# Is there a API which can get all beat.hostname in an index?

**URL:** <https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528>\
**Category:** Elasticsearch\
**Created:** [June 30, 2022, 1:53am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528 "2022-06-30T01:53:22Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [June 30, 2022, 1:53am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/1 "2022-06-30T01:53:22Z")

</div>

Or some other way...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2022, 5:27am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/2 "2022-06-30T05:27:31Z")

</div>

You can make an Elasticsearch query to get it. From [Terms aggregation | Elasticsearch Guide [8.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html);

```auto
curl -X GET "localhost:9200/INDEXNAME/_search?pretty" -H 'Content-Type: application/json' -d'
{
  "aggs": {
    "hosts": {
      "terms": { "field": "beat.hostname" }
    }
  }
}
'

```

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [June 30, 2022, 6:30am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/3 "2022-06-30T06:30:14Z")

</div>

I tried this, but returned 400 status:

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "illegal_argument_exception",
        "reason" : "Fielddata is disabled on text fields by default. Set fielddata=true on [beat.hostname] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead."
      }
    ],
    "type" : "search_phase_execution_exception",
    "reason" : "all shards failed",
    "phase" : "query",
    "grouped" : true,
    "failed_shards" : [
      {
        "shard" : 0,
        "index" : "logstash-nginx-log-whv3-2022.06.28",
        "node" : "3Fai_tbWTHS7_XRHJX5JDA",
        "reason" : {
          "type" : "illegal_argument_exception",
          "reason" : "Fielddata is disabled on text fields by default. Set fielddata=true on [beat.hostname] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead."
        }
      }
    ],
    "caused_by" : {
      "type" : "illegal_argument_exception",
      "reason" : "Fielddata is disabled on text fields by default. Set fielddata=true on [beat.hostname] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.",
      "caused_by" : {
        "type" : "illegal_argument_exception",
        "reason" : "Fielddata is disabled on text fields by default. Set fielddata=true on [beat.hostname] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead."
      }
    }
  },
  "status" : 400
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2022, 7:02am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/4 "2022-06-30T07:02:51Z")

</div>

What version are you on?

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [June 30, 2022, 7:06am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/5 "2022-06-30T07:06:25Z")

</div>

6.3.0

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2022, 7:08am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/6 "2022-06-30T07:08:02Z")

</div>

Yikes, that's very old and definitely past [EOL](https://www.elastic.co/support/eol). You need to look at upgrading as a matter of urgency, as 6.X is no longer supported, and 8.2 is latest.

Try changing the field to `beat.hostname.keyword`.

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [June 30, 2022, 7:23am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/7 "2022-06-30T07:23:43Z")

</div>

Thanks, it returned success.

But it only return 10 records, and only 2 beatnames are different. We have more than 20 beats in one index... How to get all of the beatname...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2022, 7:31am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/8 "2022-06-30T07:31:12Z")

</div>

You asked for the hostname though?

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [June 30, 2022, 7:38am UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/9 "2022-06-30T07:38:23Z")

</div>

Yes.. I am sorry, it seems I am not being clear.

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [June 30, 2022, 5:13pm UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/10 "2022-06-30T17:13:56Z")

</div>

I have found the solution.

> [@Need to get the list of hosts sending the logs to kibana](https://discuss.elastic.co/t/need-to-get-the-list-of-hosts-sending-the-logs-to-kibana/142435):
>
> Hi All, I need to setup a new visualize to get the list of hosts forwarding the logs to logstash. We have around 50 server and filebeat is the only plugin installed in all the server. I dont want the count , I want the list of hosts that have send the logs in the particular period of time. Regards Nandha

Also thanks a lot for you time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2022, 5:14pm UTC](https://discuss.elastic.co/t/is-there-a-api-which-can-get-all-beat-hostname-in-an-index/308528/11 "2022-07-28T17:14:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
