/performing-terms-queries-on-rolled-up-data-using-kibana/184968>\
**Category:** Kibana\
**Created:** [June 10, 2019, 10:30am UTC](https://discuss.elastic.co/t/performing-terms-queries-on-rolled-up-data-using-kibana/184968 "2019-06-10T10:30:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Emily2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emily2/32/47796_2.png) [@Emily2](https://discuss.elastic.co/u/Emily2)\
**Post date:** [June 10, 2019, 10:30am UTC](https://discuss.elastic.co/t/performing-terms-queries-on-rolled-up-data-using-kibana/184968/1 "2019-06-10T10:30:52Z")

</div>

Hi,

I've been trying out X-Pack Rollup (in 6.7) and cannot use Kibana to perform any terms queries for exact matches on terms that I configured Rollup for. I'm not sure whether I've done something wrong or it's just not supported or not supported yet. Is there a way to use either the Kibana search bar or the little filter panes to filter rolled-up data using terms groups that were configured in the rollup job?

Below is just more elaboration in case the question is not clear.

I am able to run aggregations on the terms using data tables with rows split by the relevant term, which is currently explicitly supported by Rollup. A data table that runs the following type of agg, for example, works.

```
  "aggs": {
"2": {
  "terms": {
    "field": "my_text_field.raw",
    "size": 5,
    "order": {
      "_count": "desc"
      }
    }
  }
}

```

But if I go to apply my\_text\_field.raw as a filter using the (+) magnifying glass (which instead uses the match\_phrase query) the query fails as:

```
Rollup search error: [illegal_argument_exception] Unsupported Query in search request: [match_phrase]

```

Using the search bar with exact terms matches, which uses a query\_string, also fails. For example, searching for

```
my_text_field.raw:"my_text_val"

```

where "my\_text\_val" is an exact match for a data table row value, gives:

```
Rollup search error: [illegal_argument_exception] Unsupported Query in search request: [query_string]
```

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [June 10, 2019, 1:40pm UTC](https://discuss.elastic.co/t/performing-terms-queries-on-rolled-up-data-using-kibana/184968/2 "2019-06-10T13:40:54Z")

</div>

> [@Emily2](#):
>
> ```auto
> tion] Unsupported Query in search request: [query_string]
> 
> ```

Hey, it's a current limitation of rollups with it only supporting a few types of queries, [ref](https://www.elastic.co/guide/en/elasticsearch/reference/current/rollup-search-limitations.html#_limited_querying_components).

It's not really supported but you may be able to get away with putting raw json in the input field in 6.7 to get perform a terms query. I don't think it works in the most recent kibana versions.

`{ term: my_field: { value: 'foo } }`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2019, 1:40pm UTC](https://discuss.elastic.co/t/performing-terms-queries-on-rolled-up-data-using-kibana/184968/3 "2019-07-08T13:40:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
