# How to do aggregation by API in 4.x

**URL:** <https://community.graylog.org/t/how-to-do-aggregation-by-api-in-4-x/21198>\
**Category:** Graylog Tech Challenges\
**Created:** [September 15, 2021, 1:10pm UTC](https://community.graylog.org/t/how-to-do-aggregation-by-api-in-4-x/21198 "2021-09-15T13:10:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bks](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/bks/32/9642_2.png) [@bks](https://community.graylog.org/u/bks)\
**Post date:** [September 15, 2021, 1:10pm UTC](https://community.graylog.org/t/how-to-do-aggregation-by-api-in-4-x/21198/1 "2021-09-15T13:10:27Z")

</div>

## Description of your problem

Get a better understanding of how to use View-API (/view/\*) that can be seen in the next picture  
I have not found a detailed documentation about the API, therefore I am unsure how to use.

 ![API-GL-4-x](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/bf31c679a69d3664613de92f7070b10109ddbc8d.png)

## How API was used in Version 3.3

In Graylog Version 3.3, I am using legacy aggregation api that is depracted in 4.x  
[https://docs.graylog.org/en/3.3/pages/upgrade/graylog-3.3.html#deprecating-legacy-aggregation-api-endpoints](https://docs.graylog.org/en/3.3/pages/upgrade/graylog-3.3.html#deprecating-legacy-aggregation-api-endpoints)

It is usful to automate and pull satistics based on certain fields, e. g. “counts for fieldname srccountry”  
See my following example.

```
```
curl -X GET "https://graylog.net:9000/api/search/universal/relative/terms?field=srccountry&query=streams%3A5c6feab5e3ef56000b1456fb&range=3600" | json_pp

   "terms" : {
      "Bosnia and Herzegovina" : 1,
      "Indonesia" : 1,
      "Germany" : 22,
      "Ireland" : 5,
      "Luxembourg" : 2,
      "Singapore" : 6,
      "Denmark" : 3,
      "Lithuania" : 1,
      "Korea, Republic of" : 1,
      "Russian Federation" : 38,
      "Brazil" : 1,
      "Hong Kong" : 3,
      "Romania" : 1,
      "Egypt" : 1,
      "Switzerland" : 1,
      "United Kingdom" : 8,
      "China" : 52,
      "United States" : 89,
      "Ukraine" : 85,
      "Bulgaria" : 2,
      "Netherlands" : 40,
      "Canada" : 1,
      "Reserved" : 1,
      "Chile" : 1,
      "Japan" : 6,
      "France" : 1
   }
```
```

Can anyone help, explain or provide an example how to use 4.x API to build my example from deprecated/legacy 3.3 API?

Many, many thanks!

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [September 17, 2021, 3:32am UTC](https://community.graylog.org/t/how-to-do-aggregation-by-api-in-4-x/21198/2 "2021-09-17T03:32:26Z")

</div>

Hello,  
To help us, help you better we would need some more information. Check out this post for a better understanding .

> [@How to Post a Question in the Community that Gets Responses](https://community.graylog.org/t/how-to-post-a-question-in-the-community-that-gets-responses/20879):
>
> This platform is made with love for community discussions on the open source tool Graylog, it components and usage. Here’s a Graylog support-inspired template (thank you, @aaronsachs ) that’ll get responses: Description of your problem \<!-- Use this section to describe the problem that you're encountering. Please include any screenshots or recordings of the problem you're running into.--\> Description of steps you’ve taken to attempt to solve the issue \<!-- Use this section to provide detailed…

Perhaps something in this post might help

> [@How to search messages using REST API](https://community.graylog.org/t/how-to-search-messages-using-rest-api/17943):
>
> I am trying to use REST API for searching through messages. I need to search message containing some string. I followed the document, created the token and able to access APIs. I dont know how exactly use this APIs. Should I need to create query first or something else? Can someone give me example endpoint so that I can search messages with any string.

> [@Graylog4 rest api search export](https://community.graylog.org/t/graylog4-rest-api-search-export/18727/4):
>
> he search via API is different in 4.0 and the documentation lacks behind … The “best” way currently is to use the export API: ## Search via Export API curl -X "POST" "https://graylog/api/views/search/messages" \ -H 'X-Requested-By: Mamamia' \ -H 'Content-Type: application/json' \ -H 'Accept: text/csv' \ -u 'USER:PASSWORD' \ -d $'{ "streams": ["5e569003c793163fea1b3373"], "query\_string": { "type": "elasticsearch", "query\_string": "section:boulder" …

---

<div class="post-metadata">

**Author:** ![bks](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/bks/32/9642_2.png) [@bks](https://community.graylog.org/u/bks)\
**Post date:** [September 21, 2021, 11:08am UTC](https://community.graylog.org/t/how-to-do-aggregation-by-api-in-4-x/21198/3 "2021-09-21T11:08:57Z")

</div>

Hi gsmith,

thanks for your feedback.

1. I’ll do better if posting a problem the next time!
2. Your hints have been helpfull. I managed to used API endpoint /views/search/sync

Many thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 5, 2021, 11:09am UTC](https://community.graylog.org/t/how-to-do-aggregation-by-api-in-4-x/21198/4 "2021-10-05T11:09:00Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
