# Restricting Bucket Aggregation to Certain Values

**URL:** <https://discuss.elastic.co/t/restricting-bucket-aggregation-to-certain-values/21134>\
**Category:** Elasticsearch\
**Created:** [December 8, 2014, 8:10am UTC](https://discuss.elastic.co/t/restricting-bucket-aggregation-to-certain-values/21134 "2014-12-08T08:10:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![William\_Bowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/william_bowen/32/1057_2.png) [@William\_Bowen](https://discuss.elastic.co/u/William_Bowen)\
**Post date:** [December 8, 2014, 8:10am UTC](https://discuss.elastic.co/t/restricting-bucket-aggregation-to-certain-values/21134/1 "2014-12-08T08:10:05Z")

</div>

I want to know if it is possible to filter the contents of an aggregation  
rather than just the documents returned by the query. For instance, I have  
a set of documents that have an array property called related concepts. I  
want to count the number of documents for each related concept that meet my  
search query. The resulting bucket looks like this:

"related\_concepts": {  
"buckets": [  
{  
"key": "foo",  
"doc\_count": 3821  
},  
{  
"key": "bar",  
"doc\_count": 3803  
},  
{  
"key": "other",  
"doc\_count": 23  
}  
]  
}

Now imagine that there are 2,000 related concepts, however, using a graph  
database I know I'm interested in a specific 5 or 6. Using the example  
above, let's say for a specific result set I want to return the bucket  
counts only for the terms "foo" and "other" but NOT include "bar" or any  
other buckets. Sort of like a SQL WHERE or HAVING clause.

I tried adding a filter to the aggregation, but it only seemed to filter  
the numbers for the aggregations, not restrict which buckets are actually  
displayed.

I found this for  
2.0 [https://github.com/elasticsearch/elasticsearch/issues/8110](https://github.com/elasticsearch/elasticsearch/issues/8110), and looks  
like it might solve my problem eventually (not in time for deadlines!), but  
my use case is pretty simple. Is there anything I can do in the current  
version of Elasticsearch to make this work? Am I overlooking something?

Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cb4d25de-825b-4c2f-9434-86419e5aa3ff%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cb4d25de-825b-4c2f-9434-86419e5aa3ff%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [December 8, 2014, 8:20am UTC](https://discuss.elastic.co/t/restricting-bucket-aggregation-to-certain-values/21134/2 "2014-12-08T08:20:00Z")

</div>

Hi,

Take a look at the includes/excludes feature on the terms aggregation. I  
think it should help with what you are trying to achieve.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Colin

On Monday, 8 December 2014 08:10:05 UTC, William Bowen wrote:

> I want to know if it is possible to filter the contents of an aggregation  
> rather than just the documents returned by the query. For instance, I have  
> a set of documents that have an array property called related concepts. I  
> want to count the number of documents for each related concept that meet my  
> search query. The resulting bucket looks like this:
> 
> "related\_concepts": {  
> "buckets": [  
> {  
> "key": "foo",  
> "doc\_count": 3821  
> },  
> {  
> "key": "bar",  
> "doc\_count": 3803  
> },  
> {  
> "key": "other",  
> "doc\_count": 23  
> }  
> ]  
> }
> 
> Now imagine that there are 2,000 related concepts, however, using a graph  
> database I know I'm interested in a specific 5 or 6. Using the example  
> above, let's say for a specific result set I want to return the bucket  
> counts only for the terms "foo" and "other" but NOT include "bar" or any  
> other buckets. Sort of like a SQL WHERE or HAVING clause.
> 
> I tried adding a filter to the aggregation, but it only seemed to filter  
> the numbers for the aggregations, not restrict which buckets are actually  
> displayed.
> 
> I found this for 2.0  
> [Reducers - Post processing of aggregation results · Issue #8110 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/8110), and looks  
> like it might solve my problem eventually (not in time for deadlines!), but  
> my use case is pretty simple. Is there anything I can do in the current  
> version of Elasticsearch to make this work? Am I overlooking something?
> 
> Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5bb64118-b4d5-4f47-8c72-530040083381%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5bb64118-b4d5-4f47-8c72-530040083381%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![William\_Bowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/william_bowen/32/1057_2.png) [@William\_Bowen](https://discuss.elastic.co/u/William_Bowen)\
**Post date:** [December 8, 2014, 8:40am UTC](https://discuss.elastic.co/t/restricting-bucket-aggregation-to-certain-values/21134/3 "2014-12-08T08:40:16Z")

</div>

Wow, this looks like exactly what I'm looking for. But I swear I spent most  
of last month scouring documentation. Is this a relatively new feature? Or  
am I just thick? Thanks, either way!

On Mon, Dec 8, 2014 at 3:20 AM, Colin Goodheart-Smithe \<  
[colin.goodheart-smithe@elasticsearch.com](mailto:colin.goodheart-smithe@elasticsearch.com)\> wrote:

> Hi,
> 
> Take a look at the includes/excludes feature on the terms aggregation. I  
> think it should help with what you are trying to achieve.
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_filtering_values)
> 
> Colin
> 
> On Monday, 8 December 2014 08:10:05 UTC, William Bowen wrote:
> 
> > I want to know if it is possible to filter the contents of an aggregation  
> > rather than just the documents returned by the query. For instance, I have  
> > a set of documents that have an array property called related concepts. I  
> > want to count the number of documents for each related concept that meet my  
> > search query. The resulting bucket looks like this:
> > 
> > "related\_concepts": {  
> > "buckets": [  
> > {  
> > "key": "foo",  
> > "doc\_count": 3821  
> > },  
> > {  
> > "key": "bar",  
> > "doc\_count": 3803  
> > },  
> > {  
> > "key": "other",  
> > "doc\_count": 23  
> > }  
> > ]  
> > }
> > 
> > Now imagine that there are 2,000 related concepts, however, using a graph  
> > database I know I'm interested in a specific 5 or 6. Using the example  
> > above, let's say for a specific result set I want to return the bucket  
> > counts only for the terms "foo" and "other" but NOT include "bar" or any  
> > other buckets. Sort of like a SQL WHERE or HAVING clause.
> > 
> > I tried adding a filter to the aggregation, but it only seemed to filter  
> > the numbers for the aggregations, not restrict which buckets are actually  
> > displayed.
> > 
> > I found this for 2.0 [GitHub - elastic/elasticsearch: Free and Open, Distributed, RESTful Search Engine](https://github.com/elasticsearch/elasticsearch/)  
> > issues/8110, and looks like it might solve my problem eventually (not in  
> > time for deadlines!), but my use case is pretty simple. Is there anything I  
> > can do in the current version of Elasticsearch to make this work? Am I  
> > overlooking something?
> > 
> > Thanks!
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/SR2Yb-Q2zB8/unsubscribe](https://groups.google.com/d/topic/elasticsearch/SR2Yb-Q2zB8/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/5bb64118-b4d5-4f47-8c72-530040083381%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5bb64118-b4d5-4f47-8c72-530040083381%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/5bb64118-b4d5-4f47-8c72-530040083381%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/5bb64118-b4d5-4f47-8c72-530040083381%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEi1X1SPbCXB8vAK-BtgGLYTbHYu5JuWxhEu8RiU-AFzAxNbQw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEi1X1SPbCXB8vAK-BtgGLYTbHYu5JuWxhEu8RiU-AFzAxNbQw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:45am UTC](https://discuss.elastic.co/t/restricting-bucket-aggregation-to-certain-values/21134/4 "2017-07-06T00:45:05Z")

</div>


