# Transforms - enabling filters as group\_by

**URL:** <https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218>\
**Category:** Elasticsearch\
**Created:** [June 23, 2020, 9:08am UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218 "2020-06-23T09:08:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [June 23, 2020, 9:08am UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218/1 "2020-06-23T09:08:07Z")

</div>

Right now options for grouping by in transforms are terms, histogram and date\_histogram.  
Is the plan adding [filters](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html) anytime soon?  
If not, I guess best option would be to create different transforms (one for each filter) for different indices, each pointing to a common alias?  
Thanks!

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [June 23, 2020, 7:12pm UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218/2 "2020-06-23T19:12:15Z")

</div>

No plans yet, the 1st step would be to add support to composite aggregations.

I wonder, do you have complicated filters in mind? Maybe you could achieve your usecase with a [scripted `group_by`](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script)?

Can you provide an example what you try to do?

---

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [June 25, 2020, 7:15am UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218/3 "2020-06-25T07:15:27Z")

</div>

Sure. I am grouping requests by user\_agent, but I'd like to reduce cardinality, since there are hundreds of different agents, into a shorter list like "iPhone", "Android", "Googlebot", "Desktop", etc. Separating using regex expressions.  
I don't understand how to use this scripted group\_by you mention 🤔

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [June 25, 2020, 8:00am UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218/4 "2020-06-25T08:00:28Z")

</div>

Here is an [example](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-painless-examples.html#painless-group-by) which works on user agents.

There is a problem however, script break continuous transform, see this [issue](https://github.com/elastic/elasticsearch/issues/57332). Currently transform allows you to use continuous, however it won't work correctly. Scripts are hard to handle, as I can not make any assumptions about the output.

If you want to do something like this in continuous mode, it's better to fix the data during ingest.

---

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [June 25, 2020, 8:19am UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218/5 "2020-06-25T08:19:52Z")

</div>

Yes... I do like solution B. Until then I guess I'll consider modifying ingest.  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2020, 8:19am UTC](https://discuss.elastic.co/t/transforms-enabling-filters-as-group-by/238218/6 "2020-07-23T08:19:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
