# KQL query to retrieve list of servers which are running metricbeat

**URL:** <https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [January 6, 2021, 12:04pm UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336 "2021-01-06T12:04:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergius92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergius92/32/81819_2.png) [@Sergius92](https://discuss.elastic.co/u/Sergius92)\
**Post date:** [January 6, 2021, 12:04pm UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336/1 "2021-01-06T12:04:56Z")

</div>

Hello,

I am trying to retrieve the list of servers which are running metricbeat.  
At this moment I have build an query but I don't know how to get the output with every host.name and the number of hits in the last minute.

Can someone please take a look?

```auto
GET metricbeat-7.6.2/_search?size=0
{
  "aggs": {
    "hosts_count": {
      "value_count": {
        "field": "host.name"
      }
    }
  },
  "query": {
    "bool": {
      "must": {
        "range": {
          "@timestamp":{"gt": "now-1m"}
        }}
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 6, 2021, 12:29pm UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336/2 "2021-01-06T12:29:53Z")

</div>

Welcome to the community @Sergius92

Remove `size=0` or change to how many results you want. If you remove it then it will default to 10 results.

That paramenter effects how many results are returned for your `query` but doesn't effect the `aggs`. You should be seeing the `aggs` in the output though.

---

<div class="post-metadata">

**Author:** ![Sergius92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergius92/32/81819_2.png) [@Sergius92](https://discuss.elastic.co/u/Sergius92)\
**Post date:** [January 6, 2021, 1:26pm UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336/3 "2021-01-06T13:26:26Z")

</div>

Thanks a lot for your hint. I am quite new into KQL and I don't know all the features available.  
I've removed it but now I have all the informations available.  
Can I filter somehow to see only the desired result?

I want to have something like:  
Host1\_name  
host1\_count: 2

host2\_name  
host2\_count:150

And so on.

Thanks a lot in advance.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 6, 2021, 2:23pm UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336/4 "2021-01-06T14:23:34Z")

</div>

Think I got it. Try below but if you don't see any results bump the 1 minute to a higher number to see if it works.

```auto
GET metricbeat-7.6.2/_search
{
  "size": 0,
  "query": {
    "range": {
      "@timestamp": {
        "gte": "now-1m",
        "lt": "now"
      }
    }
  },
  "aggs": {
    "by_host": {
      "terms": {
        "field": "host.name"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Sergius92](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergius92/32/81819_2.png) [@Sergius92](https://discuss.elastic.co/u/Sergius92)\
**Post date:** [January 7, 2021, 9:11am UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336/5 "2021-01-07T09:11:22Z")

</div>

Thank a lot @aaron-nimocks !

I've managed finally to make my output as I wanted thanks to your help.  
If someone is interested in this topic I will add the query here and the output:

```auto
GET metricbeat-7.6.2/_search?
{
  "size": 0,
  "query": {
    "range": {
      "@timestamp": {
        "gte": "now-1m",
        "lt": "now"
      }
    }
  },
  "aggs": {
    "by_host": {
      "terms": {
        "field": "host.name",
        "size": 10000
        , "order": {
          "_key": "asc"
        }
      }
    }
  }
}

```

**OUTPUT**

```auto
{
  "took" : 6,
  "timed_out" : false,
  "_shards" : {
    "total" : 10,
    "successful" : 10,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "by_host" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "hostn03",
          "doc_count" : 197
        },
        {
          "key" : "hostn04",
          "doc_count" : 195
        },
        {
          "key" : "hostn05",
          "doc_count" : 208
        },
        {
          "key" : "hostn06",
          "doc_count" : 204
        },
        {
          "key" : "hostn07",
          "doc_count" : 196
        }
.............................

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2021, 9:11am UTC](https://discuss.elastic.co/t/kql-query-to-retrieve-list-of-servers-which-are-running-metricbeat/260336/6 "2021-02-04T09:11:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
