# Best way to look for a doc across multiple indices?

**URL:** <https://discuss.elastic.co/t/best-way-to-look-for-a-doc-across-multiple-indices/238168>\
**Category:** Kibana\
**Created:** [June 23, 2020, 2:41am UTC](https://discuss.elastic.co/t/best-way-to-look-for-a-doc-across-multiple-indices/238168 "2020-06-23T02:41:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ishanjain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ishanjain/32/59637_2.png) [@ishanjain](https://discuss.elastic.co/u/ishanjain)\
**Post date:** [June 23, 2020, 2:41am UTC](https://discuss.elastic.co/t/best-way-to-look-for-a-doc-across-multiple-indices/238168/1 "2020-06-23T02:41:56Z")

</div>

Hello everyone!

Kibana saves alerts in a index `.opendistro-alerting-alerts` and when the alert completes, It moves it to `.opendistro-alerting-alert-history.yyyy.mm`.

I have a `check-incident` function in a step-function on AWS. `check-incident` runs every 2 minutes and checks the status of the incident.

Right now, I am using `Get` endpoint to fetch this doc from `.opendistro-alerting-alerts` but this fails when the incident is actually completed since the doc is no longer present in this index.

So, What is the best way to look for a doc across multiple indexes? I want to look for a doc with id `X` across `.opendistro-alerting-alert*`. I believe, `Get` endpoint doesn't accept wildcards. So, What is the best way to do this?

---

<div class="post-metadata">

**Author:** ![ishanjain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ishanjain/32/59637_2.png) [@ishanjain](https://discuss.elastic.co/u/ishanjain)\
**Post date:** [June 23, 2020, 5:36pm UTC](https://discuss.elastic.co/t/best-way-to-look-for-a-doc-across-multiple-indices/238168/2 "2020-06-23T17:36:24Z")

</div>

Resolved by using a search query on the matching indices. i.e. `.opendistro-alerting-alert*`.

```auto
{
  "query": { 
    "bool": { 
      "filter": [ 
        { "term": { "_id": "<id goes here>" }}
      ]
    }
  }
}

```

I am not sure if this is the most efficient way to look for a id in a set of indices but it works and we don't run this often enough that it'll generate perf problems for us soo, I guess this is fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2020, 5:36pm UTC](https://discuss.elastic.co/t/best-way-to-look-for-a-doc-across-multiple-indices/238168/3 "2020-07-21T17:36:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
