# Problems with min\_doc\_count

**URL:** <https://discuss.elastic.co/t/problems-with-min-doc-count/102114>\
**Category:** Kibana\
**Created:** [September 28, 2017, 12:26pm UTC](https://discuss.elastic.co/t/problems-with-min-doc-count/102114 "2017-09-28T12:26:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![klubbe](https://avatars.discourse-cdn.com/v4/letter/k/d78d45/32.png) [@klubbe](https://discuss.elastic.co/u/klubbe)\
**Post date:** [September 28, 2017, 12:26pm UTC](https://discuss.elastic.co/t/problems-with-min-doc-count/102114/1 "2017-09-28T12:26:39Z")

</div>

I'm making a visualization with the Kibana tool and it keeps giving me an error, but I don't understand why.  
What I'm trying to do is removing rows which gets 0 from the count aggregation. i have tried adding the min\_doc\_count to the other aggregations too, and although it doesn't give me an error when they are placed there, the rows which gets 0 from the count aggregation are not filtered away.

Here is the query:

> {  
> "title": "Switch CRC or Duplex error",  
> "type": "table",  
> "params": {  
> "perPage": 10,  
> "showPartialRows": false,  
> "showMeticsAtAllLevels": false,  
> "sort": {  
> "columnIndex": null,  
> "direction": null  
> },  
> "showTotal": false,  
> "totalFunc": "sum"  
> },  
> "aggs": [  
> {  
> "id": "1",  
> "enabled": true,  
> "type": "count",  
> "schema": "metric",  
> "params": {  
> "json": "",  
> "customLabel": ""  
> }  
> },  
> {  
> "id": "3",  
> "enabled": true,  
> "type": "filters",  
> "schema": "bucket",  
> "params": {  
> "filters": [  
> {  
> "input": {  
> "query": {  
> "query\_string": {  
> "query": "syslog\_message: _CRC_",  
> "analyze\_wildcard": true  
> }  
> }  
> },  
> "label": "CRC Allignment error"  
> },  
> {  
> "input": {  
> "query": {  
> "query\_string": {  
> "query": "syslog\_message: (Duplex AND Mismatch)",  
> "analyze\_wildcard": true  
> }  
> }  
> },  
> "label": "Speed Duplex error"  
> }  
> ],  
> "json": "{ "min\_doc\_count":1}"  
> }  
> },  
> {  
> "id": "4",  
> "enabled": true,  
> "type": "date\_histogram",  
> "schema": "bucket",  
> "params": {  
> "field": "received\_at",  
> "interval": "d",  
> "customInterval": "2h",  
> "min\_doc\_count": 1,  
> "extended\_bounds": {},  
> "json": "",  
> "customLabel": ""  
> }  
> },  
> {  
> "id": "2",  
> "enabled": true,  
> "type": "terms",  
> "schema": "bucket",  
> "params": {  
> "field": "host.keyword",  
> "exclude": {  
> "pattern": ""  
> },  
> "size": 5,  
> "order": "desc",  
> "orderBy": "\_term"  
> }  
> }  
> ],  
> "listeners": {}  
> }

And it gives me this error:

Error: [parsing\_exception] Unknown key for a VALUE\_NUMBER in [3]: [min\_doc\_count]., with { line=1 col=462 }

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [September 28, 2017, 7:27pm UTC](https://discuss.elastic.co/t/problems-with-min-doc-count/102114/2 "2017-09-28T19:27:08Z")

</div>

Filter aggregation does not support `min_doc_count`. You could check out [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket.html)

You could do a `terms aggregation` may be to achieve this. Do let us know. We got the same error what you got when `min_doc_count` was used. Also which version of ES/Kibana you are using helps.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![klubbe](https://avatars.discourse-cdn.com/v4/letter/k/d78d45/32.png) [@klubbe](https://discuss.elastic.co/u/klubbe)\
**Post date:** [September 29, 2017, 6:29am UTC](https://discuss.elastic.co/t/problems-with-min-doc-count/102114/3 "2017-09-29T06:29:58Z")

</div>

We are using "Version 5.0.2"

What I did to solve this was to use the term aggregation to add the field I was filtering the values from. Then I filtered the entire visualization with this ahndy little query.

> {  
> "query": {  
> "query\_string": {  
> "default\_field": "syslog\_message",  
> "query": ""CRC" OR "Duplex"",  
> "analyze\_wildcard": true  
> }  
> }  
> }

With this you can query for as many values as youd like.

Hope this helps somebody else.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2017, 6:30am UTC](https://discuss.elastic.co/t/problems-with-min-doc-count/102114/4 "2017-10-27T06:30:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
