# How to get the Key

**URL:** <https://discuss.elastic.co/t/how-to-get-the-key/31701>\
**Category:** Elasticsearch\
**Created:** [October 6, 2015, 2:10pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701 "2015-10-06T14:10:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juan\_Andres\_Ramirez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_andres_ramirez/32/9467_2.png) [@Juan\_Andres\_Ramirez](https://discuss.elastic.co/u/Juan_Andres_Ramirez)\
**Post date:** [October 6, 2015, 2:10pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/1 "2015-10-06T14:10:20Z")

</div>

Hello Guys,  
I need to know how to get a specific key named source, it's inside the section \_source.

First I executed command:

```
curl -XGET 'http://10.101.81.199:9200/graylog2_20/_search?pretty' -d '{
"query": { "match": {"source": "SERVER-1"}},
"_source": ["source"]}'

```

Output:

```
"_index" : "graylog2_20",
      "_type" : "message",
      "_id" : "9d8cfb12-605f-11e5-943e-005056a9199b",
      "_score" : 3.0858476,
      "_source":{" **source":"SERVER-1**"}

```

I need get the key source it's inside in "\_source" to find every source with SERVER-1 and delete every key found.

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 6, 2015, 2:21pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/2 "2015-10-06T14:21:30Z")

</div>

Are you looking for the [delete by query API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html)?

---

<div class="post-metadata">

**Author:** ![Juan\_Andres\_Ramirez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_andres_ramirez/32/9467_2.png) [@Juan\_Andres\_Ramirez](https://discuss.elastic.co/u/Juan_Andres_Ramirez)\
**Post date:** [October 6, 2015, 2:38pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/3 "2015-10-06T14:38:01Z")

</div>

Hi Magnus,  
Yes but I can't find the way to delete by query api. I tried with some command, for example:

```
curl -XGET 'http://10.101.81.199:9200/graylog2_20/message/_query' -d '{
 "query_string":{
 "default_field" : "source",
 "query": "SERVER-1"
 }
 }'

```

OUTPUT:

```
 {"_index":"graylog2_20","_type":"messages","_id":"_query","found":false}

```

I can delete by ID but I have around 50G in data.....delete 1 at time by ID is crazy....

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 6, 2015, 6:00pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/4 "2015-10-06T18:00:03Z")

</div>

The documentation I linked to contains examples that are very close to what you need so I'm not sure what's unclear. Your command uses `-XGET` but you need `-XDELETE`. If you correct that it might actually work. Well, except that there appears to be something wrong with the query itself since it matches zero documents.

---

<div class="post-metadata">

**Author:** ![Juan\_Andres\_Ramirez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_andres_ramirez/32/9467_2.png) [@Juan\_Andres\_Ramirez](https://discuss.elastic.co/u/Juan_Andres_Ramirez)\
**Post date:** [October 7, 2015, 12:24pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/5 "2015-10-07T12:24:50Z")

</div>

Hello Magnus, Sorry my mistake,

COMMAND:

```
curl -XDELETE 'http://10.101.81.199:9200/graylog2_0/message/_query?pretty' -d '{
 "query_string":{
 "default_field" : "source",
 "query": "SERVER-1"
 }
 }'

```

OUTPUT:

```
"_indices" : {
    "graylog2_0" : {
      "_shards" : {
        "total" : 1,
        "successful" : 0,
        "failed" : 1,
        "failures" : [ {
          "index" : "graylog2_0",
          "shard" : 0,
          "reason" : "QueryParsingException[[graylog2_0] request does not support [query_string]]"
        } ]

```

The index has enable write/read.  
Any idea why the request doesn't support?.

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 7, 2015, 12:29pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/6 "2015-10-07T12:29:44Z")

</div>

See [http://stackoverflow.com/a/32607578/414355](http://stackoverflow.com/a/32607578/414355).

---

<div class="post-metadata">

**Author:** ![Juan\_Andres\_Ramirez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_andres_ramirez/32/9467_2.png) [@Juan\_Andres\_Ramirez](https://discuss.elastic.co/u/Juan_Andres_Ramirez)\
**Post date:** [October 7, 2015, 12:59pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/7 "2015-10-07T12:59:42Z")

</div>

Its works!!, problem solved, Thank you Magnus.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:46pm UTC](https://discuss.elastic.co/t/how-to-get-the-key/31701/8 "2017-07-05T23:46:11Z")

</div>


