# Searching and Aggregating Terms

**URL:** <https://discuss.elastic.co/t/searching-and-aggregating-terms/23877>\
**Category:** Elasticsearch\
**Created:** [June 17, 2015, 8:57pm UTC](https://discuss.elastic.co/t/searching-and-aggregating-terms/23877 "2015-06-17T20:57:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![infecto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/infecto/32/3394_2.png) [@infecto](https://discuss.elastic.co/u/infecto)\
**Post date:** [June 17, 2015, 8:57pm UTC](https://discuss.elastic.co/t/searching-and-aggregating-terms/23877/1 "2015-06-17T20:57:18Z")

</div>

I am trying to create a search query that finds the top results that can then be used as filtered terms. Let me describe the workflow.

- User wants to filter list of data. The filters should be elasticsearch terms, so exact matches.
- User enters search string "John Doe". What I want to see is a return of the top hits by field. So for example the results might include the following. 1) full\_name: "John Doe" 2) email: "john.doe@gmail.com" 3) title: "something something doe something john"

Is there a nice recipe for this type of search? So far I have been playing around with a match search and then aggregation but I am not 100% sure if this is the best route.

---

<div class="post-metadata">

**Author:** ![dantuff](https://avatars.discourse-cdn.com/v4/letter/d/e79b87/32.png) [@dantuff](https://discuss.elastic.co/u/dantuff)\
**Post date:** [June 18, 2015, 10:17am UTC](https://discuss.elastic.co/t/searching-and-aggregating-terms/23877/2 "2015-06-18T10:17:35Z")

</div>

If I have understood you correctly, it is possible to do what you want using a [filter aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/1.4/search-aggregations-bucket-filter-aggregation.html) with a [terms aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html) for every field.

To search on the `email` field you'll need to add a mapping that indexes the `email` using the `simple` analyzer so that the email name is searchable, e.g., [john.doe@gmail.com](mailto:john.doe@gmail.com) is tokenized as 'john' 'doe' 'email' 'com'. You'll also need to store untokenized copies of the fields in the index for the aggregation values. Here is a simple example:

Create the index with the mapping

```
POST /example
{
    "mappings": {
        "doc": {
            "properties": {
                "full_name": {
                    "type": "string",
                    "fields": {
                        "raw": {
                            "type": "string",
                            "index": "not_analyzed"
                        }
                    }
                },
                "email": {
                    "type": "string",
                    "fields": {
                        "email_name": {
                            "type": "string",
                            "analyzer": "simple"
                        },
                        "raw": {
                            "type": "string",
                            "index": "not_analyzed"
                        }
                    }
                },
                "title": {
                    "type": "string",
                    "fields": {
                        "raw": {
                            "type": "string",
                            "index": "not_analyzed"
                        }
                    }
                }
            }
        }
    }
}

```

Create some documents:

```
POST /example/doc/1
{
    "full_name": "John Doe",
    "email": "john.doe@gmail.com",
    "title": "something something"
}

POST /example/doc/2
{
    "full_name": "John Doe",
    "email": "john.doe@gmail.com",
    "title": "something something"
}

POST /example/doc/3
{
    "full_name": "Joe Smith",
    "email": "test@email.com",
    "title": "something something doe something john"
}

```

Execute the search:

```
POST /example/doc/_search?search_type=count
{
    "aggregations": {
        "name_filter_query": {
            "filter": {
                "query": {
                    "match": {
                        "full_name": {
                            "query": "John Doe",
                            "operator": "AND"
                        }
                    }
                }
            },
            "aggregations": {
                "full_name": {
                    "terms": {
                        "field": "full_name.raw"
                    }
                }
            }
        },
        "email_filter_query": {
            "filter": {
                "query": {
                    "match": {
                        "email_name": {
                            "query": "John Doe",
                            "operator": "AND"
                        }
                    }
                }
            },
            "aggregations": {
                "full_name": {
                    "terms": {
                        "field": "email.raw"
                    }
                }
            }
        },
        "title_filter_query": {
            "filter": {
                "query": {
                    "match": {
                        "title": {
                            "query": "John Doe",
                            "operator": "AND"
                        }
                    }
                }
            },
            "aggregations": {
                "full_name": {
                    "terms": {
                        "field": "title.raw"
                    }
                }
            }
        }
    }
}

```

Returns this response:

```
"aggregations": {
    "email_filter_query": {
        "doc_count": 2,
        "full_name": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
                {
                    "key": "john.doe@gmail.com",
                    "doc_count": 2
                }
            ]
        }
    },
    "title_filter_query": {
        "doc_count": 1,
        "full_name": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
                {
                    "key": "something something doe something john",
                    "doc_count": 1
                }
            ]
        }
    },
    "name_filter_query": {
        "doc_count": 2,
        "full_name": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
                {
                    "key": "John Doe",
                    "doc_count": 2
                }
            ]
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:06am UTC](https://discuss.elastic.co/t/searching-and-aggregating-terms/23877/3 "2017-07-06T00:06:48Z")

</div>


