# Script for Aggs

**URL:** <https://discuss.elastic.co/t/script-for-aggs/188366>\
**Category:** Elasticsearch\
**Created:** [July 1, 2019, 3:55pm UTC](https://discuss.elastic.co/t/script-for-aggs/188366 "2019-07-01T15:55:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 1, 2019, 3:55pm UTC](https://discuss.elastic.co/t/script-for-aggs/188366/1 "2019-07-01T15:55:29Z")

</div>

The search is working fine, but i want to retrive only the "remetente" with ("doc\_count"\>=50),  
This is exemple for the search:

```
GET /imsva_message/_search 
{ 
"size": 0,
"aggs" : { 
    "aggdata" : { 
        "filter": { 
          "range": {
            "data1": {
              "from": "now-15m",
              "to": "now"
            }
          }
        },
        "aggs" : { 
          "aggremetente" : { 
            "terms" : { 
              "field" : "remetente.keyword" 
            } 
          } 
        } 
    } 
 } 
}

```

and this is a response:

```
{
"took" : 101,
"timed_out" : false,
"_shards" : {
"total" : 5,
"successful" : 5,
"skipped" : 0,
"failed" : 0
},
"hits" : {
"total" : 2806032,
"max_score" : 0.0,
"hits" : []
},
"aggregations" : {
"aggdata" : {
  "doc_count" : 1450,
  "aggremetente" : {
    "doc_count_error_upper_bound" : 8,
    "sum_other_doc_count" : 558,
    "buckets" : [
      {
        "key" : "xxx@xxx",
        "doc_count" : 467
      },
      {
        "key" : "xxx.com.br",
        "doc_count" : 103
      },
      {
        "key" : "xxx@yyy",
        "doc_count" : 73
      },
      {
        "key" : "yyy@xxx",
        "doc_count" : 61
      },
      {
        "key" : "xyx@xxx",
        "doc_count" : 56
      },
      {
        "key" : "xyx@yyy",
        "doc_count" : 55
      },
      {
        "key" : "xxx@xyx",
        "doc_count" : 20
      },
      {
        "key" : "yyy@xyx",
        "doc_count" : 19
      },
      {
        "key" : "yyy.yyy.com.br",
        "doc_count" : 17
      },
      {
        "key" : "yyy@yyy",
        "doc_count" : 15
      }
    ]
  }
}
}
}

```

and the response a want is the the "keys" with "doc\_count" : \>=50, what would it be:

```
{
        "key" : "xxx@xxx",
        "doc_count" : 467
      },
      {
        "key" : "xxx.com.br",
        "doc_count" : 103
      },
      {
        "key" : "xxx@yyy",
        "doc_count" : 73
      },
      {
        "key" : "yyy@xxx",
        "doc_count" : 61
      },
      {
        "key" : "xyx@xxx",
        "doc_count" : 56
      },
      {
        "key" : "xyx@yyy",
        "doc_count" : 55
      }
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 2, 2019, 11:20am UTC](https://discuss.elastic.co/t/script-for-aggs/188366/2 "2019-07-02T11:20:10Z")

</div>

See the [min\_doc\_count](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/search-aggregations-bucket-terms-aggregation.html#_minimum_document_count_4) option in the terms agg.

--Alex

---

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 2, 2019, 5:51pm UTC](https://discuss.elastic.co/t/script-for-aggs/188366/3 "2019-07-02T17:51:47Z")

</div>

Thank you Alex, is working fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 5:51pm UTC](https://discuss.elastic.co/t/script-for-aggs/188366/4 "2019-07-30T17:51:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
