# Querying syslog data to fetch unique error messages

**URL:** https://discuss.elastic.co/t/querying-syslog-data-to-fetch-unique-error-messages/239259
**Category:** Elasticsearch
**Created:** [June 30, 2020, 9:07am UTC](https://discuss.elastic.co/t/querying-syslog-data-to-fetch-unique-error-messages/239259 "2020-06-30T09:07:35Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![N220](https://avatars.discourse-cdn.com/v4/letter/n/3d9bf3/32.png) [@N220](https://discuss.elastic.co/u/N220)
#### Post date: [June 30, 2020, 9:07am UTC](https://discuss.elastic.co/t/querying-syslog-data-to-fetch-unique-error-messages/239259/1 "2020-06-30T09:07:35Z")

</div>

Here is the query I have tried.... Although I have kept filter\_duplicate\_text as true still I get messages of the form {"............June 3 time stamp ...log message.............."} I want to filter out all these duplicate messages. Can anybody help me with this?

```auto
GET log_stash_2020.06.16/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "match_phrase": {
            "message": "Error"
          }
        },
        {
          "match_phrase": {
            "type": "lab_id"
          }
        }
      ]
    }
  },
  "aggs": {
    "log_message": {
      "significant_text": {
        "field": "message",
        "filter_duplicate_text": "true"
      }
    }
  },
  "size": 1000
}

```

```auto
Sample documents containing log messages:

{
        "_index" : "logstash_2020.06.16",
        "_type" : "doc",
        "_id" : "################",
        "_score" : 1.0,
        "_source" : {
          "logsource" : "router_id",
          "timestamp" : "Jun 15 20:00:00",
          "program" : "some_program",
          "host" : "#############",
          "priority" : "27",
          "@timestamp" : "2020-06-16T00:00:01.020Z",
          "type" : "lab_id",
          "pid" : "####",
          "message" : ": ############### send failed with error: ENOENT -- Item not found (No error: 0)",
          "@version" : "1"
        }
      }

{
        "_index" : "logstash_2020.06.16",
        "_type" : "doc",
        "_id" : "################",
        "_score" : 1.0,
        "_source" : {
          "host" : "################",
          "@timestamp" : "2020-06-16T00:00:02.274Z",
          "type" : "####",
          "tags" : [
            "_grokparsefailure"
          ],
          "message" : "################:Jun 15 20:00:18.908 EDT: mediasvr[2546]: %MEDIASVR-MEDIASVR-4-PARTITION_USAGE_ALERT : High disk usage alert : host ##### exceeded 100% \n",
          "@version" : "1"
        }
      }

```

```auto
 The second response contains timestamp in the error message itself and the message field is of type "text".How do I write a query so that it will fetch unique error messages from elastic search DB i.e ignore the time stamp if it is the only difference between two messages.

```

```auto
The mapping details of the index.
{
  "logstash-2020.05.07" : {
    "mappings" : {
      "doc" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "match_mapping_type" : "string",
              "mapping" : {
                "norms" : false,
                "type" : "text"
              }
            }
          },
          {
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "fields" : {
                  "keyword" : {
                    "ignore_above" : 256,
                    "type" : "keyword"
                  }
                },
                "norms" : false,
                "type" : "text"
              }
            }
          }
        ],
        "properties" : {
          "@timestamp" : {
            "type" : "date"
          },
          "@version" : {
            "type" : "keyword"
          },
          "geoip" : {
            "dynamic" : "true",
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "location" : {
                "type" : "geo_point"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "host" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "logsource" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "message" : {
            "type" : "text",
            "norms" : false
          },
          "pid" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "priority" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "program" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "tags" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "timestamp" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "type" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      },
      "_default_" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "match_mapping_type" : "string",
              "mapping" : {
                "norms" : false,
                "type" : "text"
              }
            }
          },
          {
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "fields" : {
                  "keyword" : {
                    "ignore_above" : 256,
                    "type" : "keyword"
                  }
                },
                "norms" : false,
                "type" : "text"
              }
            }
          }
        ],
        "properties" : {
          "@timestamp" : {
            "type" : "date"
          },
          "@version" : {
            "type" : "keyword"
          },
          "geoip" : {
            "dynamic" : "true",
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "location" : {
                "type" : "geo_point"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 28, 2020, 9:07am UTC](https://discuss.elastic.co/t/querying-syslog-data-to-fetch-unique-error-messages/239259/2 "2020-07-28T09:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
