# Filter for documents that only have one of possible values

**URL:** <https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949>\
**Category:** Elasticsearch\
**Created:** [April 27, 2020, 11:50am UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949 "2020-04-27T11:50:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gyterpena](https://avatars.discourse-cdn.com/v4/letter/g/a9a28c/32.png) [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Post date:** [April 27, 2020, 11:50am UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949/1 "2020-04-27T11:50:52Z")

</div>

I have documents/web logs that have source IP and http method(GET,POST,PUT...)

I need to query list of source IPs that only did POST in specified time window.

Any ideas?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 27, 2020, 12:37pm UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949/2 "2020-04-27T12:37:14Z")

</div>

Use a match query to filter this.  
Ideally use that in a bool query with 2 filter clauses, one with the range query on the date and the match or term query on the verb.

---

<div class="post-metadata">

**Author:** ![gyterpena](https://avatars.discourse-cdn.com/v4/letter/g/a9a28c/32.png) [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Post date:** [April 27, 2020, 1:33pm UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949/3 "2020-04-27T13:33:43Z")

</div>

How would it work for this set? I'm after list with 1.1.1.1,4.4.4.4

id:1,src.ip:1.1.1.1, http\_method:POST

id2,src.ip:2.2.2.2, http\_method:POST

id3,src.ip:2.2.2.2, http\_method:GET

id4,src.ip:3.3.3.3, http\_method:POST

id5,src.ip:3.3.3.3, http\_method:GET

id6,src.ip:4.4.4.4, http\_method:POST

(scale to several millions)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 27, 2020, 7:18pm UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949/4 "2020-04-27T19:18:49Z")

</div>

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![gyterpena](https://avatars.discourse-cdn.com/v4/letter/g/a9a28c/32.png) [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Post date:** [May 15, 2020, 11:41am UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949/5 "2020-05-15T11:41:12Z")

</div>

I ended up using this.

```auto
curl -k -XPOST -u USENAME:PASSWORD --header 'Content-Type: application/json' '[https://localhost:9200/_sql?format=txt](https://localhost:9200/_sql?format=txt)' -d "{ \"query\": \"SELECT src.ip, max(\\\"@timestamp\\\") times, (CURRENT_TIMESTAMP - interval 10 minutes) cutOfDate, max(http.http_method) method, count(distinct http.http_method) methods FROM \\\"logs-syslog\\\" WHERE \\\"@timestamp\\\" >= CURRENT_TIMESTAMP - interval 10 minutes AND [host.name](https://host.name) = 'SOME-HOSTNAME' group by src.ip having methods = 1\" }" | grep POST | sed 's/|.*//' | ts '%d-%b-%Y %H:%M:%S' >> IP-list.log

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2020, 11:41am UTC](https://discuss.elastic.co/t/filter-for-documents-that-only-have-one-of-possible-values/229949/6 "2020-06-12T11:41:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
