# Querying elastic search in Kibana using Json

**URL:** <https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150>\
**Category:** Elasticsearch\
**Created:** [October 27, 2016, 1:16pm UTC](https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150 "2016-10-27T13:16:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![adhikz](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@adhikz](https://discuss.elastic.co/u/adhikz)\
**Post date:** [October 27, 2016, 1:16pm UTC](https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150/1 "2016-10-27T13:16:10Z")

</div>

Hi, I have set up my Elk stack and everything seems to be working perfectly in terms of indexing and filtering data that i require.

My log file contains the following :

```
123 20126254 6718 Chicken
1234 20326254 6718 Bread
123 20126254 6718 Chicken
123 20126254 6718 Chicken
12345 20426254 6718 Rice
123456 20526254 6718 apples
123 20126254 6718 Chicken

```

When i filter the results with grok i get the following output for each line in my log file:

```
OrderNumber : 123
ProductId: 20126254 
ProductType: 6718
ProductName: Chicken

```

I need some advice on how to go about querying this data in elastic search in order to get specific results.

This is what i would like to do:

**_Select all OrderNumbers that contain the same productId_**

Please advise me on how i should go about doing this?

Should i use json?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 27, 2016, 1:44pm UTC](https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150/2 "2016-10-27T13:44:40Z")

</div>

> Select all OrderNumbers that contain the same productId

Do you mean "select all documents that have a particular product id (e.g. 20126254)"? Or do you want to select all documents but group them by the product id?

---

<div class="post-metadata">

**Author:** ![adhikz](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@adhikz](https://discuss.elastic.co/u/adhikz)\
**Post date:** [October 27, 2016, 2:14pm UTC](https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150/3 "2016-10-27T14:14:41Z")

</div>

when i run this query it should return the follwoing :

**Current Data** in one index

```
123 20126254 6718 Chicken
1234 20326254 6718 Bread
12363 20126254 6718 Chicken
12323 20126254 6718 Chicken
12345 20426254 6718 Rice
123456 20526254 6718 apples
12379 20126254 6718 Chicken

```

**After i run query** i would like to see the follwoing result :

```
123 20126254 6718 Chicken
12363 20126254 6718 Chicken
12379 20126254 6718 Chicken
12323 20126254 6718 Chicken

```

As you can see above this will return all OrderNumbers which are different but contain the same ProductId.

```
OrderNumber : 123  	     
ProductId : 20126254	   

OrderNumber : 12363        
ProductId : 20126254	   

OrderNumber : 12379        
ProductId : 20126254	   

OrderNumber : 12323	     
ProductId : 20126254	   

```

I hope i explained correctly.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 28, 2016, 11:14am UTC](https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150/4 "2016-10-28T11:14:07Z")

</div>

Use the query `ProductId:20126254` to get all documents with the product id 20126254.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:08pm UTC](https://discuss.elastic.co/t/querying-elastic-search-in-kibana-using-json/64150/5 "2017-07-05T22:08:44Z")

</div>


