Hi ,
I am using the following query to get a unique value. I used "cardinality" for unique value , but I am getting multiple value. Can you pls help me.
res = es.search(index='data-log-*',size=10000, body ={"sort": [{"@timestamp": {"order": "asc"}}],"aggs": { "2": { "terms": { "field": "cputime", "size": 5, "order": { "1": "desc" } }, "aggs": { "1": { "cardinality": { "field": "Id.keyword" } }, "3": { "terms": { "field": "Id.keyword", "size": 5, "order": { "1": "desc" } }, "aggs": { "1": { "cardinality": { "field": "Id.keyword" } } } } } } }, "query": { "bool": { "must": [ { "match_all": {} }, { "match_phrase": { "user.keyword": { "query": "xyz" } } }, { "match_phrase": { "clustername": { "query": "abc" } } }, { "match_phrase": { "status": { "query": "DONE" } } }, { "range": { "cputime": { "gte": 0, "lt": 1000 } } }, { "range": { "@timestamp": { "gte": 1562221936870, "lte": 1562236336870, "format": "epoch_millis" } } } ] } } })