# Search syntax to provide unique values for a single field in the result set

**URL:** <https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892>\
**Category:** Kibana\
**Created:** [August 1, 2016, 1:17pm UTC](https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892 "2016-08-01T13:17:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeremy\_Colton](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@Jeremy\_Colton](https://discuss.elastic.co/u/Jeremy_Colton)\
**Post date:** [August 1, 2016, 1:17pm UTC](https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892/1 "2016-08-01T13:17:30Z")

</div>

I'm trying to find all countries whose users visited a specific website. My ES document has 'publisherDomain' and 'geoip.country\_name'.

So far I have:

```
GET /logstash-*/_search?size=100
{
  "query": {     
    "match": {
      "publisherDomain": "mysite.com"
    }
  }
}

```

How do I filter the results to only include the 'geoip.country\_code' values?

Many thanks.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 1, 2016, 8:34pm UTC](https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892/2 "2016-08-01T20:34:43Z")

</div>

_As this more of an Elasticsearch question than Kibana, I'm moving it to the Elasticsearch category. If there is a followup Kibana question to this, feel free to move it to the Kibana category at that time._

If I understand your question correctly, you want the resulting `hits` in the response to only show the `geoip.country_code` field (as opposed to all the fields under `_source`. To do this you can use [source filtering](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-request-source-filtering.html) to only include the `geoip.country_code` field in the results.

Of course, this would give you _all_ values in the `geoip.country_code`, as opposed to just the unique ones. If you want unique ones you can use the [terms aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html) on the `geoip.country_code` field. Note that, in this case, you might as well specify [`size` as 0](https://www.elastic.co/guide/en/elasticsearch/reference/current/returning-only-agg-results.html) as the unique list of terms you are looking for will be in the `aggregations` section of the response, not the `hits` section.

---

<div class="post-metadata">

**Author:** ![Jeremy\_Colton](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@Jeremy\_Colton](https://discuss.elastic.co/u/Jeremy_Colton)\
**Post date:** [August 1, 2016, 9:53pm UTC](https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892/3 "2016-08-01T21:53:31Z")

</div>

Thanks for your reply. I have your first option working but getting unique string values is much better as you suggested. I have checked the aggregrations link you provided and have this so far:

```
GET /logstash-*/_search?size=100
{
  "_source": "geoip.country_name",
  "query": {     
    "match": {
      "publisherDomain": "fashionseoul.com"
    }
  },
  "aggs" : {
        "genres" : {
            "terms" : { "field" : "geoip.country_code" }
        }
    }
}

```

But it doesn't aggregate the results. How do I combine the filter in the 'aggs'?

I also tried the simpler:

```
GET /logstash-*/_search?
{
  "_source": "geoip.country_name",
    "aggs" : {
        "genres" : {
            "terms" : { "field" : "geoip.country_code" }
        }
    }
}

```

Again, this does not aggregate anything! All the results are under 'hits' and nothing is under 'aggregations'. What am i missing?

Many thanks.

---

<div class="post-metadata">

**Author:** ![Jeremy\_Colton](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@Jeremy\_Colton](https://discuss.elastic.co/u/Jeremy_Colton)\
**Post date:** [August 2, 2016, 8:32am UTC](https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892/4 "2016-08-02T08:32:37Z")

</div>

@shaunak I managed to get it working with this:

```
GET /logstash-*/_search?search_type=count
{
	"size": 0,
	"query": {
		"filtered": {
			"query": {
				"query_string": {
					"query": "publisherDomain:mysite.com",
					"analyze_wildcard": true
				}
			}
		}
	},
	"aggs": {
		"domains": {
			"terms": {
				"field": "geoip.country_name.raw",
			  "size": 5,
				"order": {
					"_count": "desc"
				}
			}
		}
	}
}

```

Please let me know if you think it can be improved.

Many thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/search-syntax-to-provide-unique-values-for-a-single-field-in-the-result-set/56892/5 "2017-07-06T13:42:28Z")

</div>


