1
0

tophits-aggregation.asciidoc 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409
  1. [[search-aggregations-metrics-top-hits-aggregation]]
  2. === Top Hits Aggregation
  3. A `top_hits` metric aggregator keeps track of the most relevant document being aggregated. This aggregator is intended
  4. to be used as a sub aggregator, so that the top matching documents can be aggregated per bucket.
  5. The `top_hits` aggregator can effectively be used to group result sets by certain fields via a bucket aggregator.
  6. One or more bucket aggregators determines by which properties a result set get sliced into.
  7. ==== Options
  8. * `from` - The offset from the first result you want to fetch.
  9. * `size` - The maximum number of top matching hits to return per bucket. By default the top three matching hits are returned.
  10. * `sort` - How the top matching hits should be sorted. By default the hits are sorted by the score of the main query.
  11. ==== Supported per hit features
  12. The top_hits aggregation returns regular search hits, because of this many per hit features can be supported:
  13. * <<search-request-highlighting,Highlighting>>
  14. * <<search-request-explain,Explain>>
  15. * <<search-request-named-queries-and-filters,Named filters and queries>>
  16. * <<search-request-source-filtering,Source filtering>>
  17. * <<search-request-stored-fields,Stored fields>>
  18. * <<search-request-script-fields,Script fields>>
  19. * <<search-request-docvalue-fields,Doc value fields>>
  20. * <<search-request-version,Include versions>>
  21. * <<search-request-seq-no-primary-term,Include Sequence Numbers and Primary Terms>>
  22. ==== Example
  23. In the following example we group the sales by type and per type we show the last sale.
  24. For each sale only the date and price fields are being included in the source.
  25. [source,js]
  26. --------------------------------------------------
  27. POST /sales/_search?size=0
  28. {
  29. "aggs": {
  30. "top_tags": {
  31. "terms": {
  32. "field": "type",
  33. "size": 3
  34. },
  35. "aggs": {
  36. "top_sales_hits": {
  37. "top_hits": {
  38. "sort": [
  39. {
  40. "date": {
  41. "order": "desc"
  42. }
  43. }
  44. ],
  45. "_source": {
  46. "includes": [ "date", "price" ]
  47. },
  48. "size" : 1
  49. }
  50. }
  51. }
  52. }
  53. }
  54. }
  55. --------------------------------------------------
  56. // CONSOLE
  57. // TEST[setup:sales]
  58. Possible response:
  59. [source,js]
  60. --------------------------------------------------
  61. {
  62. ...
  63. "aggregations": {
  64. "top_tags": {
  65. "doc_count_error_upper_bound": 0,
  66. "sum_other_doc_count": 0,
  67. "buckets": [
  68. {
  69. "key": "hat",
  70. "doc_count": 3,
  71. "top_sales_hits": {
  72. "hits": {
  73. "total" : {
  74. "value": 3,
  75. "relation": "eq"
  76. },
  77. "max_score": null,
  78. "hits": [
  79. {
  80. "_index": "sales",
  81. "_type": "_doc",
  82. "_id": "AVnNBmauCQpcRyxw6ChK",
  83. "_source": {
  84. "date": "2015/03/01 00:00:00",
  85. "price": 200
  86. },
  87. "sort": [
  88. 1425168000000
  89. ],
  90. "_score": null
  91. }
  92. ]
  93. }
  94. }
  95. },
  96. {
  97. "key": "t-shirt",
  98. "doc_count": 3,
  99. "top_sales_hits": {
  100. "hits": {
  101. "total" : {
  102. "value": 3,
  103. "relation": "eq"
  104. },
  105. "max_score": null,
  106. "hits": [
  107. {
  108. "_index": "sales",
  109. "_type": "_doc",
  110. "_id": "AVnNBmauCQpcRyxw6ChL",
  111. "_source": {
  112. "date": "2015/03/01 00:00:00",
  113. "price": 175
  114. },
  115. "sort": [
  116. 1425168000000
  117. ],
  118. "_score": null
  119. }
  120. ]
  121. }
  122. }
  123. },
  124. {
  125. "key": "bag",
  126. "doc_count": 1,
  127. "top_sales_hits": {
  128. "hits": {
  129. "total" : {
  130. "value": 1,
  131. "relation": "eq"
  132. },
  133. "max_score": null,
  134. "hits": [
  135. {
  136. "_index": "sales",
  137. "_type": "_doc",
  138. "_id": "AVnNBmatCQpcRyxw6ChH",
  139. "_source": {
  140. "date": "2015/01/01 00:00:00",
  141. "price": 150
  142. },
  143. "sort": [
  144. 1420070400000
  145. ],
  146. "_score": null
  147. }
  148. ]
  149. }
  150. }
  151. }
  152. ]
  153. }
  154. }
  155. }
  156. --------------------------------------------------
  157. // TESTRESPONSE[s/\.\.\./"took": $body.took,"timed_out": false,"_shards": $body._shards,"hits": $body.hits,/]
  158. // TESTRESPONSE[s/AVnNBmauCQpcRyxw6ChK/$body.aggregations.top_tags.buckets.0.top_sales_hits.hits.hits.0._id/]
  159. // TESTRESPONSE[s/AVnNBmauCQpcRyxw6ChL/$body.aggregations.top_tags.buckets.1.top_sales_hits.hits.hits.0._id/]
  160. // TESTRESPONSE[s/AVnNBmatCQpcRyxw6ChH/$body.aggregations.top_tags.buckets.2.top_sales_hits.hits.hits.0._id/]
  161. ==== Field collapse example
  162. Field collapsing or result grouping is a feature that logically groups a result set into groups and per group returns
  163. top documents. The ordering of the groups is determined by the relevancy of the first document in a group. In
  164. Elasticsearch this can be implemented via a bucket aggregator that wraps a `top_hits` aggregator as sub-aggregator.
  165. In the example below we search across crawled webpages. For each webpage we store the body and the domain the webpage
  166. belong to. By defining a `terms` aggregator on the `domain` field we group the result set of webpages by domain. The
  167. `top_hits` aggregator is then defined as sub-aggregator, so that the top matching hits are collected per bucket.
  168. Also a `max` aggregator is defined which is used by the `terms` aggregator's order feature to return the buckets by
  169. relevancy order of the most relevant document in a bucket.
  170. [source,js]
  171. --------------------------------------------------
  172. POST /sales/_search
  173. {
  174. "query": {
  175. "match": {
  176. "body": "elections"
  177. }
  178. },
  179. "aggs": {
  180. "top_sites": {
  181. "terms": {
  182. "field": "domain",
  183. "order": {
  184. "top_hit": "desc"
  185. }
  186. },
  187. "aggs": {
  188. "top_tags_hits": {
  189. "top_hits": {}
  190. },
  191. "top_hit" : {
  192. "max": {
  193. "script": {
  194. "source": "_score"
  195. }
  196. }
  197. }
  198. }
  199. }
  200. }
  201. }
  202. --------------------------------------------------
  203. // CONSOLE
  204. // TEST[setup:sales]
  205. At the moment the `max` (or `min`) aggregator is needed to make sure the buckets from the `terms` aggregator are
  206. ordered according to the score of the most relevant webpage per domain. Unfortunately the `top_hits` aggregator
  207. can't be used in the `order` option of the `terms` aggregator yet.
  208. ==== top_hits support in a nested or reverse_nested aggregator
  209. If the `top_hits` aggregator is wrapped in a `nested` or `reverse_nested` aggregator then nested hits are being returned.
  210. Nested hits are in a sense hidden mini documents that are part of regular document where in the mapping a nested field type
  211. has been configured. The `top_hits` aggregator has the ability to un-hide these documents if it is wrapped in a `nested`
  212. or `reverse_nested` aggregator. Read more about nested in the <<nested,nested type mapping>>.
  213. If nested type has been configured a single document is actually indexed as multiple Lucene documents and they share
  214. the same id. In order to determine the identity of a nested hit there is more needed than just the id, so that is why
  215. nested hits also include their nested identity. The nested identity is kept under the `_nested` field in the search hit
  216. and includes the array field and the offset in the array field the nested hit belongs to. The offset is zero based.
  217. Let's see how it works with a real sample. Considering the following mapping:
  218. [source,js]
  219. --------------------------------------------------
  220. PUT /sales
  221. {
  222. "mappings": {
  223. "properties" : {
  224. "tags" : { "type" : "keyword" },
  225. "comments" : { <1>
  226. "type" : "nested",
  227. "properties" : {
  228. "username" : { "type" : "keyword" },
  229. "comment" : { "type" : "text" }
  230. }
  231. }
  232. }
  233. }
  234. }
  235. --------------------------------------------------
  236. // CONSOLE
  237. <1> The `comments` is an array that holds nested documents under the `product` object.
  238. And some documents:
  239. [source,js]
  240. --------------------------------------------------
  241. PUT /sales/_doc/1?refresh
  242. {
  243. "tags": ["car", "auto"],
  244. "comments": [
  245. {"username": "baddriver007", "comment": "This car could have better brakes"},
  246. {"username": "dr_who", "comment": "Where's the autopilot? Can't find it"},
  247. {"username": "ilovemotorbikes", "comment": "This car has two extra wheels"}
  248. ]
  249. }
  250. --------------------------------------------------
  251. // CONSOLE
  252. // TEST[continued]
  253. It's now possible to execute the following `top_hits` aggregation (wrapped in a `nested` aggregation):
  254. [source,js]
  255. --------------------------------------------------
  256. POST /sales/_search
  257. {
  258. "query": {
  259. "term": { "tags": "car" }
  260. },
  261. "aggs": {
  262. "by_sale": {
  263. "nested" : {
  264. "path" : "comments"
  265. },
  266. "aggs": {
  267. "by_user": {
  268. "terms": {
  269. "field": "comments.username",
  270. "size": 1
  271. },
  272. "aggs": {
  273. "by_nested": {
  274. "top_hits":{}
  275. }
  276. }
  277. }
  278. }
  279. }
  280. }
  281. }
  282. --------------------------------------------------
  283. // CONSOLE
  284. // TEST[continued]
  285. // TEST[s/_search/_search\?filter_path=aggregations.by_sale.by_user.buckets/]
  286. Top hits response snippet with a nested hit, which resides in the first slot of array field `comments`:
  287. [source,js]
  288. --------------------------------------------------
  289. {
  290. ...
  291. "aggregations": {
  292. "by_sale": {
  293. "by_user": {
  294. "buckets": [
  295. {
  296. "key": "baddriver007",
  297. "doc_count": 1,
  298. "by_nested": {
  299. "hits": {
  300. "total" : {
  301. "value": 1,
  302. "relation": "eq"
  303. },
  304. "max_score": 0.3616575,
  305. "hits": [
  306. {
  307. "_index": "sales",
  308. "_type" : "_doc",
  309. "_id": "1",
  310. "_nested": {
  311. "field": "comments", <1>
  312. "offset": 0 <2>
  313. },
  314. "_score": 0.3616575,
  315. "_source": {
  316. "comment": "This car could have better brakes", <3>
  317. "username": "baddriver007"
  318. }
  319. }
  320. ]
  321. }
  322. }
  323. }
  324. ...
  325. ]
  326. }
  327. }
  328. }
  329. }
  330. --------------------------------------------------
  331. // TESTRESPONSE[s/\.\.\.//]
  332. <1> Name of the array field containing the nested hit
  333. <2> Position if the nested hit in the containing array
  334. <3> Source of the nested hit
  335. If `_source` is requested then just the part of the source of the nested object is returned, not the entire source of the document.
  336. Also stored fields on the *nested* inner object level are accessible via `top_hits` aggregator residing in a `nested` or `reverse_nested` aggregator.
  337. Only nested hits will have a `_nested` field in the hit, non nested (regular) hits will not have a `_nested` field.
  338. The information in `_nested` can also be used to parse the original source somewhere else if `_source` isn't enabled.
  339. If there are multiple levels of nested object types defined in mappings then the `_nested` information can also be hierarchical
  340. in order to express the identity of nested hits that are two layers deep or more.
  341. In the example below a nested hit resides in the first slot of the field `nested_grand_child_field` which then resides in
  342. the second slow of the `nested_child_field` field:
  343. [source,js]
  344. --------------------------------------------------
  345. ...
  346. "hits": {
  347. "total" : {
  348. "value": 2565,
  349. "relation": "eq"
  350. },
  351. "max_score": 1,
  352. "hits": [
  353. {
  354. "_index": "a",
  355. "_type": "b",
  356. "_id": "1",
  357. "_score": 1,
  358. "_nested" : {
  359. "field" : "nested_child_field",
  360. "offset" : 1,
  361. "_nested" : {
  362. "field" : "nested_grand_child_field",
  363. "offset" : 0
  364. }
  365. }
  366. "_source": ...
  367. },
  368. ...
  369. ]
  370. }
  371. ...
  372. --------------------------------------------------
  373. // NOTCONSOLE