# Terms Aggregation, but over a time period?

**URL:** <https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275>\
**Category:** Elasticsearch\
**Created:** [January 30, 2020, 9:18pm UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275 "2020-01-30T21:18:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![erin\_verbeck](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@erin\_verbeck](https://discuss.elastic.co/u/erin_verbeck)\
**Post date:** [January 30, 2020, 9:18pm UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275/1 "2020-01-30T21:18:50Z")

</div>

Hi everyone! I am trying to create a query that searches and identifies when a specific term reaches a threshold over a given period of time. My first thought is to construct a search that will, for example, bring back the total number of ice cream cones sold over 3 hours, aggregated by flavor. What would be the best route for this? I can see a terms aggregation could help:

```
GET /_search
{
    "aggs" : {
        "genres" : {
            "terms" : { "field" : "genre" } 
        }
    }
}

```

But is it possible to include the time in the search? I have access to the @timestamp field, so would it be possible to combine a basic must query (where i can reference @timestamp) and the term aggregation? My ideal output would be something like this - but over a 3 hour period:

...  
"aggregations" : {  
"cone\_flavors" : {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets" : [  
{  
"key" : "vanilla",  
"doc\_count" : 100  
},  
{  
"key" : "chocolate",  
"doc\_count" : 83  
},  
{  
"key" : "twist",  
"doc\_count" : 43  
}  
]  
}  
}  
}

Thank you all for your help, and apologies if the answer is somewhere in the docs but I overlooked 🥶

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 31, 2020, 9:17am UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275/2 "2020-01-31T09:17:33Z")

</div>

yes, you can combine a query and and aggregation like this

```auto
{
  "query" : { "range" : { "@timestamp" : { "gte" : "now-3d", "lt" : "now" } } },
  "aggs" : {
        "genres" : {
            "terms" : { "field" : "genre" } 
        }
    }
}

```

This will only aggregate on the documents that match the query.

---

<div class="post-metadata">

**Author:** ![erin\_verbeck](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@erin\_verbeck](https://discuss.elastic.co/u/erin_verbeck)\
**Post date:** [January 31, 2020, 4:18pm UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275/3 "2020-01-31T16:18:13Z")

</div>

Hi Spinscale, thanks for your response. I'm still having trouble getting the response to return within the time limit.

I am getting back everything from X index from the last 3 days (using the example), and then get back the buckets containing all the genres with their total counts. However, if I would change the @timestamp to be 1 minute, the buckets still contain the same count for the genre aggregation.  
These two queries return the same results, almost as if the queries were operating separately:

```
GET /blah-blah*/_search
{
  "query": {
    "range": {
      "@timestamp": {
        "from": "now-1M",
        "to": "now"
      }
    }
  },
  "aggs": {
    "genres": {
      "terms": {
        "field": "genre"
      }
    }
  }
}

 GET /blah-blah*/_search
    {
      "query": {
        "range": {
          "@timestamp": {
            "from": "now-3d",
            "to": "now"
          }
        }
      },
      "aggs": {
        "genres": {
          "terms": {
            "field": "genre"
          }
        }
      }
    }

```

Results:  
....  
"aggregations" : {  
"genres" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [  
{  
"key" : "Rock",  
"doc\_count" : 30746  
},  
{  
"key" : "Bluegrass",  
"doc\_count" : 20477  
},  
{  
"key" : "Jazz",  
"doc\_count" : 3221  
},  
{  
"key" : "Country",  
"doc\_count" : 1918  
},  
...

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 3, 2020, 3:07pm UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275/4 "2020-02-03T15:07:20Z")

</div>

hey, can you share the **full** response of both queries?

---

<div class="post-metadata">

**Author:** ![erin\_verbeck](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@erin\_verbeck](https://discuss.elastic.co/u/erin_verbeck)\
**Post date:** [February 12, 2020, 8:33pm UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275/5 "2020-02-12T20:33:11Z")

</div>

Hi Spinscale, I am so sorry for the delayed response. So, as it turns out, your query totally worked - I was searching over the past month of data (1M), not minute in my above query. And, since our Elasticsearch cluster was so new (like, 2 days old), it returned the same amount of data. Thank you for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2020, 8:33pm UTC](https://discuss.elastic.co/t/terms-aggregation-but-over-a-time-period/217275/6 "2020-03-11T20:33:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
