# Elasticsearch query for unique value

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-for-unique-value/188893>\
**Category:** Elasticsearch\
**Created:** [July 4, 2019, 10:52am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-unique-value/188893 "2019-07-04T10:52:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![niraj\_pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_pandey/32/44034_2.png) [@niraj\_pandey](https://discuss.elastic.co/u/niraj_pandey)\
**Post date:** [July 4, 2019, 10:52am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-unique-value/188893/1 "2019-07-04T10:52:44Z")

</div>

Hi ,

I am using the following query to get a unique value. I used "cardinality" for unique value , but I am getting multiple value. Can you pls help me.

res = es.search(index='data-log-\*',size=10000, body ={"sort": [{"@timestamp": {"order": "asc"}}],"aggs": { "2": { "terms": { "field": "cputime", "size": 5, "order": { "1": "desc" } }, "aggs": { "1": { "cardinality": { "field": "Id.keyword" } }, "3": { "terms": { "field": "Id.keyword", "size": 5, "order": { "1": "desc" } }, "aggs": { "1": { "cardinality": { "field": "Id.keyword" } } } } } } }, "query": { "bool": { "must": [{ "match\_all": {} }, { "match\_phrase": { "user.keyword": { "query": "xyz" } } }, { "match\_phrase": { "clustername": { "query": "abc" } } }, { "match\_phrase": { "status": { "query": "DONE" } } }, { "range": { "cputime": { "gte": 0, "lt": 1000 } } }, { "range": { "@timestamp": { "gte": 1562221936870, "lte": 1562236336870, "format": "epoch\_millis" } } }] } } })

---

<div class="post-metadata">

**Author:** ![niraj\_pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_pandey/32/44034_2.png) [@niraj\_pandey](https://discuss.elastic.co/u/niraj_pandey)\
**Post date:** [July 4, 2019, 10:52am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-unique-value/188893/2 "2019-07-04T10:52:56Z")

</div>

I am using this on python

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [July 4, 2019, 2:21pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-unique-value/188893/3 "2019-07-04T14:21:40Z")

</div>

Hi @niraj_pandey,

Can you please format your code it's hard to read.

If I didn't mistake the aggregations parts is here:

```
"aggs": {
  "1": { 
    "cardinality": { "field": "Id.keyword" } 
  }, 
  "3": { 
    "terms": { "field": "Id.keyword", "size": 5, "order": { "1": "desc" } }, 
    "aggs": { 
      "1": { 
        "cardinality": { "field": "Id.keyword" } 
      } 
    } 
  } 
}

```

There's 2 aggregations "1" and "3", the second aggregation have a sub aggregation called "1". Better naming can help.

Which one is returning multiple value? Can you provide some documents to be able to reproduce the problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2019, 2:21pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-unique-value/188893/4 "2019-08-01T14:21:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
