# Field\_name values from ml result resource

**URL:** <https://discuss.elastic.co/t/field-name-values-from-ml-result-resource/209589>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [November 27, 2019, 12:28am UTC](https://discuss.elastic.co/t/field-name-values-from-ml-result-resource/209589 "2019-11-27T00:28:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Inammathe\_Inna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inammathe_inna/32/40656_2.png) [@Inammathe\_Inna](https://discuss.elastic.co/u/Inammathe_Inna)\
**Post date:** [November 27, 2019, 12:28am UTC](https://discuss.elastic.co/t/field-name-values-from-ml-result-resource/209589/1 "2019-11-27T00:28:41Z")

</div>

Hey guys,

I have a ML job that is doing a distinct count of a field over another e.g.

```auto
"detector_description": "distinct_count(reply_CustomerId) over request_IPAddress",
"function": "distinct_count",
"field_name": "reply_CustomerId",
"over_field_name": "request_IPAddress"

```

I was wondering if it is possible to somehow retrieve the field\_name values? I intend to use them in a watcher action.

I've had a look through your [result resource documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/ml-results-resource.html#ml-results-records) and the closest I can see is in the `field_name` property.

I've also tried adding my field that I am doing the distinct\_count over as an influencer to my ml job however, it appears to not include all of the population of `reply_CustomerId` that the distinct count is performed on. Just a small handful or none.

We are currently on Version: 6.5.4

Any clues?

Thank you!

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 27, 2019, 3:28pm UTC](https://discuss.elastic.co/t/field-name-values-from-ml-result-resource/209589/2 "2019-11-27T15:28:39Z")

</div>

In this case, ML does not retain the values of the field\_name (`reply_CustomerId`) - so they are not stored within the .ml-anomalies-\* index.

If you truly wanted them, you'd need to have your Watch use an "[input chain](https://www.elastic.co/guide/en/x-pack/current/input-chain.html)" where the 1st input is a query to determine the anomaly for the field `request_IPAddress` - then use that `request_IPAddress` in a subsequent query to the raw data index (passing that `request_IPAddress` value and most likely also the timestamp of the bucket that the anomaly occurs in).

Then, you could have a list of the `reply_CustomerId`s that made the distinct count anomalous.

An example of a chain input watch can be seen here: [https://github.com/elastic/examples/blob/master/Alerting/Sample%20Watches/ml\_examples/bucket\_record\_chain\_watch.json](https://github.com/elastic/examples/blob/master/Alerting/Sample%20Watches/ml_examples/bucket_record_chain_watch.json)

But note that in the above example, the 2nd query also hits the .ml-anomalies-\* index. In your case, you'd hit the raw data index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 3:28pm UTC](https://discuss.elastic.co/t/field-name-values-from-ml-result-resource/209589/3 "2019-12-25T15:28:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
