# Terms aggregation is breaking field into tokens

**URL:** https://discuss.elastic.co/t/terms-aggregation-is-breaking-field-into-tokens/43640
**Category:** Elasticsearch
**Created:** [March 7, 2016, 10:46am UTC](https://discuss.elastic.co/t/terms-aggregation-is-breaking-field-into-tokens/43640 "2016-03-07T10:46:07Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![harshafrnd4u](https://avatars.discourse-cdn.com/v4/letter/h/fbc32d/32.png) [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)
#### Post date: [March 7, 2016, 10:46am UTC](https://discuss.elastic.co/t/terms-aggregation-is-breaking-field-into-tokens/43640/1 "2016-03-07T10:46:07Z")

</div>

I am using terms aggregation in elasticsearch something like

"aggs": {  
"url": {  
"terms": {  
"field": "request"  
}  
}  
}

My request field have values like "GET /" or "GET /test.html" . When I execute above query the output has buckets with

"buckets": [  
{  
"key": "get",  
"doc\_count": 436830  
},  
{  
"key": "test.html",  
"doc\_count": 2  
}  
]

I can see that it broke request field into multiple tokens and made it buckets. How to use aggregation with exact field ? I expect buckets to be "GET /" and "GET /test.html" .Please help

---

<div class="post-metadata">

### Author: ![mainec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mainec/32/5557_2.png) [@mainec](https://discuss.elastic.co/u/mainec)
#### Post date: [March 7, 2016, 12:02pm UTC](https://discuss.elastic.co/t/terms-aggregation-is-breaking-field-into-tokens/43640/2 "2016-03-07T12:02:21Z")

</div>

You probably stored the data in the field you are running the aggregation on in analyzed form. This means that the string stored in this field is split into what Elasticsearch thinks are distinct tokens/words. What you want instead is to store your data as "not\_analyzed". For more information see also here:

[https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-intro.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-intro.html)

Hope this helps,  
Isabel

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:10pm UTC](https://discuss.elastic.co/t/terms-aggregation-is-breaking-field-into-tokens/43640/3 "2017-07-05T23:10:43Z")

</div>


