# Common fields

**URL:** <https://discuss.elastic.co/t/common-fields/152980>\
**Category:** Elasticsearch\
**Created:** [October 18, 2018, 10:15am UTC](https://discuss.elastic.co/t/common-fields/152980 "2018-10-18T10:15:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Florent\_Fauvin](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@Florent\_Fauvin](https://discuss.elastic.co/u/Florent_Fauvin)\
**Post date:** [October 18, 2018, 10:15am UTC](https://discuss.elastic.co/t/common-fields/152980/1 "2018-10-18T10:15:15Z")

</div>

Hi !

My proxy logs provide "URL" and "user" fields.

I would like to discover all the common "URL" between 2 user.  
Is it possible ?

Thank you,

Florent

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [October 19, 2018, 7:01am UTC](https://discuss.elastic.co/t/common-fields/152980/2 "2018-10-19T07:01:06Z")

</div>

If you are talking about any pair of users this could be possible using a combination of the terms and cardinality aggregations but would require some tricks to scale if you have millions of unique urls and distributed indices/shards. Is that the case ?  
If you are talking about a specific pair of users then a query for them with the terms aggregation on the url field and a cardinality agg on users should suffice.

---

<div class="post-metadata">

**Author:** ![Florent\_Fauvin](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@Florent\_Fauvin](https://discuss.elastic.co/u/Florent_Fauvin)\
**Post date:** [October 19, 2018, 2:57pm UTC](https://discuss.elastic.co/t/common-fields/152980/3 "2018-10-19T14:57:45Z")

</div>

Yes, I am talking about a specific pair of users.  
For instance, what are the common "URL" between "source\_login":user1 and "source\_login":user2 ?

The problem is that the OR request ("source\_login":user1 OR "source\_login":user2) provide the UNION of accessed "URL".  
But I don't know how I can get the INTERSECTION of accessed "URL" for these two users ?

Thank you for your help,

Regards,

Florent

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [October 19, 2018, 3:06pm UTC](https://discuss.elastic.co/t/common-fields/152980/4 "2018-10-19T15:06:59Z")

</div>

Try this:

```
DELETE test
PUT test
{
  "settings": {
	"number_of_shards": 1,
	"number_of_replicas": 0
  },
  "mappings": {
	"_doc":{
	  "properties":{
		"url":{
		  "type":"keyword"  
		},
		"user":{
		  "type":"keyword"  
		}
	
	  }
	}
  }
}
POST test/_doc/_bulk
{"index":{}}
{"user":"user1", "url":"url1"}
{"index":{}}
{"user":"user1", "url":"url2"}
{"index":{}}
{"user":"user2", "url":"url2"}
{"index":{}}
{"user":"user2", "url":"url2"}
{"index":{}}
{"user":"user2", "url":"url3"}
{"index":{}}
{"user":"user3", "url":"url3"}
{"index":{}}
{"user":"user3", "url":"url4"}

GET test/_search
{
  "query": {
	"terms":{
	  "user":["user1", "user2"]
	}
  },
  "size":0,
  "aggs":{
	"urls":{
	  "terms":{
		"field":"url",
		"min_doc_count": 2,
		"order": {
		  "numUsers": "desc"
		}
	  },
	  "aggs":{
		"numUsers":{
		  "cardinality": {
			"field": "user"
		  }
		}
	  }
	}
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2018, 3:07pm UTC](https://discuss.elastic.co/t/common-fields/152980/5 "2018-11-16T15:07:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
