how to remove similar buckets of aggregation in elasticsearch





.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ height:90px;width:728px;box-sizing:border-box;
}







0















In the following aggregation, I want to extract top 10 unique URLs which indexed from nginx logs. I'm not sure about the aggregation's result. How can I achieve the below criteria:




  • collapse request_path field

  • return unique addresses

  • remove similar addresses like /rest/v3/users, /rest/v3/users/uuid and return parent resource in results


Query:



GET _search
{
"query": {
"bool": {
"must": {
"match_phrase": {
"request_path": "rest/v3"
}
}
}
},
"aggs": {
"top_hits": {
"terms": {
"field": "request_path.keyword",
"size": 100000,
"include": {
"partition": 1,
"num_partitions": 100
}
}
}
},
"size": 20
}


Expected Result:



[
{
"request_path": "/rest/v3/users",
"count": 100
},
{
"request_path": "/rest/v3/archives",
"count": 20
},
{
"request_path": "/rest/v3/payments",
"count": 85
}
...
]









share|improve this question




















  • 1





    You can refer to this answer stackoverflow.com/a/52942008/3838328 Let me know if it helps.

    – Kamal
    Nov 16 '18 at 17:15


















0















In the following aggregation, I want to extract top 10 unique URLs which indexed from nginx logs. I'm not sure about the aggregation's result. How can I achieve the below criteria:




  • collapse request_path field

  • return unique addresses

  • remove similar addresses like /rest/v3/users, /rest/v3/users/uuid and return parent resource in results


Query:



GET _search
{
"query": {
"bool": {
"must": {
"match_phrase": {
"request_path": "rest/v3"
}
}
}
},
"aggs": {
"top_hits": {
"terms": {
"field": "request_path.keyword",
"size": 100000,
"include": {
"partition": 1,
"num_partitions": 100
}
}
}
},
"size": 20
}


Expected Result:



[
{
"request_path": "/rest/v3/users",
"count": 100
},
{
"request_path": "/rest/v3/archives",
"count": 20
},
{
"request_path": "/rest/v3/payments",
"count": 85
}
...
]









share|improve this question




















  • 1





    You can refer to this answer stackoverflow.com/a/52942008/3838328 Let me know if it helps.

    – Kamal
    Nov 16 '18 at 17:15














0












0








0








In the following aggregation, I want to extract top 10 unique URLs which indexed from nginx logs. I'm not sure about the aggregation's result. How can I achieve the below criteria:




  • collapse request_path field

  • return unique addresses

  • remove similar addresses like /rest/v3/users, /rest/v3/users/uuid and return parent resource in results


Query:



GET _search
{
"query": {
"bool": {
"must": {
"match_phrase": {
"request_path": "rest/v3"
}
}
}
},
"aggs": {
"top_hits": {
"terms": {
"field": "request_path.keyword",
"size": 100000,
"include": {
"partition": 1,
"num_partitions": 100
}
}
}
},
"size": 20
}


Expected Result:



[
{
"request_path": "/rest/v3/users",
"count": 100
},
{
"request_path": "/rest/v3/archives",
"count": 20
},
{
"request_path": "/rest/v3/payments",
"count": 85
}
...
]









share|improve this question
















In the following aggregation, I want to extract top 10 unique URLs which indexed from nginx logs. I'm not sure about the aggregation's result. How can I achieve the below criteria:




  • collapse request_path field

  • return unique addresses

  • remove similar addresses like /rest/v3/users, /rest/v3/users/uuid and return parent resource in results


Query:



GET _search
{
"query": {
"bool": {
"must": {
"match_phrase": {
"request_path": "rest/v3"
}
}
}
},
"aggs": {
"top_hits": {
"terms": {
"field": "request_path.keyword",
"size": 100000,
"include": {
"partition": 1,
"num_partitions": 100
}
}
}
},
"size": 20
}


Expected Result:



[
{
"request_path": "/rest/v3/users",
"count": 100
},
{
"request_path": "/rest/v3/archives",
"count": 20
},
{
"request_path": "/rest/v3/payments",
"count": 85
}
...
]






elasticsearch






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Nov 16 '18 at 13:26







jesuismasoud

















asked Nov 16 '18 at 13:20









jesuismasoudjesuismasoud

432313




432313








  • 1





    You can refer to this answer stackoverflow.com/a/52942008/3838328 Let me know if it helps.

    – Kamal
    Nov 16 '18 at 17:15














  • 1





    You can refer to this answer stackoverflow.com/a/52942008/3838328 Let me know if it helps.

    – Kamal
    Nov 16 '18 at 17:15








1




1





You can refer to this answer stackoverflow.com/a/52942008/3838328 Let me know if it helps.

– Kamal
Nov 16 '18 at 17:15





You can refer to this answer stackoverflow.com/a/52942008/3838328 Let me know if it helps.

– Kamal
Nov 16 '18 at 17:15












0






active

oldest

votes












Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53338733%2fhow-to-remove-similar-buckets-of-aggregation-in-elasticsearch%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53338733%2fhow-to-remove-similar-buckets-of-aggregation-in-elasticsearch%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Bressuire

Vorschmack

Quarantine