# Unable to match data, e.g. \`/service/${id}\`

**URL:** https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356
**Category:** Elasticsearch
**Created:** [March 20, 2020, 6:09am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356 "2020-03-20T06:09:50Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![LiuDui](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@LiuDui](https://discuss.elastic.co/u/LiuDui)
#### Post date: [March 20, 2020, 6:09am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356/1 "2020-03-20T06:09:50Z")

</div>

Dev Tools

```auto
GET http-log/kong/_search
{
  "query": {
    "match": {
      "request.uri": "/service"
    }
  }, 
  "size": 0, 
  "aggs": {
    "group": {
      "terms": {
        "field": "request.uri.keyword",
        "size": 20
      }
    }
  }
}

```

Output

```auto
  "aggregations": {
    "group": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "/service/3",
          "doc_count": 8
        },
        {
          "key": "/service/10",
          "doc_count": 6
        },
        {
          "key": "/service/26",
          "doc_count": 2
        },
        {
          "key": "/service/1",
          "doc_count": 1
        },
        {
          "key": "/service/2",
          "doc_count": 1
        }
      ]
    }
  }

```

The following `keys` are all log data `/service/${id}` generated by the same API, but they are divided into different keys and how do I match them together?

```auto
/service/3
/service/10
/service/26
/service/1
/service/2

```

---

<div class="post-metadata">

### Author: ![LiuDui](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@LiuDui](https://discuss.elastic.co/u/LiuDui)
#### Post date: [March 20, 2020, 6:12am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356/2 "2020-03-20T06:12:20Z")

</div>

Looking forward to your reply

---

<div class="post-metadata">

### Author: ![LiuDui](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@LiuDui](https://discuss.elastic.co/u/LiuDui)
#### Post date: [March 20, 2020, 6:14am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356/3 "2020-03-20T06:14:45Z")

</div>

Container deployment

```auto
docker.elastic.co/kibana/kibana:6.3.2
docker.elastic.co/elasticsearch/elasticsearch:6.3.2
OS: centos7

```

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [March 20, 2020, 9:20am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356/4 "2020-03-20T09:20:12Z")

</div>

Elasticsearch does not have the notion of grouping by default. There are two approaches to this. First, add another field in your indexing process that only indexes the first part of the URL (`/service/` in this case and then group by that one), second, use a script in the terms aggregation, that is only returning the first part of the URL. Note that this will be rather slow and is not recommended, when you execute this query often, but can help you to verify this idea.

Hope this helps!

---

<div class="post-metadata">

### Author: ![LiuDui](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@LiuDui](https://discuss.elastic.co/u/LiuDui)
#### Post date: [March 30, 2020, 9:40am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356/5 "2020-03-30T09:40:24Z")

</div>

> [@LiuDui](#):
>
> he following `keys` are all log data `/service/${id}` generated by the same API, but they are divided into different keys and how do I match them together?

thanks！

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 27, 2020, 9:40am UTC](https://discuss.elastic.co/t/unable-to-match-data-e-g-service-id/224356/6 "2020-04-27T09:40:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
