# Collect fields into the hash

**URL:** <https://discuss.elastic.co/t/collect-fields-into-the-hash/19438>\
**Category:** Elasticsearch\
**Created:** [August 25, 2014, 3:08pm UTC](https://discuss.elastic.co/t/collect-fields-into-the-hash/19438 "2014-08-25T15:08:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vitaly\_bulgakov](https://avatars.discourse-cdn.com/v4/letter/v/76d3ee/32.png) [@vitaly\_bulgakov](https://discuss.elastic.co/u/vitaly_bulgakov)\
**Post date:** [August 25, 2014, 3:08pm UTC](https://discuss.elastic.co/t/collect-fields-into-the-hash/19438/1 "2014-08-25T15:08:59Z")

</div>

I have the following index:  
{  
"message" =\> "Thu Jun 05 08:00:00 2014 RID 978a1861-1401973200416  
URL ..... ",  
"@version" =\> "1",  
"@timestamp" =\> "2014-08-22T15:46:22.729Z",  
"host" =\> "........",  
"kw" =\> "Ready Mix Concrete",  
"town" =\> "Zephyrhills",  
"state" =\> "FL",  
"ip" =\> "63.251.207.54",  
"src" =\> "comlocal5"  
}  
{  
"message" =\> "Thu Jun 05 08:00:00 2014 RID 978a1861-1401973200435  
URL ..... ",  
"@version" =\> "1",  
"@timestamp" =\> "2014-08-22T15:46:22.729Z",  
"host" =\> "....",  
"kw" =\> "video",  
"town" =\> "Norfolk",  
"state" =\> "VA",  
"ip" =\> "216.54.94.2",  
"src" =\> "Lsxppc21128"  
}  
For simplicity only 2 documents.

I want to get hash with field "kw" as a key and frequency as a value.  
In this case it will be  
hash{"Ready Mix Concrete} =\> 1  
hash{video} =\> 1

I know that I should possibly use aggregates, but it did not work for me:

> curl -XGET '[http://localhost:9200/\_search?search\_type=count](http://localhost:9200/_search?search_type=count)' -d  
> '{"aggregations":{"terms":{"field":"kw"}}}'

{"took":24,"timed\_out":false,"\_shards":{"total":10,"successful":10,"failed":0},"hits":{"total":4,"max\_score":0.0,"hits":}}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/173839c3-62ad-41dd-927b-99628d114a63%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/173839c3-62ad-41dd-927b-99628d114a63%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [August 26, 2014, 1:20pm UTC](https://discuss.elastic.co/t/collect-fields-into-the-hash/19438/2 "2014-08-26T13:20:38Z")

</div>

Hello Vitaly ,

The format of your query is wrong.  
Here is the right syntax -

curl -XGET '[http://localhost:9200/es/\_search?search\_type=count&pretty](http://localhost:9200/es/_search?search_type=count&pretty)' -d  
'{"aggregations":{"kwStats" : {"terms":{"field":"kw"}}}}'

Thanks  
Vineeth

On Mon, Aug 25, 2014 at 8:38 PM, vitaly [vitaly.bulgakov@gmail.com](mailto:vitaly.bulgakov@gmail.com) wrote:

> I have the following index:  
> {  
> "message" =\> "Thu Jun 05 08:00:00 2014 RID 978a1861-1401973200416  
> URL ..... ",  
> "@version" =\> "1",  
> "@timestamp" =\> "2014-08-22T15:46:22.729Z",  
> "host" =\> "........",  
> "kw" =\> "Ready Mix Concrete",  
> "town" =\> "Zephyrhills",  
> "state" =\> "FL",  
> "ip" =\> "63.251.207.54",  
> "src" =\> "comlocal5"  
> }  
> {  
> "message" =\> "Thu Jun 05 08:00:00 2014 RID 978a1861-1401973200435  
> URL ..... ",  
> "@version" =\> "1",  
> "@timestamp" =\> "2014-08-22T15:46:22.729Z",  
> "host" =\> "....",  
> "kw" =\> "video",  
> "town" =\> "Norfolk",  
> "state" =\> "VA",  
> "ip" =\> "216.54.94.2",  
> "src" =\> "Lsxppc21128"  
> }  
> For simplicity only 2 documents.
> 
> I want to get hash with field "kw" as a key and frequency as a value.  
> In this case it will be  
> hash{"Ready Mix Concrete} =\> 1  
> hash{video} =\> 1
> 
> I know that I should possibly use aggregates, but it did not work for me:
> 
> > curl -XGET '[http://localhost:9200/\_search?search\_type=count](http://localhost:9200/_search?search_type=count)' -d  
> > '{"aggregations":{"terms":{"field":"kw"}}}'
> 
> {"took":24,"timed\_out":false,"\_shards":{"total":10,"successful":10,"failed":0},"hits":{"total":4,"max\_score":0.0,"hits":}}
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/173839c3-62ad-41dd-927b-99628d114a63%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/173839c3-62ad-41dd-927b-99628d114a63%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/173839c3-62ad-41dd-927b-99628d114a63%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/173839c3-62ad-41dd-927b-99628d114a63%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5kDwFUJ3V5ztt%2BRBHxXMi8D2nQ9cjgNtiB84XxsK94%2B0A%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5kDwFUJ3V5ztt%2BRBHxXMi8D2nQ9cjgNtiB84XxsK94%2B0A%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:06am UTC](https://discuss.elastic.co/t/collect-fields-into-the-hash/19438/3 "2017-07-06T01:06:23Z")

</div>


