# Return a set of values only on the first occurrence of one of them

**URL:** <https://discuss.elastic.co/t/return-a-set-of-values-only-on-the-first-occurrence-of-one-of-them/157239>\
**Category:** Elasticsearch\
**Created:** [November 18, 2018, 6:31pm UTC](https://discuss.elastic.co/t/return-a-set-of-values-only-on-the-first-occurrence-of-one-of-them/157239 "2018-11-18T18:31:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dany1](https://avatars.discourse-cdn.com/v4/letter/d/f04885/32.png) [@Dany1](https://discuss.elastic.co/u/Dany1)\
**Post date:** [November 18, 2018, 6:31pm UTC](https://discuss.elastic.co/t/return-a-set-of-values-only-on-the-first-occurrence-of-one-of-them/157239/1 "2018-11-18T18:31:02Z")

</div>

Hi all,

I use the latest ES version. My data set is a network flow (see an exemple below). Each time a new host starts a flow with one other, a new and unique flow\_id is created. I would like to write an Elasticsearch request so I can grab for instance the dest\_ip and the dest\_port only at when the flow\_id first appears in time. So my final answer would be for instance:  
flow\_id1 =\> dest\_ip1 =\> dest\_port1  
flow\_id2 =\> dest\_ip2 =\> dest port 2  
but not  
flow\_id1 =\> dest\_ip1 =\> dest\_port1  
flow\_id2 =\> dest\_ip2 =\> dest\_port2  
flow\_id1 =\> dest\_ip1 =\> dest\_port2  
How could I manage this? I need this to be able to get the first set of values of the flow\_id, and no the ones appearing later.

In SQL I would be doing SELECT dest\_ip, dest\_port, distinct flow\_id FROM index ORDER BY timestamp.

For the moment I did this, but I'm not sure it's the best way. How can I return other fields (dest\_ip, dest\_port) with flow\_id?

```
GET index-*/_search
{
  "size": 0,
  "aggs": {
    "2": {
      "terms": {
        "field": "flow_id",
        "size": 150,
        "order": {
          "_key": "asc"
        }
      },
      "aggs": {
        "1": {
          "top_hits": {
            "docvalue_fields": [
              "flow_id"
            ],
            "_source": "error",
            "size": 1,
            "sort": [
              {
                "timestamp": {
                  "order": "asc"
                }
              }
            ]
          }
        }
      }
    }
  }
}

```

Index pattern example:

```
{
  "_index": "index-2018-11-17",
  "_type": "doc",
  "_id": "h3qeIGcBeUNSQc4lIwrI",
  "_version": 1,
  "_score": null,
  "_source": {
    "proto": "UDP",
    "@version": "1",
    "dest_ip": "192.168.0.15",
    "@timestamp": "2018-11-17T07:41:33.923Z",
    "dest_port": 49328,
    "in_iface": "wlp2s0",
    "timestamp": "2018-11-17T08:41:33.778296+0100",
    "flow_id": 1026861285856324,
    "event_type": "dns",
    "dns": {
      "type": "answer",
      "rrtype": "SOA",
      "id": 56358,
      "rcode": "NOERROR",
      "rrname": "elastic.co",
      "ttl": 10183
    },
    "host": "xxx",
    "src_ip": "XX.2.0.1",
    "src_port": 53
  },
  "fields": {
    "@timestamp": [
      "2018-11-17T07:41:33.923Z"
    ],
    "timestamp": [
      "2018-11-17T07:41:33.778Z"
    ]
  },
  "sort": [
    1542440493923
  ]
}
```

---

<div class="post-metadata">

**Author:** ![Dany1](https://avatars.discourse-cdn.com/v4/letter/d/f04885/32.png) [@Dany1](https://discuss.elastic.co/u/Dany1)\
**Post date:** [November 19, 2018, 8:49pm UTC](https://discuss.elastic.co/t/return-a-set-of-values-only-on-the-first-occurrence-of-one-of-them/157239/2 "2018-11-19T20:49:55Z")

</div>

Finally got it by:

```
GET index-*/_search
{
  "size": 0,
  "aggs": {
    "2": {
      "terms": {
        "field": "flow_id",
        "size": 150,
        "order": {
          "_key": "asc"
        }
      },
      "aggs": {
        "1": {
          "top_hits": {
            "docvalue_fields": [
              "flow_id","src_ip.keyword", "dest_ip.keyword" 
            ],
            "_source": "error",
            "size": 1,
            "sort": [
              {
                "timestamp": {
                  "order": "asc"
                }
              }
            ]
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2018, 8:49pm UTC](https://discuss.elastic.co/t/return-a-set-of-values-only-on-the-first-occurrence-of-one-of-them/157239/3 "2018-12-17T20:49:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
