# Fetch top k frequent fields

**URL:** <https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928>\
**Category:** Elasticsearch\
**Tags:** painless, eql-elastic-query-language, esql\
**Created:** [June 5, 2025, 4:16pm UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928 "2025-06-05T16:16:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Parthpuri\_Goswami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parthpuri_goswami/32/141878_2.png) [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Post date:** [June 5, 2025, 4:16pm UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928/1 "2025-06-05T16:16:17Z")

</div>

Hi all,

I want to fetch the top k fields that are most frequent in the last 5 minutes of documents or in whole index. I have tried some queries, as shown below, to get the desired output, but it's taking a long time. I guess it's because of the painless script. Can someone help me with the query or suggest another API to fetch the most k frequent fields in the index?

```auto
GET /logs-*/_search
{
  "size": 0,
  "aggs": {
    "top_k_fields": {
      "terms": {
        "script": {
          "source": "return params._source.keySet()",
          "lang": "painless"
        },
        "size": 10
      }
    }
  }
}

```

Also, as a follow-up, I want to retrieve the values along with the top k frequent fields. For example, if field\_A is the most frequent field and is available in all documents, I want to retrieve the data for that field as well. If this can be done with a single query, that would be great.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [June 5, 2025, 5:27pm UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928/2 "2025-06-05T17:27:57Z")

</div>

> [@Parthpuri\_Goswami](#):
>
> want to fetch the top k fields that are most frequent in the last 5 minutes of documents or in whole index

For whole index there are the field statistics.

> **[Field usage stats API | Elasticsearch Guide \[8.18\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.18/field-usage-stats.html)**

I’m curious why you want this info on last X minutes. Just curious.

---

<div class="post-metadata">

**Author:** ![Parthpuri\_Goswami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parthpuri_goswami/32/141878_2.png) [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Post date:** [June 6, 2025, 5:00am UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928/3 "2025-06-06T05:00:28Z")

</div>

Hi,

Thanks for the quick response. I have checked the `_field_usage_stats` API, but it won't give me the desired output. I want the top k fields based on which fields are available in most of the documents, not by usage of them. Suppose I have 10 documents, and field\_A is present in 7 documents, field\_B is present in 5 documents, and field\_C is present in 3 documents. If I query the top 2 fields, it should return field\_A and field\_B.

> I'm curious why you want this info on last X minutes. Just curious.

Means if I add a filter, is it possible to get the desired output because, in that case, the documents will be filtered out.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [June 6, 2025, 7:53am UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928/4 "2025-06-06T07:53:57Z")

</div>

> [@Parthpuri\_Goswami](#):
>
> Means if I add a filter, is it possible to get the desired output because, in that case, the documents will be filtered out.

Sorry on 2 counts.

One, you are right, the fields data is keeping a sort of count, but not counting how many docs each field is present in.

Two, the answer quoted there makes no sense to me. But I was just curious.
