# Assistance with fields and filtering on Elk query

**URL:** <https://discuss.elastic.co/t/assistance-with-fields-and-filtering-on-elk-query/255695>\
**Category:** Kibana\
**Created:** [November 17, 2020, 12:37pm UTC](https://discuss.elastic.co/t/assistance-with-fields-and-filtering-on-elk-query/255695 "2020-11-17T12:37:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![douglasnew](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@douglasnew](https://discuss.elastic.co/u/douglasnew)\
**Post date:** [November 17, 2020, 12:37pm UTC](https://discuss.elastic.co/t/assistance-with-fields-and-filtering-on-elk-query/255695/1 "2020-11-17T12:37:35Z")

</div>

HI all.

Can someone assist. I am trying to add an additional field to this query but it does not seem to work as expected. I am trying to simply ass the field "message" and filter based on a matched string.

Here is my query....

{  
"aggs": {  
"2": {  
"terms": {  
"field": "httpURI.keyword",  
"order": {  
"1": "desc"  
},  
"size": 5  
},  
"aggs": {  
"1": {  
"cardinality": {  
"field": "xxxxxxxxxxx-redacted"  
}  
},  
"3": {  
"terms": {  
"field": "httpResponseCode",  
"order": {  
"1": "desc"  
},  
"size": 5  
},  
"aggs": {  
"1": {  
"cardinality": {  
"field": "xxxxxxxxx-redated"  
}  
}  
}  
}  
}  
}  
},  
"size": 0,  
"\_source": {  
"excludes":   
},  
"stored\_fields": [  
"\*"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "@timestamp",  
"format": "date\_time"  
}  
],  
"query": {  
"bool": {  
"must": ,  
"filter": [  
{  
"match\_all": {}  
},  
{  
"match\_all": {}  
},  
{  
"match\_phrase": {  
"httpMethod.keyword": {  
"query": "POST"  
}  
}  
},  
{  
"exists": {  
"field": "httpResponseCode"  
}  
},  
{  
"bool": {  
"minimum\_should\_match": 1,  
"should": [  
{  
"match\_phrase": {  
"httpURI.keyword": "URL1 - dedacted"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "url2 - redacted"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "url3 redatced"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "URL 4 redacted"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "URL5 redacted"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "url6 redacted"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "url7 redacted"  
}  
},  
{  
"match\_phrase": {  
"httpURI.keyword": "url8 redacted"  
}  
}  
]  
}  
},  
{  
"range": {  
"@timestamp": {  
"format": "strict\_date\_optional\_time",  
"gte": "2020-08-31T22:00:00.000Z",  
"lte": "2020-09-01T11:19:46.563Z"  
}  
}  
}  
],  
"should": ,  
"must\_not":   
}  
}  
}

Thanks in advance... PS. struggling with the nesting of fields in the top part of the query.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 17, 2020, 10:39pm UTC](https://discuss.elastic.co/t/assistance-with-fields-and-filtering-on-elk-query/255695/2 "2020-11-17T22:39:11Z")

</div>

Welcome to our community! 😃

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 10:39pm UTC](https://discuss.elastic.co/t/assistance-with-fields-and-filtering-on-elk-query/255695/3 "2020-12-15T22:39:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
