# Search query based of number of values a field contains

**URL:** <https://discuss.elastic.co/t/search-query-based-of-number-of-values-a-field-contains/260408>\
**Category:** Elasticsearch\
**Created:** [January 7, 2021, 5:33am UTC](https://discuss.elastic.co/t/search-query-based-of-number-of-values-a-field-contains/260408 "2021-01-07T05:33:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bevano](https://avatars.discourse-cdn.com/v4/letter/b/6bbea6/32.png) [@bevano](https://discuss.elastic.co/u/bevano)\
**Post date:** [January 7, 2021, 5:33am UTC](https://discuss.elastic.co/t/search-query-based-of-number-of-values-a-field-contains/260408/1 "2021-01-07T05:33:20Z")

</div>

Hi,

I was wondering whether you can point me at any documentation, or let me know if this is not possible for the following.

I am trying to write a query of a fields called result\_code. Some of my documents contain multiple values for result\_code  
EXAMPLE: result\_code: 00, 08, 51

And majority of my other documents result\_code only has one value  
EXAMPLE: result\_code: 00

Is there any way I can filter out (ignore) documents where this field has multiple values. I want to do aggregations on the result\_code where is only contains 1 value

Thanks

---

<div class="post-metadata">

**Author:** ![vincenbr](https://avatars.discourse-cdn.com/v4/letter/v/8edcca/32.png) [@vincenbr](https://discuss.elastic.co/u/vincenbr)\
**Post date:** [January 8, 2021, 12:05am UTC](https://discuss.elastic.co/t/search-query-based-of-number-of-values-a-field-contains/260408/2 "2021-01-08T00:05:48Z")

</div>

Hi Bevano,  
You could use a scripted filter aggregation in order to filter only single-value docs for the result\_code field in your subsequent aggregations.  
example:

```auto
GET myindex/_search
{
  "aggs": {
    "only_single_value": {
      "filter": {
        "script": {
          "script": {
            "source": "doc['result_code.keyword'].size() == 1",
            "lang": "painless"
          }
        }
      },
      "aggs": {
        "my_codes": {
          "terms": {
            "field": "result_code.keyword",
            "size": 10
          }
        }
      }
    }
  }
}

```

Otherwise (less flexible but more efficient at search time), if you don't do arithlmetics on result\_code field, map it as type "text" and add a multi-field "lenght" of type "token\_count".  
Then, index the multiple values as a single concatenated value.  
Upon search, you will be able to filter on the numeric field result\_code.length=1

Hope this will help you !

Vincent

---

<div class="post-metadata">

**Author:** ![bevano](https://avatars.discourse-cdn.com/v4/letter/b/6bbea6/32.png) [@bevano](https://discuss.elastic.co/u/bevano)\
**Post date:** [January 8, 2021, 2:34am UTC](https://discuss.elastic.co/t/search-query-based-of-number-of-values-a-field-contains/260408/3 "2021-01-08T02:34:14Z")

</div>

> [@vincenbr](#):
>
> ```auto
> {
> "aggs": {
> "only_single_value": {
> "filter": {
> "script": {
> "script": {
> "source": "doc['result_code.keyword'].size() == 1",
> "lang": "painless"
> }
> }
> },
> "aggs": {
> "my_codes": {
> "terms": {
> "field": "result_code.keyword",
> "size": 10
> }
> }
> }
> }
> }
> }
> 
> ```

This is perfect @vincenbr. I totally forgot about scripts since I rarely use them. Life saver!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2021, 2:34am UTC](https://discuss.elastic.co/t/search-query-based-of-number-of-values-a-field-contains/260408/4 "2021-02-05T02:34:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
