# Recursive queries (Perform new query based on previous results)

**URL:** <https://discuss.elastic.co/t/recursive-queries-perform-new-query-based-on-previous-results/19062>\
**Category:** Elasticsearch\
**Created:** [August 4, 2014, 8:26am UTC](https://discuss.elastic.co/t/recursive-queries-perform-new-query-based-on-previous-results/19062 "2014-08-04T08:26:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andreas\_Hallberg](https://avatars.discourse-cdn.com/v4/letter/a/c37758/32.png) [@Andreas\_Hallberg](https://discuss.elastic.co/u/Andreas_Hallberg)\
**Post date:** [August 4, 2014, 8:26am UTC](https://discuss.elastic.co/t/recursive-queries-perform-new-query-based-on-previous-results/19062/1 "2014-08-04T08:26:00Z")

</div>

Hi!  
I'm just starting to learn about ES and I have a question regarding  
recursive queries (I'm not sure that's the correct term for what I'm trying  
to do...).  
I'm using Logstash to index logs from multiple sources, and Kibana to  
perform queries/visualization.

What I would like to do is this:

1. Perform a query (QUERY\_1) looking for a specific kind of log output,  
for instance "Error application A".
2. I expect to get a list of messages containing "Error application A",  
now I would like to get all variations of a field, let's say there's a  
"host"- field.
3. Perform a new query (QUERY\_2): "For each host returned from QUERY\_1,  
show messages with fieldX='asd' ".

Is there any way to do this using only ES/Kibana? I guess I could build  
something of my own to do it, but it would be nice to be able to combine  
QUERY\_1 and QUERY\_2 into one single query. Any ideas, or could you point me  
to some tutorial/guide on how to do this?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/952d8d61-64ea-41d5-a8c4-a8ec40cf098c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/952d8d61-64ea-41d5-a8c4-a8ec40cf098c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:11am UTC](https://discuss.elastic.co/t/recursive-queries-perform-new-query-based-on-previous-results/19062/2 "2017-07-06T01:11:11Z")

</div>


