# Strange terms aggregation result: the single document is placed in several buckets if field contains some special symbols

**URL:** <https://discuss.elastic.co/t/strange-terms-aggregation-result-the-single-document-is-placed-in-several-buckets-if-field-contains-some-special-symbols/62850>\
**Category:** Elasticsearch\
**Created:** [October 12, 2016, 6:38pm UTC](https://discuss.elastic.co/t/strange-terms-aggregation-result-the-single-document-is-placed-in-several-buckets-if-field-contains-some-special-symbols/62850 "2016-10-12T18:38:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![111134](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111134/32/12445_2.png) [@111134](https://discuss.elastic.co/u/111134)\
**Post date:** [October 12, 2016, 6:38pm UTC](https://discuss.elastic.co/t/strange-terms-aggregation-result-the-single-document-is-placed-in-several-buckets-if-field-contains-some-special-symbols/62850/1 "2016-10-12T18:38:27Z")

</div>

Hello all

I'm trying to make the terms aggregation for simple string field. In the most cases all is ok but for string containing some symbols like / or @ the document with such string is placed into several buckets with key containing only part of original string.

Here is the exmple.  
Index structure:  
curl -XPUT "[http://localhost:9200/test/](http://localhost:9200/test/)" -d'  
{  
"mappings": {  
"url": {  
"properties": {  
"date": {  
"type": "date",  
"format": "dateOptionalTime"  
},  
"address": {  
"type": "string"  
}  
}  
}  
}  
}'

Bulk insert:  
curl -XPOST "[http://localhost:9200/test/\_bulk](http://localhost:9200/test/_bulk)" -d'  
{"index":{"\_index":"test","\_type":"url", "\_id": "1"}}  
{"date":"2016-10-01", "address":"79031112233"}  
{"index":{"\_index":"test","\_type":"url", "\_id": "2"}}  
{"date":"2016-10-02", "address":"part1/part2@part3"}  
'

Aggregation request:  
curl -XPOST "[http://localhost:9200/test/url/\_search?pretty](http://localhost:9200/test/url/_search?pretty)" -d'  
{  
"size": 0,  
"aggregations": {  
"the\_name": {  
"terms": {  
"field": "address"  
}  
}  
}  
}'

I expected to receive two buckets in the response with keys 79031112233 and part1/part2@part3 but received:  
{  
"took" : 20,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 5,  
"successful" : 5,  
"failed" : 0  
},  
"hits" : {  
"total" : 2,  
"max\_score" : 0.0,  
"hits" : []  
},  
"aggregations" : {  
"the\_name" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [ {  
"key" : "79031112233",  
"doc\_count" : 1  
}, {  
"key" : "part1",  
"doc\_count" : 1  
}, {  
"key" : "part2",  
"doc\_count" : 1  
}, {  
"key" : "part3",  
"doc\_count" : 1  
} ]  
}  
}  
}

Could anyone explain the result and point me how to get 'the correct' one with two buckets? I'm a newbit to elasticsearch so probably I missed something obvious in the docs.

Thanks in advance  
Alexey

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [October 13, 2016, 3:57am UTC](https://discuss.elastic.co/t/strange-terms-aggregation-result-the-single-document-is-placed-in-several-buckets-if-field-contains-some-special-symbols/62850/2 "2016-10-13T03:57:42Z")

</div>

Your address field is "analyzed" field.  
See [https://www.elastic.co/guide/en/elasticsearch/reference/2.4/string.html#string](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/string.html#string)  
and [https://www.elastic.co/guide/en/elasticsearch/guide/2.x/aggregations-and-analysis.html](https://www.elastic.co/guide/en/elasticsearch/guide/2.x/aggregations-and-analysis.html)

---

<div class="post-metadata">

**Author:** ![111134](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111134/32/12445_2.png) [@111134](https://discuss.elastic.co/u/111134)\
**Post date:** [October 13, 2016, 6:58am UTC](https://discuss.elastic.co/t/strange-terms-aggregation-result-the-single-document-is-placed-in-several-buckets-if-field-contains-some-special-symbols/62850/3 "2016-10-13T06:58:52Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:12pm UTC](https://discuss.elastic.co/t/strange-terms-aggregation-result-the-single-document-is-placed-in-several-buckets-if-field-contains-some-special-symbols/62850/4 "2017-07-05T22:12:45Z")

</div>


