# Retrieve information about matched words before aggregation

**URL:** <https://discuss.elastic.co/t/retrieve-information-about-matched-words-before-aggregation/81581>\
**Category:** Elasticsearch\
**Created:** [April 7, 2017, 7:38am UTC](https://discuss.elastic.co/t/retrieve-information-about-matched-words-before-aggregation/81581 "2017-04-07T07:38:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pierre\_l](https://avatars.discourse-cdn.com/v4/letter/p/7ea924/32.png) [@pierre\_l](https://discuss.elastic.co/u/pierre_l)\
**Post date:** [April 7, 2017, 7:39am UTC](https://discuss.elastic.co/t/retrieve-information-about-matched-words-before-aggregation/81581/1 "2017-04-07T07:39:00Z")

</div>

Hi guys,

I'm new to elasticsearch so I hope I used the right terms and that my explanations are clear.  
Please tell me if the title is unclear (and sorry for bad english)

I have this schema :

```
{
  "myindex" : {
    "mappings" : {
      "information" : {
        "_parent" : {
          "type" : "user"
        },
        "_routing" : {
          "required" : true
        },
        "properties" : {
          "event" : {
            "type" : "keyword"
          },
          "date" : {
            "type" : "date"
          }
        }
      }
    }
  }
}

{
  "myindex" : {
    "mappings" : {
      "user" : {
        "properties" : {
          "name" : {
            "type" : "keyword"
          }
        }
      }
    }
  }
}

```

I'm trying to make a query like "_all user who went through event "A" then through event "B"_ " :  
So I did this :

```
curl -XPOST 'localhost:9200/myindex/information/_search?pretty' -d '
{
  "query": {
    "bool": {
      "must": [{
        "has_parent" : {
          "parent_type" : "user",
          "query" : {
            "bool": {
              "must": [{
                "has_child" : {
                  "type" : "information",
                  "query" : {
                    "term" : {
                      "event" : "A"
                    }
                  }
                }
              },{
                "has_child" : {
                  "type" : "information",
                  "query" : {
                    "term" : {
                      "event" : "B"
                    }
                  }
                }
              }]
            }
          }
        }
      },{
        "bool": {
          "should": {
            "term": {
              "event": "A"
            }
          },
          "should": {
            "term": {
              "event": "B"
            }
          }
        }
      }]
    },
    "aggs": {
      "isok": {
        "scripted_metric": {
          "init_script" : "params.myctx.compute_map = [:];params._agg.listusers = [];",
          "map_script" : {
            "lang" : "groovy",
            "file" : "myscript"
          },
          "params": {
            "_agg": {},
            "myctx": {},
            "firstCrit" : "A",
            "secdCrit" : "B"
          }
        }
      }
    }
  }
}'

```

I get all the "informations" hits about event "A" or event "B" from users who went through event A and through event B  
When I have all these hits I aggregate with my script "myscript", where I fill a double map like  
map[[user.name](http://user.name)][information.event]=information.date (for each user, I try to find the oldest event A, the newest event B and I compare to know if eventA.date\<eventB.date etc ....)  
And it works fine !

but actually the "event" field is not a keyword field but a text.  
The query is the same, I just replace "term" with "match" but I can't make my aggregation anymore because when my script is executed for each hit from the query, I miss the event.  
I know the current hit contains A or B (or both) but I don't know which.  
I can't access the "event" field because it's a text field so I lost the information about "why this hit has been selected" before the aggregation phase.

Is there a way to retreive this information from my aggregation script ?  
Could I pass the information on which word(s) matched before the aggregation ?

Thank in advance for your help,

Regards,

Pierre

---

<div class="post-metadata">

**Author:** ![pierre\_l](https://avatars.discourse-cdn.com/v4/letter/p/7ea924/32.png) [@pierre\_l](https://discuss.elastic.co/u/pierre_l)\
**Post date:** [April 21, 2017, 9:27am UTC](https://discuss.elastic.co/t/retrieve-information-about-matched-words-before-aggregation/81581/2 "2017-04-21T09:27:33Z")

</div>

Hi,

I tried to use scipt fields but they are not visible from aggregation.

It looks like there is no way to achieve my query.

I was very enthusiastic when I found out how to make my query "all user who went through event "A" then through event "B" " as I realized the power of parent/child relationship and scripted aggregations.  
I really hoped it could be possible to make this kind of complex queries on a "match" criteria.  
Unfortunatly it seems impossible at the aggregation stage to retreive the information about which word matched a match query.  
I'll have to use several queries and deal with results (compare to know if eventA.date\<eventB.date etc ...) on my side.

Regards,

Pierre

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 9:34am UTC](https://discuss.elastic.co/t/retrieve-information-about-matched-words-before-aggregation/81581/3 "2017-05-19T09:34:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
