# Retrieving all the unique events

**URL:** <https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758>\
**Category:** Elasticsearch\
**Created:** [November 21, 2018, 5:25pm UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758 "2018-11-21T17:25:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![23141](https://avatars.discourse-cdn.com/v4/letter/2/b5e925/32.png) [@23141](https://discuss.elastic.co/u/23141)\
**Post date:** [November 21, 2018, 5:25pm UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758/1 "2018-11-21T17:25:01Z")

</div>

Hey,

I have an field in my documents called eventType and I want to get all the unique event types over a given time range. How can I achieve this?

```
curl -X GET "http://server:9200/_all/_search" -H 'Content-Type: application/json' -d'
{
  "size": 10000,
  "_source": ["level", "eventType"],  
  "aggs" : {
    "uniq_events" : {
        "terms" : { "field" : "eventType.keyword" }
    }
  },
  "query": {
    "match": { 
      "level": "WARN"
    }
  }
}
'

```

The above is what I have written but I can't filter by timestamp and size 10000 doesn't bring back all the unqiue records. Please help 🙂

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [November 22, 2018, 4:31am UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758/2 "2018-11-22T04:31:21Z")

</div>

As for the filter by timestamp, you should be able to do that with [a range query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#_date_format_in_range_queries).

Now, the answer to the other part of your question, it depends on exactly what you're trying to retrieve. As written, you query will return 10,000 documents with `level: WARN`, as well as the 10 keywords which occur most often across all documents which have `level: WARN`, which I suspect is not what you want.

Without knowing more exactly what you're trying to do, it's hard to make a specific recommendation, but if you want to retrieve all unique values, the [Composite aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-composite-aggregation.html) may be useful if `eventType.keyword` has a large number of unique values.

---

<div class="post-metadata">

**Author:** ![23141](https://avatars.discourse-cdn.com/v4/letter/2/b5e925/32.png) [@23141](https://discuss.elastic.co/u/23141)\
**Post date:** [November 22, 2018, 7:54pm UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758/3 "2018-11-22T19:54:49Z")

</div>

Hi @gbrown - thanks so much for trying to help.

I'm trying to get all the events ("eventType") for the past week. I played around with the sizes and realized the below is what I want.

```
curl -X GET "http://server:9200/_all/_search" -H 'Content-Type: application/json' -d'
{
  "size": 0,
  "_source": ["level", "eventType"],  
  "aggs" : {
    "uniq_events" : {
        "terms" : { "field" : "eventType.keyword" },
        "size": 1000
    }
  },
  "query": {
    "match": { 
      "level": "WARN"
    }
  }
}
'

```

As you mentioned

> As for the filter by timestamp, you should be able to do that with [a range query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#_date_format_in_range_queries).

I'm not sure how to do a filtered search while still want to match on warn

```
"query": {
    "match": { 
      "level": "WARN"
    }
  }

```

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [November 22, 2018, 8:09pm UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758/4 "2018-11-22T20:09:42Z")

</div>

Good to hear you figured out the aggregation you need! To combine the two queries, you'll need to use a [Bool Query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html). In your case, I think your query will end up looking something like this:

```auto
"query": {
  "bool": {
    "filter": [
      {"match": {"level": "WARN"}},
      {"range": {"timestamp": {"gte": "2018/1/1", "lte": "2018/1/31"}}}
    ]
  }
}

```

Although you may need to adjust the date format to match the format in your mapping.

---

<div class="post-metadata">

**Author:** ![23141](https://avatars.discourse-cdn.com/v4/letter/2/b5e925/32.png) [@23141](https://discuss.elastic.co/u/23141)\
**Post date:** [November 22, 2018, 9:28pm UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758/5 "2018-11-22T21:28:51Z")

</div>

me \<3 @gbrown  
Thanks for your help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2018, 9:28pm UTC](https://discuss.elastic.co/t/retrieving-all-the-unique-events/157758/6 "2018-12-20T21:28:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
