# Filter unique value fron url field

**URL:** <https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378>\
**Category:** Kibana\
**Created:** [September 14, 2022, 7:39am UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378 "2022-09-14T07:39:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vivek\_Nigam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_nigam/32/25094_2.png) [@Vivek\_Nigam](https://discuss.elastic.co/u/Vivek_Nigam)\
**Post date:** [September 14, 2022, 7:39am UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/1 "2022-09-14T07:39:22Z")

</div>

I want to filer all unique device id from url message , is it possible?? please help

url: "/v1/default/hls-ts-fk/vodm/f452aa15-87ca-5013-856e-b0758db7c3d5/default\_ott.m3u8?PID=testing.30d&PAID=TITL0000000000391111&deviceIdType=test&_deviceId=379a1232c7ade1b5fa4f5cbb662f7ee8_&appId=com.testing.testing&appName=testing%20Go&devModel=ios\_phone&sessionId=abr-vod-2e325654-dd3b-4596-8e8c-a7d8d866ab87&optin=true&externalPackageId=PACK00000000003911111&parentalRating=10&hhid=92a0449ce4e76aa6ef99a06d4a946f25&daiEnabled=true"

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [September 14, 2022, 9:23am UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/2 "2022-09-14T09:23:44Z")

</div>

Hi  
Could you provide come context, where you want to filter it, and with filtering do you mean you want to filter in our out those values? our do you mean you want to create e.h. a table showing you all unique values of _deviceId_ ? For all cases you should extract this field value to it's own keyword typed field so you could use it for aggregations in Elasticsearch

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![Vivek\_Nigam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_nigam/32/25094_2.png) [@Vivek\_Nigam](https://discuss.elastic.co/u/Vivek_Nigam)\
**Post date:** [September 20, 2022, 9:18am UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/3 "2022-09-20T09:18:02Z")

</div>

> [@Vivek\_Nigam](#):
>
> deviceId=379a1232c7ade1b5fa4f5cbb662f7ee8

want to filter all _deviceId=379a1232c7ade1b5fa4f5cbb662f7ee8_

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [September 27, 2022, 1:02pm UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/4 "2022-09-27T13:02:31Z")

</div>

Ok, thx what's the mapping of your message field?

---

<div class="post-metadata">

**Author:** ![Vivek\_Nigam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_nigam/32/25094_2.png) [@Vivek\_Nigam](https://discuss.elastic.co/u/Vivek_Nigam)\
**Post date:** [September 30, 2022, 3:29am UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/5 "2022-09-30T03:29:05Z")

</div>

Url Field

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [October 5, 2022, 8:41pm UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/6 "2022-10-05T20:41:49Z")

</div>

I mean the mapping in Elasticsearch, here's an overview about that:

> **[Field data types | Elasticsearch Guide \[8.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-types.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2022, 8:42pm UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378/7 "2022-11-02T20:42:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
