The indexes should be the same, it is a mistake.
but it happens to me exactly the same thing, I attach the result of the second code that I mention to you that does not make correctly the grouping:
GET /wazuh-alerts-4.x-inventory-2024.03.20/_search
{
"size": 0,
"aggs": {
"group_by_category": {
"terms": {
"field": "data.ip",
"size": 10
},
"aggs": {
"services": {
"terms": {
"field": "data.port_proto.keyword",
"size": 10
}
}
}
}
}
}
Result:
{
"took": 5,
"timed_out": false,
"_shards": {
"total": 1,
"successful": 1,
"skipped": 0,
"failed": 0
},
"hits": {
"total": {
"value": 114,
"relation": "eq"
},
"max_score": null,
"hits": []
},
"aggregations": {
"group_by_category": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 94,
"buckets": [
{
"key": "0.0.0.0",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "63.245.209.91",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "63.245.209.105",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "64.4.20.169",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "65.54.95.64",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "65.54.95.198",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "65.54.234.75",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "65.55.16.121",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "65.55.18.18",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
},
{
"key": "65.55.184.155",
"doc_count": 2,
"services": {
"doc_count_error_upper_bound": 0,
"sum_other_doc_count": 0,
"buckets": []
}
}
]
}
}
}