# Count instances of a field in Elasticsearch index

**URL:** <https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907>\
**Category:** Elasticsearch\
**Created:** [June 12, 2020, 2:01pm UTC](https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907 "2020-06-12T14:01:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gitterhh](https://avatars.discourse-cdn.com/v4/letter/g/b19c9b/32.png) [@gitterhh](https://discuss.elastic.co/u/gitterhh)\
**Post date:** [June 12, 2020, 2:01pm UTC](https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907/1 "2020-06-12T14:01:40Z")

</div>

How to count the instances of a particular field, across all documents, in a given Elasticsearch index.  
For example, if I've got the following documents in index `goober` :

```auto
{
    '_id':'foo',
    'field1':'a value',
    'field2':'a value'
},
{
    '_id':'bar',
    'field1':'a value',
    'field2':'a value'
},
{
    '_id':'baz',
    'field1':'a value',
    'field3':'a value'
}

```

I'd like to know something like the following:

```auto
{
    'index':'goober',
    'field_counts':
        'field1':3,
        'field2':2,
        'field3':1
}

```

Is this possible?

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [June 14, 2020, 3:49pm UTC](https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907/2 "2020-06-14T15:49:22Z")

</div>

If you know field names at the time of constructing query, you can use exists query for each field. You can combine for multiple exists queries using multi search or nest inside filters aggregation

```auto
{
  "size": 0,
  "aggs": {
    "messages": {
      "filters": {
        "filters": {
          "field1": {
            "exists": {
              "field": "field1"
            }
          },
          "field2": {
            "exists": {
              "field": "field2"
            }
          },
          "field3": {
            "exists": {
              "field": "field3"
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![gitterhh](https://avatars.discourse-cdn.com/v4/letter/g/b19c9b/32.png) [@gitterhh](https://discuss.elastic.co/u/gitterhh)\
**Post date:** [June 14, 2020, 9:11pm UTC](https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907/3 "2020-06-14T21:11:11Z")

</div>

Thanks, it works.

Can you please also advise if it is possible to execute such request for all properties without explicitly specify all the fields?

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [June 15, 2020, 2:08am UTC](https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907/4 "2020-06-15T02:08:07Z")

</div>

Unless you have turned off dynamic mapping, any document inserted or updated, can add more fields to the existing index mapping. So the listing of "all properties" can change by the time your query reaches server.

If you need it for a daily / weekly report, then you can write a small script to fetch index mapping using `curl -XGET http://<host>:<port>/<index>/_mappings` and then recursively extract properties to form the list.

What's your use case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2020, 2:08am UTC](https://discuss.elastic.co/t/count-instances-of-a-field-in-elasticsearch-index/236907/5 "2020-07-13T02:08:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
