# SubAggregations with array fields - more results than expected

**URL:** <https://discuss.elastic.co/t/subaggregations-with-array-fields-more-results-than-expected/34202>\
**Category:** Elasticsearch\
**Created:** [November 9, 2015, 9:23pm UTC](https://discuss.elastic.co/t/subaggregations-with-array-fields-more-results-than-expected/34202 "2015-11-09T21:23:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eliran\_Moyal](https://avatars.discourse-cdn.com/v4/letter/e/f6c823/32.png) [@Eliran\_Moyal](https://discuss.elastic.co/u/Eliran_Moyal)\
**Post date:** [November 9, 2015, 9:23pm UTC](https://discuss.elastic.co/t/subaggregations-with-array-fields-more-results-than-expected/34202/1 "2015-11-09T21:23:59Z")

</div>

Hey, i have a index contains a field named "message" which could by a string or array of strings.

i'm trying to do query like:  
select sumsum , message, count(\*) from myIndex  
where message in ('a','d')  
group by sumsum , message

so i did a simple query with terms agg sub and term sub aggregations  
but got more buckets than expected (messages which are not "a" or "d")

someone told me to try and use nested\_objects.  
so i re-indexed my data, and changed the query to:  
{  
"from": 0,  
"size": 0,  
"query": {  
"filtered": {  
"filter": {  
"bool": {  
"must": {  
"or": {  
"filters": [  
{  
"nested": {  
"path": "message",  
"query": {  
"match": {  
"message.name": {  
"query": "a",  
"type": "phrase"  
}  
}  
}  
}  
},  
{  
"nested": {  
"path": "message",  
"query": {  
"match": {  
"message.name": {  
"query": "d",  
"type": "phrase"  
}  
}  
}  
}  
}  
]  
}  
}  
}  
}  
}  
},  
"aggregations": {  
"sumsum": {  
"terms": {  
"field": "sumsum",  
"size": 3  
},  
"aggregations": {  
"message.name": {  
"nested": {  
"path": "message"  
},  
"aggregations": {  
"names": {  
"terms": {  
"field": "message.name",  
"size": 0  
}  
}  
}  
}  
}  
}  
}  
}

but still got more buckets than expected, example to output:  
{  
"took": 37,  
"timed\_out": false,  
"\_shards": {  
"total": 5,  
"successful": 5,  
"failed": 0  
},  
"hits": {  
"total": 194,  
"max\_score": 0,  
"hits": [

```
]

```

},  
"aggregations": {  
"sumsum": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 115,  
"buckets": [  
{  
"key": 0,  
"doc\_count": 28,  
"message.name": {  
"doc\_count": 28,  
"names": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"key": "a",  
"doc\_count": 17  
},  
{  
"key": "d",  
"doc\_count": 11  
},  
{  
"key": "c",  
"doc\_count": 1  
},  
{  
"key": "f",  
"doc\_count": 1  
},  
{  
"key": "h",  
"doc\_count": 1  
},  
{  
"key": "i",  
"doc\_count": 1  
}  
]  
}  
}  
},  
{  
"key": 1,  
"doc\_count": 27,  
"message.name": {  
"doc\_count": 27,  
"names": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"key": "d",  
"doc\_count": 14  
},  
{  
"key": "a",  
"doc\_count": 13  
},  
{  
"key": "f",  
"doc\_count": 1  
},  
{  
"key": "g",  
"doc\_count": 1  
},  
{  
"key": "h",  
"doc\_count": 1  
}  
]  
}  
}  
},  
{  
"key": 2,  
"doc\_count": 24,  
"message.name": {  
"doc\_count": 24,  
"names": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"key": "a",  
"doc\_count": 12  
},  
{  
"key": "d",  
"doc\_count": 12  
},  
{  
"key": "b",  
"doc\_count": 1  
}  
]  
}  
}  
}  
]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:39pm UTC](https://discuss.elastic.co/t/subaggregations-with-array-fields-more-results-than-expected/34202/2 "2017-07-05T23:39:37Z")

</div>


