# Querying for inner json parameters

**URL:** <https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083>\
**Category:** Kibana\
**Created:** [October 24, 2017, 2:53pm UTC](https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083 "2017-10-24T14:53:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shaked571](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaked571/32/23975_2.png) [@shaked571](https://discuss.elastic.co/u/shaked571)\
**Post date:** [October 24, 2017, 2:53pm UTC](https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083/1 "2017-10-24T14:53:16Z")

</div>

HI everyone,  
I am new in Kibana and i have some difficulties in my queries while using the Dev Tools.  
I try to find a log according to his nested json and getting an Error back and i wish to know what I'm doing wrong  
for example-for this log:  
_{_  
\_ "_index": "logstash-2017.10.20",_  
\_ "_type": "my\_type",_  
\_ "_id": "AV86NYdT0q4wZ6aQFflk",_  
\_ "_score": 1,_  
\_ "_source": {_  
\_ "offset": 4553353,\_  
\_ "sourceTimestamp": "2017-10-20 08:13:42,583",\_  
\_ "level": "INFO",\_  
\_ "logger": "ExecuteProcessTaskExecutor",\_  
\_ "input\_type": "log",\_  
\_ "source": "D:\log\A.[15400].log",\_  
\_ "message": "[foo:17400]: 2017-10-20 08:13:42,582 [1] INFO ",\_  
\_ "type": "SIMP - Scheduler",\_  
\_ "tags": [\_  
\_ "beats\_input\_codec\_plain\_applied"\_  
\_ ],\_  
\_ "@timestamp": "2017-10-20T14:31:48.017Z",\_  
\_ "task": "Exec:17400:StdOut",\_  
\_ "@version": "1",\_  
\_ "beat": {\_  
\_ "hostname": "A01",\_  
\_ "name": "A01",\_  
\_ "version": "5.3.0"\_  
\_ },\_  
\_ "host": "A01"\_  
\_ }\_  
\_ }\_

i would like to find it according to his hostname or name.  
but all the options i tried lead to an error or to 0 hits.

can anyone assist?

Thnax in advance!

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [October 24, 2017, 7:22pm UTC](https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083/2 "2017-10-24T19:22:43Z")

</div>

You can use a term query to find all the documents that match that host:

```auto
GET logstash-*/_search
{
  "query": {
    "term": {
      "beat.hostname": {
        "value": "A01"
      }
    }
  }
}

```

[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-term-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-term-query.html)

---

<div class="post-metadata">

**Author:** ![shaked571](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaked571/32/23975_2.png) [@shaked571](https://discuss.elastic.co/u/shaked571)\
**Post date:** [October 25, 2017, 8:24am UTC](https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083/3 "2017-10-25T08:24:23Z")

</div>

great, thank you very much!  
Followup question:  
if I want to do a query for more specific document. in which I demand the log both will have hostname " **A01**"  
and the type will be" **my type.**"  
(that's was my real intention - and the problem is occurred in the aggregation in my search -  
for the type i used this query:

```
   "query": { 
       "bool":{
           "must": 
             {
              "term":{
              "_type": "my_type"
            }
        }
     }
   }
}

```

but i cant combine them.

**edit:**  
I saw in the exception i got that:

> [term] query doesn't support multiple fields

what search type does give me that option?

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [October 25, 2017, 5:00pm UTC](https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083/4 "2017-10-25T17:00:34Z")

</div>

You are close. 😉 You have to use the array form of `must`:

```auto
{
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "_type": "my_type"
          }
        },
        {
          "term": {
            "hostname": "A01"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2017, 5:00pm UTC](https://discuss.elastic.co/t/querying-for-inner-json-parameters/105083/5 "2017-11-22T17:00:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
