# Terms Aggregation of long value

**URL:** https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223
**Category:** Elasticsearch
**Created:** [September 12, 2017, 2:19pm UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223 "2017-09-12T14:19:01Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Moshe\_Saada](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Moshe\_Saada](https://discuss.elastic.co/u/Moshe_Saada)
#### Post date: [September 12, 2017, 2:19pm UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/1 "2017-09-12T14:19:01Z")

</div>

Hi,

I've created data table visualization with terms aggregation and I saw the aggregation isn't working on some values, I think it's connected to the long but not sure.  
For example, the following value is aggregatable:

> "text": "#auto #error bgs failed to send feedback, however run itself completed"

and the following value is not aggregatable:

> "text": "#auto #error \n\*\*\*\*\*\*\*\*\n\* Uncaught EXCEPTION. Message: TypeError: r is not a function. (In 'r(function(){},function(){},"CarizmaExtensions","updateZappTokens",[{tokens:t,hotViewName:e}])', 'r' is undefined)\n\* Source: [https://app.carizma.com/v18/app.7890ab6d49b18fe01a87.js\n](https://app.carizma.com/v18/app.7890ab6d49b18fe01a87.js%5Cn)\* Line:column: [84:28287]\n\* Error: {"line":84,"column":28287,"sourceURL":"[https://app.carizma.com/v18/app.7890ab6d49b18fe01a87.js\](https://app.carizma.com/v18/app.7890ab6d49b18fe01a87.js%5C)"}\n\* Previous log line before exception: CardsService - after putApprovalsFirst there are 0 cards\n\*\*\*\*\*\*\*\*\n",

Do you have an idea why?

Thanks a lot

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [September 13, 2017, 9:01am UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/2 "2017-09-13T09:01:34Z")

</div>

Sorry, I don't recognise any of those error messages. What software is producing those?  
Can you simplify the problem down to an example CURL request and response to elasticsearch directly?

---

<div class="post-metadata">

### Author: ![Moshe\_Saada](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Moshe\_Saada](https://discuss.elastic.co/u/Moshe_Saada)
#### Post date: [September 13, 2017, 9:08am UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/3 "2017-09-13T09:08:57Z")

</div>

@Mark_Harwood  
It's our internal software logs, consider it as a string value of the "text" key.  
when I'm creating a data table with term aggregation of the "text" field the value of the second example (the long one) is not aggregatable.  
Thanks.

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [September 13, 2017, 9:30am UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/4 "2017-09-13T09:30:13Z")

</div>

> [@Moshe\_Saada](#):
>
> consider it as a string value of the "text" key.

Ah I see. Often there's a limit on field length for aggregatable values. See [1].  
Not a logstash expert but I expect 256 is the default limit in an index mapping.

[1] [ignore\_above | Elasticsearch Reference [5.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/ignore-above.html)

---

<div class="post-metadata">

### Author: ![Moshe\_Saada](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Moshe\_Saada](https://discuss.elastic.co/u/Moshe_Saada)
#### Post date: [September 14, 2017, 10:37am UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/5 "2017-09-14T10:37:06Z")

</div>

I think it's related to the mapping of the field. keyword\text ???  
What is the parallel behavior of "type: string", "index: not\_analyzed" on the new ES versions 5.x.x ?

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [September 14, 2017, 10:38am UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/6 "2017-09-14T10:38:32Z")

</div>

> [@Moshe\_Saada](#):
>
> "type: string", "index: not\_analyzed" on the new ES versions 5.x.x ?

type : keyword

---

<div class="post-metadata">

### Author: ![Moshe\_Saada](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Moshe\_Saada](https://discuss.elastic.co/u/Moshe_Saada)
#### Post date: [September 14, 2017, 2:05pm UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/7 "2017-09-14T14:05:43Z")

</div>

Do the "text.keyword" field is already mapped as keyword?  
Which field do I need to specify on the mapping- "text.keyword" or "text"?

> "mappings": {  
> "feedbacks": {  
> "properties": {  
> "text": {  
> "type": "keyword"  
> }  
> }  
> }  
> }

or:

> "mappings": {  
> "feedbacks": {  
> "properties": {  
> "text": {  
> "properties": {  
> "keyword": {  
> "type": "keyword"  
> } } } } }

---

<div class="post-metadata">

### Author: ![guardhunt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guardhunt/32/21933_2.png) [@guardhunt](https://discuss.elastic.co/u/guardhunt)
#### Post date: [September 14, 2017, 2:55pm UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/8 "2017-09-14T14:55:48Z")

</div>

Try testing explicit mapping for both text (type: text) and text.keyword (type: keyword) and see the problem persists with aggregation. These are called [Multi-Fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-types.html#_multi_fields). You set one field with multiple types to allow for different use/search scenarios.

The longer value may not be able to be aggregated due to length, but it would need to be keyword type for aggregation to work.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 12, 2017, 2:56pm UTC](https://discuss.elastic.co/t/terms-aggregation-of-long-value/100223/9 "2017-10-12T14:56:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
