# Unable to drop result bucket in terms aggregation

**URL:** <https://discuss.elastic.co/t/unable-to-drop-result-bucket-in-terms-aggregation/56314>\
**Category:** Elasticsearch\
**Created:** [July 25, 2016, 3:58pm UTC](https://discuss.elastic.co/t/unable-to-drop-result-bucket-in-terms-aggregation/56314 "2016-07-25T15:58:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![generogo](https://avatars.discourse-cdn.com/v4/letter/g/f05b48/32.png) [@generogo](https://discuss.elastic.co/u/generogo)\
**Post date:** [July 25, 2016, 3:58pm UTC](https://discuss.elastic.co/t/unable-to-drop-result-bucket-in-terms-aggregation/56314/1 "2016-07-25T15:58:12Z")

</div>

Hi,

I have documents in Elasticsearch with the following structure:

> "mappings": {  
> "document": {  
> "properties": {  
> "@timestamp": {  
> "type": "date",  
> "format": "strict\_date\_optional\_time||epoch\_millis"  
> },  
> "@version": {  
> "type": "string"  
> },  
> "id\_secuencia": {  
> "type": "long"  
> },  
> "event": {  
> "properties": {  
> "elapsedTime": {  
> "type": "double"  
> },  
> "requestTime": {  
> "type": "date",  
> "format": "strict\_date\_optional\_time||epoch\_millis"  
> },  
> "error": {  
> "properties": {  
> "errorCode": {  
> "type": "string",  
> "index": "not\_analyzed"  
> },  
> "failureDetail": {  
> "type": "string"  
> },  
> "fault": {  
> "type": "string"  
> }  
> }  
> },  
> "file": {  
> "type": "string",  
> "index": "not\_analyzed"  
> },  
> "messageId": {  
> "type": "string"  
> },  
> "request": {  
> "properties": {  
> "body": {  
> "type": "string"  
> },  
> "header": {  
> "type": "string"  
> }  
> }  
> },  
> "responseTime": {  
> "type": "date",  
> "format": "strict\_date\_optional\_time||epoch\_millis"  
> },  
> "service": {  
> "properties": {  
> "operation": {  
> "type": "string",  
> "index": "not\_analyzed"  
> },  
> "project": {  
> "type": "string",  
> "index": "not\_analyzed"  
> },  
> "proxy": {  
> "type": "string",  
> "index": "not\_analyzed"  
> },  
> "version": {  
> "type": "string",  
> "index": "not\_analyzed"  
> }  
> }  
> },  
> "timestamp": {  
> "type": "date",  
> "format": "strict\_date\_optional\_time||epoch\_millis"  
> },  
> "user": {  
> "type": "string",  
> "index": "not\_analyzed"  
> }  
> }  
> },  
> "type": {  
> "type": "string"  
> }  
> }  
> }  
> }

And I need to retrieve a list of unique values for the field " **event.file**" (to show in a Kibana Data Table) according to the following criteria:

- There is more than one document with the same value for the field "event.file"
- All the occurences for that value of "event.file" have resulted in error (field " **event.error.errorCode**" exists in all documents)

For that purpose the approach I've been testing is the use of **terms aggregation** , so I can get a list of buckets with all documents for a single file name. What I haven't been able to achieve is to drop some of the resulting buckets in the aggregation according to the previous criteria (if at least one of them does not have an error the bucket should be discarded).

Is this the correct approach or is there a better/easier way to get this type of result?

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![generogo](https://avatars.discourse-cdn.com/v4/letter/g/f05b48/32.png) [@generogo](https://discuss.elastic.co/u/generogo)\
**Post date:** [July 28, 2016, 7:08am UTC](https://discuss.elastic.co/t/unable-to-drop-result-bucket-in-terms-aggregation/56314/2 "2016-07-28T07:08:02Z")

</div>

After trying out several queries I found the following approach (see query below) to be valid for my purpose. The problem I see now is that apparently it is not possible to do this in Kibana, as it has no support for pipeline aggregations (see [https://github.com/elastic/kibana/issues/4584](https://github.com/elastic/kibana/issues/4584)).

```
{
  "query": {
    "bool": {
      "must": [
        {
          "filtered": {
            "filter": {
              "exists": {
                "field": "event.file"
              }
            }
          }
        }
      ]
    }
  },
  "size": 0,
  "aggs": {
    "file-events": {
      "terms": {
        "field": "event.file",
        "size": 0,
        "min_doc_count": 2
      },
      "aggs": {
        "files": {
          "filter": {
            "exists": {
              "field": "event.file"
            }
          },
          "aggs": {
            "totalFiles": {
              "value_count": {
                "field": "event.file"
              }
            }
          }
        },
        "errors": {
          "filter": {
            "exists": {
              "field": "event.error.errorCode"
            }
          },
          "aggs": {
            "totalErrors": {
              "value_count": {
                "field": "event.error.errorCode"
              }
            }
          }
        },
        "exhausted": {
          "bucket_selector": {
            "buckets_path": {
              "total_files":"files>totalFiles",
              "total_errors":"errors>totalErrors"
            },
            "script": "total_errors == total_files"
          }
        }
      }
    }
  }
}

```

Again, if I'm missing something, feedback will be appreciated 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:32pm UTC](https://discuss.elastic.co/t/unable-to-drop-result-bucket-in-terms-aggregation/56314/3 "2017-07-05T22:32:17Z")

</div>


