# How not present the duplicated data using elasticsearch \_search query api

**URL:** https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322
**Category:** Kibana
**Tags:** kql-kibana-query-language
**Created:** [March 23, 2023, 8:13am UTC](https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322 "2023-03-23T08:13:22Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![LongKang\_Fan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/longkang_fan/32/97516_2.png) [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)
#### Post date: [March 23, 2023, 8:13am UTC](https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322/1 "2023-03-23T08:13:22Z")

</div>

Hi.

I am using Filebeat -\> Logstash -\> Elasticsearch to save my logfiles. I have saved a field called **casename** to the index pattern like caselog-{YYYY.MM.dd} and I want to query all the case names in that index but just show the same casename in the result only once. What should I do?

```auto
GET /caselog-2023.03.23/_search
{
  "query": {
    "bool": {
      "must": [
        {"match": { "input.type": "filestream" }},
        {"match": {"host.ip": "172.22.0.2"}}
      ]
    }
  },
  "_source": ["casename"]
}

```

How do I improve my query to show the **d.log** only once?

```auto
{
  "took": 703,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 548,
      "relation": "eq"
    },
    "max_score": 0.0018223235,
    "hits": [
      {
        "_index": "caselog-2023.03.23",
        "_id": "LOlnDYcBdTWF_DUiXPsD",
        "_score": 0.0018223235,
        "_source": {
          "casename": "d.log"
        }
      },
      {
        "_index": "caselog-2023.03.23",
        "_id": "JulnDYcBdTWF_DUiXPsC",
        "_score": 0.0018223235,
        "_source": {
          "casename": "Identify_IdfyCtrlValueVerify.py_2023-02-01_02-38-29.log"
        }
      },
      {
        "_index": "caselog-2023.03.23",
        "_id": "J-lnDYcBdTWF_DUiXPsC",
        "_score": 0.0018223235,
        "_source": {
          "casename": "d.log"
        }
      },
.......
.......
.......

```

---

<div class="post-metadata">

### Author: ![LongKang\_Fan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/longkang_fan/32/97516_2.png) [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)
#### Post date: [March 27, 2023, 3:01am UTC](https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322/2 "2023-03-27T03:01:56Z")

</div>

Anyone can help?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 24, 2023, 3:02am UTC](https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322/3 "2023-04-24T03:02:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
