Reverse nested aggregation

Reverse nested aggregation

A special single bucket aggregation that enables aggregating on parent docs from nested documents. Effectively this aggregation can break out of the nested block structure and link to other nested structures or the root document, which allows nesting other aggregations that aren’t part of the nested object in a nested aggregation.

The reverse_nested aggregation must be defined inside a nested aggregation.

Options:

  • path - Which defines to what nested object field should be joined back. The default is empty, which means that it joins back to the root / main document level. The path cannot contain a reference to a nested object field that falls outside the nested aggregation’s nested structure a reverse_nested is in.

For example, lets say we have an index for a ticket system with issues and comments. The comments are inlined into the issue documents as nested documents. The mapping could look like:

  1. resp = client.indices.create(
  2. index="issues",
  3. mappings={
  4. "properties": {
  5. "tags": {
  6. "type": "keyword"
  7. },
  8. "comments": {
  9. "type": "nested",
  10. "properties": {
  11. "username": {
  12. "type": "keyword"
  13. },
  14. "comment": {
  15. "type": "text"
  16. }
  17. }
  18. }
  19. }
  20. },
  21. )
  22. print(resp)
  1. response = client.indices.create(
  2. index: 'issues',
  3. body: {
  4. mappings: {
  5. properties: {
  6. tags: {
  7. type: 'keyword'
  8. },
  9. comments: {
  10. type: 'nested',
  11. properties: {
  12. username: {
  13. type: 'keyword'
  14. },
  15. comment: {
  16. type: 'text'
  17. }
  18. }
  19. }
  20. }
  21. }
  22. }
  23. )
  24. puts response
  1. const response = await client.indices.create({
  2. index: "issues",
  3. mappings: {
  4. properties: {
  5. tags: {
  6. type: "keyword",
  7. },
  8. comments: {
  9. type: "nested",
  10. properties: {
  11. username: {
  12. type: "keyword",
  13. },
  14. comment: {
  15. type: "text",
  16. },
  17. },
  18. },
  19. },
  20. },
  21. });
  22. console.log(response);
  1. PUT /issues
  2. {
  3. "mappings": {
  4. "properties": {
  5. "tags": { "type": "keyword" },
  6. "comments": {
  7. "type": "nested",
  8. "properties": {
  9. "username": { "type": "keyword" },
  10. "comment": { "type": "text" }
  11. }
  12. }
  13. }
  14. }
  15. }

The comments is an array that holds nested documents under the issue object.

The following aggregations will return the top commenters’ username that have commented and per top commenter the top tags of the issues the user has commented on:

  1. resp = client.search(
  2. index="issues",
  3. query={
  4. "match_all": {}
  5. },
  6. aggs={
  7. "comments": {
  8. "nested": {
  9. "path": "comments"
  10. },
  11. "aggs": {
  12. "top_usernames": {
  13. "terms": {
  14. "field": "comments.username"
  15. },
  16. "aggs": {
  17. "comment_to_issue": {
  18. "reverse_nested": {},
  19. "aggs": {
  20. "top_tags_per_comment": {
  21. "terms": {
  22. "field": "tags"
  23. }
  24. }
  25. }
  26. }
  27. }
  28. }
  29. }
  30. }
  31. },
  32. )
  33. print(resp)
  1. response = client.search(
  2. index: 'issues',
  3. body: {
  4. query: {
  5. match_all: {}
  6. },
  7. aggregations: {
  8. comments: {
  9. nested: {
  10. path: 'comments'
  11. },
  12. aggregations: {
  13. top_usernames: {
  14. terms: {
  15. field: 'comments.username'
  16. },
  17. aggregations: {
  18. comment_to_issue: {
  19. reverse_nested: {},
  20. aggregations: {
  21. top_tags_per_comment: {
  22. terms: {
  23. field: 'tags'
  24. }
  25. }
  26. }
  27. }
  28. }
  29. }
  30. }
  31. }
  32. }
  33. }
  34. )
  35. puts response
  1. const response = await client.search({
  2. index: "issues",
  3. query: {
  4. match_all: {},
  5. },
  6. aggs: {
  7. comments: {
  8. nested: {
  9. path: "comments",
  10. },
  11. aggs: {
  12. top_usernames: {
  13. terms: {
  14. field: "comments.username",
  15. },
  16. aggs: {
  17. comment_to_issue: {
  18. reverse_nested: {},
  19. aggs: {
  20. top_tags_per_comment: {
  21. terms: {
  22. field: "tags",
  23. },
  24. },
  25. },
  26. },
  27. },
  28. },
  29. },
  30. },
  31. },
  32. });
  33. console.log(response);
  1. GET /issues/_search
  2. {
  3. "query": {
  4. "match_all": {}
  5. },
  6. "aggs": {
  7. "comments": {
  8. "nested": {
  9. "path": "comments"
  10. },
  11. "aggs": {
  12. "top_usernames": {
  13. "terms": {
  14. "field": "comments.username"
  15. },
  16. "aggs": {
  17. "comment_to_issue": {
  18. "reverse_nested": {},
  19. "aggs": {
  20. "top_tags_per_comment": {
  21. "terms": {
  22. "field": "tags"
  23. }
  24. }
  25. }
  26. }
  27. }
  28. }
  29. }
  30. }
  31. }
  32. }

As you can see above, the reverse_nested aggregation is put in to a nested aggregation as this is the only place in the dsl where the reverse_nested aggregation can be used. Its sole purpose is to join back to a parent doc higher up in the nested structure.

A reverse_nested aggregation that joins back to the root / main document level, because no path has been defined. Via the path option the reverse_nested aggregation can join back to a different level, if multiple layered nested object types have been defined in the mapping

Possible response snippet:

  1. {
  2. "aggregations": {
  3. "comments": {
  4. "doc_count": 1,
  5. "top_usernames": {
  6. "doc_count_error_upper_bound" : 0,
  7. "sum_other_doc_count" : 0,
  8. "buckets": [
  9. {
  10. "key": "username_1",
  11. "doc_count": 1,
  12. "comment_to_issue": {
  13. "doc_count": 1,
  14. "top_tags_per_comment": {
  15. "doc_count_error_upper_bound" : 0,
  16. "sum_other_doc_count" : 0,
  17. "buckets": [
  18. {
  19. "key": "tag_1",
  20. "doc_count": 1
  21. }
  22. ...
  23. ]
  24. }
  25. }
  26. }
  27. ...
  28. ]
  29. }
  30. }
  31. }
  32. }