# Terms Aggregations

**URL:** <https://discuss.elastic.co/t/terms-aggregations/17318>\
**Category:** Elasticsearch\
**Created:** [May 2, 2014, 9:44am UTC](https://discuss.elastic.co/t/terms-aggregations/17318 "2014-05-02T09:44:45Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_A\_Garcia](https://avatars.discourse-cdn.com/v4/letter/j/f19dbf/32.png) [@Jose\_A\_Garcia](https://discuss.elastic.co/u/Jose_A_Garcia)\
**Post date:** [May 2, 2014, 9:44am UTC](https://discuss.elastic.co/t/terms-aggregations/17318/1 "2014-05-02T09:44:45Z")

</div>

Hi,

I have a question about Aggregations. I have documents with several fields:

{  
field1 : A,  
field2: B,  
field3: C,  
size: 1,  
}

{  
field1 : A,  
field2: B2,  
field3: C2,  
size: 2,  
}

{  
field1 : Z,  
field2: B3,  
field3: C3,  
size: 99,  
}

And I need to be able to calculate aggregations for each one of those  
fields, and get the sum of the sizes for each field, so for example,  
aggregating by field1 should get me { A, size = 3 }, {Z, size = 99}.

Looking at the documentation for aggregations I can see how to get the sum  
for a field and how to get the terms and their counts, but I need a  
combination of both, what is the best way to do this?

Thanks in advance,  
Jose.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 2, 2014, 1:51pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/2 "2014-05-02T13:51:36Z")

</div>

Hi Jose,

There are two ways to do so: either with a script (slow because term  
ordinals can't be used):

"terms" : {  
"script": "doc['A'].values + doc['B'].values + doc['C'].values"  
}

Or by having all values in a single field at indexing time (potentially  
using `copy_to`[1]).

[1]

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On Fri, May 2, 2014 at 11:44 AM, Jose A. Garcia [argantonio@gmail.com](mailto:argantonio@gmail.com)wrote:

> Hi,
> 
> I have a question about Aggregations. I have documents with several fields:
> 
> {  
> field1 : A,  
> field2: B,  
> field3: C,  
> size: 1,  
> }
> 
> {  
> field1 : A,  
> field2: B2,  
> field3: C2,  
> size: 2,  
> }
> 
> {  
> field1 : Z,  
> field2: B3,  
> field3: C3,  
> size: 99,  
> }
> 
> And I need to be able to calculate aggregations for each one of those  
> fields, and get the sum of the sizes for each field, so for example,  
> aggregating by field1 should get me { A, size = 3 }, {Z, size = 99}.
> 
> Looking at the documentation for aggregations I can see how to get the sum  
> for a field and how to get the terms and their counts, but I need a  
> combination of both, what is the best way to do this?
> 
> Thanks in advance,  
> Jose.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j6ECS%2B0t8%2BZSVTj64CpNqrhmE5gfWcS5F0qvw%2BHQLPRcA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j6ECS%2B0t8%2BZSVTj64CpNqrhmE5gfWcS5F0qvw%2BHQLPRcA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jose\_A\_Garcia](https://avatars.discourse-cdn.com/v4/letter/j/f19dbf/32.png) [@Jose\_A\_Garcia](https://discuss.elastic.co/u/Jose_A_Garcia)\
**Post date:** [May 2, 2014, 2:08pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/3 "2014-05-02T14:08:18Z")

</div>

Hi Adrien,

Thanks for your answer, but I have a question. Wouldn't that give me the  
different sums of the values of those fields?

What I need is, using the example from before:

Doc1 : { field1 : A, field2: B, field3: C, size: 1, }  
Doc2: { field1 : A, field2: B2, field3: C2, size: 2}  
Doc3: { field1 : Z, field2: B3, field3: C3, size: 99 }

If I search in my index and those three documents match my query I want a  
list of the possible values that 'field1' can take and the sum of the  
'size' fields for all documents with each value in my result set. So in  
this case I would expect:

field1: {  
{value: 'A', sum\_of\_sizes: 3}  
{value: 'Z', sum\_of\_sizes: 99}  
}

Thanks,  
Jose.

On Friday, 2 May 2014 14:51:36 UTC+1, Adrien Grand wrote:

> Hi Jose,
> 
> There are two ways to do so: either with a script (slow because term  
> ordinals can't be used):
> 
> "terms" : {  
> "script": "doc['A'].values + doc['B'].values + doc['C'].values"  
> }
> 
> Or by having all values in a single field at indexing time (potentially  
> using `copy_to`[1]).
> 
> [1]  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-core-types.html#copy-to)
> 
> On Fri, May 2, 2014 at 11:44 AM, Jose A. Garcia \<[argan...@gmail.com](mailto:argan...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > Hi,
> > 
> > I have a question about Aggregations. I have documents with several  
> > fields:
> > 
> > {  
> > field1 : A,  
> > field2: B,  
> > field3: C,  
> > size: 1,  
> > }
> > 
> > {  
> > field1 : A,  
> > field2: B2,  
> > field3: C2,  
> > size: 2,  
> > }
> > 
> > {  
> > field1 : Z,  
> > field2: B3,  
> > field3: C3,  
> > size: 99,  
> > }
> > 
> > And I need to be able to calculate aggregations for each one of those  
> > fields, and get the sum of the sizes for each field, so for example,  
> > aggregating by field1 should get me { A, size = 3 }, {Z, size = 99}.
> > 
> > Looking at the documentation for aggregations I can see how to get the  
> > sum for a field and how to get the terms and their counts, but I need a  
> > combination of both, what is the best way to do this?
> > 
> > Thanks in advance,  
> > Jose.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 2, 2014, 2:18pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/4 "2014-05-02T14:18:37Z")

</div>

Oh, I'm sorry, I completely missed your question, I thought you wanted to  
merge the counts for different fields.

Would this aggregation do what you are looking for?  
{  
"terms": {  
"field": "fieldA"  
},  
"aggs": {  
"size\_sum": {  
"sum": {  
"field": "size"  
}  
}  
}  
}

See

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

the documentation of the sum aggregation. I hope I got your question  
right this time!

On Fri, May 2, 2014 at 4:08 PM, Jose A. Garcia [argantonio@gmail.com](mailto:argantonio@gmail.com) wrote:

> Hi Adrien,
> 
> Thanks for your answer, but I have a question. Wouldn't that give me the  
> different sums of the values of those fields?
> 
> What I need is, using the example from before:
> 
> Doc1 : { field1 : A, field2: B, field3: C, size: 1, }  
> Doc2: { field1 : A, field2: B2, field3: C2, size: 2}  
> Doc3: { field1 : Z, field2: B3, field3: C3, size: 99 }
> 
> If I search in my index and those three documents match my query I want a  
> list of the possible values that 'field1' can take and the sum of the  
> 'size' fields for all documents with each value in my result set. So in  
> this case I would expect:
> 
> field1: {  
> {value: 'A', sum\_of\_sizes: 3}  
> {value: 'Z', sum\_of\_sizes: 99}  
> }
> 
> Thanks,  
> Jose.
> 
> On Friday, 2 May 2014 14:51:36 UTC+1, Adrien Grand wrote:
> 
> > Hi Jose,
> > 
> > There are two ways to do so: either with a script (slow because term  
> > ordinals can't be used):
> > 
> > "terms" : {  
> > "script": "doc['A'].values + doc['B'].values + doc['C'].values"  
> > }
> > 
> > Or by having all values in a single field at indexing time (potentially  
> > using `copy_to`[1]).
> > 
> > [1] [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/)  
> > reference/current/mapping-core-types.html#copy-to
> > 
> > On Fri, May 2, 2014 at 11:44 AM, Jose A. Garcia [argan...@gmail.com](mailto:argan...@gmail.com)wrote:
> > 
> > > Hi,
> > > 
> > > I have a question about Aggregations. I have documents with several  
> > > fields:
> > > 
> > > {  
> > > field1 : A,  
> > > field2: B,  
> > > field3: C,  
> > > size: 1,  
> > > }
> > > 
> > > {  
> > > field1 : A,  
> > > field2: B2,  
> > > field3: C2,  
> > > size: 2,  
> > > }
> > > 
> > > {  
> > > field1 : Z,  
> > > field2: B3,  
> > > field3: C3,  
> > > size: 99,  
> > > }
> > > 
> > > And I need to be able to calculate aggregations for each one of those  
> > > fields, and get the sum of the sizes for each field, so for example,  
> > > aggregating by field1 should get me { A, size = 3 }, {Z, size = 99}.
> > > 
> > > Looking at the documentation for aggregations I can see how to get the  
> > > sum for a field and how to get the terms and their counts, but I need a  
> > > combination of both, what is the best way to do this?
> > > 
> > > Thanks in advance,  
> > > Jose.
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%  
> > > [40googlegroups.com](http://40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > Adrien Grand
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j44%2Ba\_JXWzWLWwNkHxy0%3DaGiyaWmXgy-JmxPY3h2nmQ%2Bw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j44%2Ba_JXWzWLWwNkHxy0%3DaGiyaWmXgy-JmxPY3h2nmQ%2Bw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jose\_A\_Garcia](https://avatars.discourse-cdn.com/v4/letter/j/f19dbf/32.png) [@Jose\_A\_Garcia](https://discuss.elastic.co/u/Jose_A_Garcia)\
**Post date:** [May 2, 2014, 2:47pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/5 "2014-05-02T14:47:46Z")

</div>

Hi,

That's closer but I would get all the possible values and counts for  
'fieldA' and the total sum of 'size' for my result set, but I need the sum  
of sizes for each value of 'fieldA', so it's a combination of both terms  
and sum, but none seems to give me exactly what I need...

Thanks,  
Jose.

On Friday, 2 May 2014 15:18:37 UTC+1, Adrien Grand wrote:

> Oh, I'm sorry, I completely missed your question, I thought you wanted to  
> merge the counts for different fields.
> 
> Would this aggregation do what you are looking for?  
> {  
> "terms": {  
> "field": "fieldA"  
> },  
> "aggs": {  
> "size\_sum": {  
> "sum": {  
> "field": "size"  
> }  
> }  
> }  
> }
> 
> See  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/search-aggregations-metrics-sum-aggregation.htmlfor) the documentation of the sum aggregation. I hope I got your question  
> right this time!
> 
> On Fri, May 2, 2014 at 4:08 PM, Jose A. Garcia \<[argan...@gmail.com](mailto:argan...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > Hi Adrien,
> > 
> > Thanks for your answer, but I have a question. Wouldn't that give me the  
> > different sums of the values of those fields?
> > 
> > What I need is, using the example from before:
> > 
> > Doc1 : { field1 : A, field2: B, field3: C, size: 1, }  
> > Doc2: { field1 : A, field2: B2, field3: C2, size: 2}  
> > Doc3: { field1 : Z, field2: B3, field3: C3, size: 99 }
> > 
> > If I search in my index and those three documents match my query I want a  
> > list of the possible values that 'field1' can take and the sum of the  
> > 'size' fields for all documents with each value in my result set. So in  
> > this case I would expect:
> > 
> > field1: {  
> > {value: 'A', sum\_of\_sizes: 3}  
> > {value: 'Z', sum\_of\_sizes: 99}  
> > }
> > 
> > Thanks,  
> > Jose.
> > 
> > On Friday, 2 May 2014 14:51:36 UTC+1, Adrien Grand wrote:
> > 
> > > Hi Jose,
> > > 
> > > There are two ways to do so: either with a script (slow because term  
> > > ordinals can't be used):
> > > 
> > > "terms" : {  
> > > "script": "doc['A'].values + doc['B'].values + doc['C'].values"  
> > > }
> > > 
> > > Or by having all values in a single field at indexing time (potentially  
> > > using `copy_to`[1]).
> > > 
> > > [1] [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/)  
> > > reference/current/mapping-core-types.html#copy-to
> > > 
> > > On Fri, May 2, 2014 at 11:44 AM, Jose A. Garcia [argan...@gmail.com](mailto:argan...@gmail.com)wrote:
> > > 
> > > > Hi,
> > > > 
> > > > I have a question about Aggregations. I have documents with several  
> > > > fields:
> > > > 
> > > > {  
> > > > field1 : A,  
> > > > field2: B,  
> > > > field3: C,  
> > > > size: 1,  
> > > > }
> > > > 
> > > > {  
> > > > field1 : A,  
> > > > field2: B2,  
> > > > field3: C2,  
> > > > size: 2,  
> > > > }
> > > > 
> > > > {  
> > > > field1 : Z,  
> > > > field2: B3,  
> > > > field3: C3,  
> > > > size: 99,  
> > > > }
> > > > 
> > > > And I need to be able to calculate aggregations for each one of those  
> > > > fields, and get the sum of the sizes for each field, so for example,  
> > > > aggregating by field1 should get me { A, size = 3 }, {Z, size = 99}.
> > > > 
> > > > Looking at the documentation for aggregations I can see how to get the  
> > > > sum for a field and how to get the terms and their counts, but I need a  
> > > > combination of both, what is the best way to do this?
> > > > 
> > > > Thanks in advance,  
> > > > Jose.
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > 
> > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > > msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%  
> > > > [40googlegroups.com](http://40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1deb1eb1-a5dc-40cb-8689-c5518869f40a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > --  
> > > Adrien Grand
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ec381c10-45cd-4406-8aac-2e542097cf49%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/146e90a8-48de-4bad-b5ce-6685ea4563ca%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/146e90a8-48de-4bad-b5ce-6685ea4563ca%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 2, 2014, 2:55pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/6 "2014-05-02T14:55:50Z")

</div>

On Fri, May 2, 2014 at 4:47 PM, Jose A. Garcia [argantonio@gmail.com](mailto:argantonio@gmail.com) wrote:

> That's closer but I would get all the possible values and counts for  
> 'fieldA' and the total sum of 'size' for my result set, but I need the sum  
> of sizes for each value of 'fieldA', so it's a combination of both terms  
> and sum, but none seems to give me exactly what I need...

This should work: The sum aggregation is _under_ the terms aggregation, so  
sums would be computed for each unique value of 'fieldA'.

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j4exmQ2AfYy\_bPQkuVWoEHqJA\_5D%3DvAw9O7Si5zaakzRA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j4exmQ2AfYy_bPQkuVWoEHqJA_5D%3DvAw9O7Si5zaakzRA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jose\_A\_Garcia](https://avatars.discourse-cdn.com/v4/letter/j/f19dbf/32.png) [@Jose\_A\_Garcia](https://discuss.elastic.co/u/Jose_A_Garcia)\
**Post date:** [May 2, 2014, 3:22pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/7 "2014-05-02T15:22:30Z")

</div>

Sorry, I think I must be misunderstanding something, if I do:

GET /summary/row/\_search  
{  
"query": {  
"match": {  
"field3": 1  
}  
},  
"aggs": {  
"terms": {  
"field": "field1"  
},  
"field1\_count": {  
"sum": {  
"field": "count"  
}  
}  
}  
}

I just get this in the response:

"aggregations": {  
"file1\_count": {  
"value": 75000  
}  
}

It's just ignoring all the values of 'file1' and adding all the sizes from  
the response. Am I doing something wrong?

Thanks,  
Jose.

On Friday, 2 May 2014 15:55:50 UTC+1, Adrien Grand wrote:

> On Fri, May 2, 2014 at 4:47 PM, Jose A. Garcia \<[argan...@gmail.com](mailto:argan...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > That's closer but I would get all the possible values and counts for  
> > 'fieldA' and the total sum of 'size' for my result set, but I need the sum  
> > of sizes for each value of 'fieldA', so it's a combination of both terms  
> > and sum, but none seems to give me exactly what I need...
> 
> This should work: The sum aggregation is _under_ the terms aggregation, so  
> sums would be computed for each unique value of 'fieldA'.
> 
> --  
> Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 2, 2014, 3:28pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/8 "2014-05-02T15:28:08Z")

</div>

Your aggregation has no name, and unfortunately this causes undefined  
behavior because the parsing is too lenient in 1.1 and previous versions  
(will be fixed in 1.2.0). Please try the following request:

GET /summary/row/\_search  
{  
"query": {  
"match": {  
"field3": 1  
}  
},  
"aggs": {  
"field1\_top\_terms": {  
"terms": {  
"field": "field1"  
},  
"field1\_count": {  
"sum": {  
"field": "count"  
}  
}  
}  
}  
}

On Fri, May 2, 2014 at 5:22 PM, Jose A. Garcia [argantonio@gmail.com](mailto:argantonio@gmail.com) wrote:

> Sorry, I think I must be misunderstanding something, if I do:
> 
> GET /summary/row/\_search  
> {  
> "query": {  
> "match": {  
> "field3": 1  
> }  
> },  
> "aggs": {  
> "terms": {  
> "field": "field1"  
> },  
> "field1\_count": {  
> "sum": {  
> "field": "count"  
> }  
> }  
> }  
> }
> 
> I just get this in the response:
> 
> "aggregations": {  
> "file1\_count": {  
> "value": 75000  
> }  
> }
> 
> It's just ignoring all the values of 'file1' and adding all the sizes from  
> the response. Am I doing something wrong?
> 
> Thanks,  
> Jose.
> 
> On Friday, 2 May 2014 15:55:50 UTC+1, Adrien Grand wrote:
> 
> > On Fri, May 2, 2014 at 4:47 PM, Jose A. Garcia [argan...@gmail.com](mailto:argan...@gmail.com)wrote:
> > 
> > > That's closer but I would get all the possible values and counts for  
> > > 'fieldA' and the total sum of 'size' for my result set, but I need the sum  
> > > of sizes for each value of 'fieldA', so it's a combination of both terms  
> > > and sum, but none seems to give me exactly what I need...
> > 
> > This should work: The sum aggregation is _under_ the terms aggregation,  
> > so sums would be computed for each unique value of 'fieldA'.
> > 
> > --  
> > Adrien Grand
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j5R\_aTb7i%2Buz0GfystfHOxdhApU3Y6gB55eTNGBXzLAkg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j5R_aTb7i%2Buz0GfystfHOxdhApU3Y6gB55eTNGBXzLAkg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jose\_A\_Garcia](https://avatars.discourse-cdn.com/v4/letter/j/f19dbf/32.png) [@Jose\_A\_Garcia](https://discuss.elastic.co/u/Jose_A_Garcia)\
**Post date:** [May 2, 2014, 3:40pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/9 "2014-05-02T15:40:54Z")

</div>

Sorry to keep on with this, but if I do that I get an error:

Parse Failure [Found two aggregation type definitions in  
[field1\_top\_terms]: [terms] and [field1\_count]. Only one type is allowed.]

If I take the 'field1\_count' from inside 'field1\_top\_terms' like this:

GET /summary/row/\_search  
{  
"query": {  
"match": {  
"file3": 1  
}  
},  
"aggs": {  
"field1\_top\_terms": {  
"terms": {  
"field": "field1"  
}  
},  
"field1\_count": {  
"sum": {  
"field": "count"  
}  
}  
}  
}

I get the two independent aggregations.

Thanks again for you patience...  
Jose.

On Friday, 2 May 2014 16:28:08 UTC+1, Adrien Grand wrote:

> Your aggregation has no name, and unfortunately this causes undefined  
> behavior because the parsing is too lenient in 1.1 and previous versions  
> (will be fixed in 1.2.0). Please try the following request:
> 
> GET /summary/row/\_search  
> {  
> "query": {  
> "match": {  
> "field3": 1  
> }  
> },  
> "aggs": {  
> "field1\_top\_terms": {  
> "terms": {  
> "field": "field1"  
> },  
> "field1\_count": {  
> "sum": {  
> "field": "count"  
> }  
> }  
> }  
> }  
> }
> 
> On Fri, May 2, 2014 at 5:22 PM, Jose A. Garcia \<[argan...@gmail.com](mailto:argan...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > Sorry, I think I must be misunderstanding something, if I do:
> > 
> > GET /summary/row/\_search  
> > {  
> > "query": {  
> > "match": {  
> > "field3": 1  
> > }  
> > },  
> > "aggs": {  
> > "terms": {  
> > "field": "field1"  
> > },  
> > "field1\_count": {  
> > "sum": {  
> > "field": "count"  
> > }  
> > }  
> > }  
> > }
> > 
> > I just get this in the response:
> > 
> > "aggregations": {  
> > "file1\_count": {  
> > "value": 75000  
> > }  
> > }
> > 
> > It's just ignoring all the values of 'file1' and adding all the sizes  
> > from the response. Am I doing something wrong?
> > 
> > Thanks,  
> > Jose.
> > 
> > On Friday, 2 May 2014 15:55:50 UTC+1, Adrien Grand wrote:
> > 
> > > On Fri, May 2, 2014 at 4:47 PM, Jose A. Garcia [argan...@gmail.com](mailto:argan...@gmail.com)wrote:
> > > 
> > > > That's closer but I would get all the possible values and counts for  
> > > > 'fieldA' and the total sum of 'size' for my result set, but I need the sum  
> > > > of sizes for each value of 'fieldA', so it's a combination of both terms  
> > > > and sum, but none seems to give me exactly what I need...
> > > 
> > > This should work: The sum aggregation is _under_ the terms aggregation,  
> > > so sums would be computed for each unique value of 'fieldA'.
> > > 
> > > --  
> > > Adrien Grand
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3e7e30bd-2482-4c99-9643-679adef5610d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/2d1225aa-827a-4ae7-8f39-0edd0f8b7f18%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/2d1225aa-827a-4ae7-8f39-0edd0f8b7f18%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 2, 2014, 3:47pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/10 "2014-05-02T15:47:12Z")

</div>

On Fri, May 2, 2014 at 5:40 PM, Jose A. Garcia [argantonio@gmail.com](mailto:argantonio@gmail.com) wrote:

> Sorry to keep on with this, but if I do that I get an error:
> 
> Parse Failure [Found two aggregation type definitions in  
> [field1\_top\_terms]: [terms] and [field1\_count]. Only one type is allowed.]

Oops, I fixed the outer aggregation, but not the inner one. This time I  
tested the request to it should work (hopefully :)).

GET /summary/row/\_search  
{  
"query": {  
"match": {  
"field3": 1  
}  
},  
"aggs": {  
"field1\_top\_terms": {  
"terms": {  
"field": "field1"  
},  
"aggs": {  
"field1\_count": {  
"sum": {  
"field": "count"  
}  
}  
}  
}  
}  
}

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j7L1d%2BnUGZiYcfk2\_MbYXZN0pv4KK1VCWzpZ%2BwXp0S0zQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j7L1d%2BnUGZiYcfk2_MbYXZN0pv4KK1VCWzpZ%2BwXp0S0zQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jose\_A\_Garcia](https://avatars.discourse-cdn.com/v4/letter/j/f19dbf/32.png) [@Jose\_A\_Garcia](https://discuss.elastic.co/u/Jose_A_Garcia)\
**Post date:** [May 2, 2014, 3:56pm UTC](https://discuss.elastic.co/t/terms-aggregations/17318/11 "2014-05-02T15:56:38Z")

</div>

This time it works perfectly and it does exactly what I need.

Thanks a lot!  
Jose.

On Friday, 2 May 2014 16:47:12 UTC+1, Adrien Grand wrote:

> On Fri, May 2, 2014 at 5:40 PM, Jose A. Garcia \<[argan...@gmail.com](mailto:argan...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > Sorry to keep on with this, but if I do that I get an error:
> > 
> > Parse Failure [Found two aggregation type definitions in  
> > [field1\_top\_terms]: [terms] and [field1\_count]. Only one type is  
> > allowed.]
> 
> Oops, I fixed the outer aggregation, but not the inner one. This time I  
> tested the request to it should work (hopefully :)).
> 
> GET /summary/row/\_search  
> {  
> "query": {  
> "match": {  
> "field3": 1  
> }  
> },  
> "aggs": {  
> "field1\_top\_terms": {  
> "terms": {  
> "field": "field1"  
> },  
> "aggs": {  
> "field1\_count": {  
> "sum": {  
> "field": "count"  
> }  
> }  
> }  
> }  
> }  
> }
> 
> --  
> Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4528c39b-3b2f-46cc-bb71-63f01d1c837b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4528c39b-3b2f-46cc-bb71-63f01d1c837b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:32am UTC](https://discuss.elastic.co/t/terms-aggregations/17318/12 "2017-07-06T01:32:04Z")

</div>


