# REST API to fetch values based on Terms aggregation

**URL:** <https://discuss.elastic.co/t/rest-api-to-fetch-values-based-on-terms-aggregation/241188>\
**Category:** Elasticsearch\
**Created:** [July 14, 2020, 8:01pm UTC](https://discuss.elastic.co/t/rest-api-to-fetch-values-based-on-terms-aggregation/241188 "2020-07-14T20:01:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Venkat\_Raj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkat_raj/32/51823_2.png) [@Venkat\_Raj](https://discuss.elastic.co/u/Venkat_Raj)\
**Post date:** [July 14, 2020, 8:01pm UTC](https://discuss.elastic.co/t/rest-api-to-fetch-values-based-on-terms-aggregation/241188/1 "2020-07-14T20:01:48Z")

</div>

Hi All,

I have a requirement to fetch data from Elasticsearch based on Term aggregation. I need to build a request using terms aggregation where I need to groupby a particular field name and then fetch other fields corresponding to that particular field value.

For example, I have the following fields:  
Hostname, hostip, hostinglocation, applicationinfo, portsopened.  
Now first I need to groupby using Hostname and then fetch the corresponding values of hostip, hostinglocation, applicationinfo and portsopened for that particular hostname.  
Again for the next hostname, i need the next set of information.  
so the request should something like below:

```auto
{
  "aggs": {
    "agg1": {
      "terms": {
        "field": "field1"
      },
      "aggs": {
        "agg2": {
          "terms": {
            "field": "field2"
          },
          "aggs": {
            "agg3": {
              "terms": {
                "field": "field3"
              }
            }
          }          
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 14, 2020, 10:05pm UTC](https://discuss.elastic.co/t/rest-api-to-fetch-values-based-on-terms-aggregation/241188/2 "2020-07-14T22:05:16Z")

</div>

@Venkat_Raj

> [@Venkat\_Raj](#):
>
> Now first I need to groupby using Hostname and then fetch the corresponding values of hostip, hostinglocation, applicationinfo and portsopened for that particular hostname.

For a given hostname let's say there are 1000 documents, do you want to see all 1000? Generally you group on a field and get aggregate (count, avg) on other fields.

These 1000 documents may contain multiple documents for a given let's say hostip. Do you want to group on hostip under each hostname?

---

<div class="post-metadata">

**Author:** ![Venkat\_Raj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkat_raj/32/51823_2.png) [@Venkat\_Raj](https://discuss.elastic.co/u/Venkat_Raj)\
**Post date:** [July 27, 2020, 7:55pm UTC](https://discuss.elastic.co/t/rest-api-to-fetch-values-based-on-terms-aggregation/241188/3 "2020-07-27T19:55:29Z")

</div>

HI @Vinayak_Sapre

I have used the aggregation function to group the values i would need to get from the given set of records and it worked.  
Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2020, 7:55pm UTC](https://discuss.elastic.co/t/rest-api-to-fetch-values-based-on-terms-aggregation/241188/4 "2020-08-24T19:55:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
