# Retrieving 'Quick Values' using the API

**URL:** <https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772>\
**Category:** Graylog Central (peer support)\
**Created:** [July 18, 2017, 3:01pm UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772 "2017-07-18T15:01:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![steven.cherry](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/steven.cherry/32/3148_2.png) [@steven.cherry](https://community.graylog.org/u/steven.cherry)\
**Post date:** [July 18, 2017, 3:01pm UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772/1 "2017-07-18T15:01:43Z")

</div>

In the web UI once a search has been performed it’s then possible to expand any of the fields and select ‘Quick Values’ which lists the relative percentage of the field values found in the search. Is it possible to do the same using the API?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![derPhlipsi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/derphlipsi/32/38_2.png) [@derPhlipsi](https://community.graylog.org/u/derPhlipsi)\
**Post date:** [July 18, 2017, 3:33pm UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772/2 "2017-07-18T15:33:44Z")

</div>

Hey @steven.cherry,

have a look at the terms/ entpoint in the API-Browser, that is what you want (this is actually the API-endpoint the Quick Value Widget is using 😃

Greeting - Phil

---

<div class="post-metadata">

**Author:** ![steven.cherry](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/steven.cherry/32/3148_2.png) [@steven.cherry](https://community.graylog.org/u/steven.cherry)\
**Post date:** [July 18, 2017, 3:43pm UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772/3 "2017-07-18T15:43:13Z")

</div>

Hi @derPhlipsi

Thanks for the reply, I’ve already looked at the API browser but without success 🙁

---

<div class="post-metadata">

**Author:** ![derPhlipsi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/derphlipsi/32/38_2.png) [@derPhlipsi](https://community.graylog.org/u/derPhlipsi)\
**Post date:** [July 18, 2017, 4:34pm UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772/4 "2017-07-18T16:34:37Z")

</div>

Oh, I see…  
I guess it is under the **Search/\*** endpoint, because that is where the request goes when a Quick Value Widget is created. I can’t check, my API-Browser is broken for some reason 😕

Well, here is what I (once) found out about the terms/ endpoint by using the Firefox Network Console:

Query URL: `https://graylog.example.de/api/search/universal/relative/terms?query=action%3Aallow&range=300&field=application`  
(Note: %3A is URL-encoded for colon)

This is the response:

```auto
HTTP/1.1 200 OK
Server: nginx/1.10.3
Date: Tue, 18 Jul 2017 15:55:22 GMT
Content-Type: application/json
Content-Length: 2412
Connection: keep-alive
X-Graylog-Node-ID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Cache-Control: no-cache
X-Runtime-Microseconds: 1056418
Strict-Transport-Security: max-age=31536000

{
	"time": 1042,
	"terms": {
		"ssl": 16733,
                <redacted>
		"dns": 6222,
		"web-browsing": 3927,
		"apt-get": 6
	},
	"missing": 0,
	"other": 81,
	"total": 34440,
	"built_query": "{
		"from": 0,
		"query": {
			"bool": {
				"must": {
					"query_string": {
						"query": "action: allow",
						"allow_leading_wildcard": false
					}
				},
				"filter": {
					"bool": {
						"must": {
							"range": {
								"timestamp": {
									"from": "2017-07-1815: 50: 21.249",
									"to": "2017-07-1815: 55: 21.249",
									"include_lower": true,
									"include_upper": true
								}
							}
						}
					}
				}
			}
		},
		"aggregations": {
			"gl2_filter": {
				"filter": {
					"bool": {
						"must": {
							"range": {
								"timestamp": {
									"from": "2017-07-1815: 50: 21.249",
									"to": "2017-07-1815: 55: 21.249",
									"include_lower": true,
									"include_upper": true
								}
							}
						}
					}
				},
				"aggregations": {
					"gl2_terms": {
						"terms": {
							"field": "application",
							"size": 50,
							"order": {
								"_count": "desc"
							}
						}
					},
					"missing": {
						"missing": {
							"field": "application"
						}
					}
				}
			}
		}
	}"
}

```

This is basically how to use the terms endpoint. Just give it a query, a (time)range, and a field to aggregate on in the url and it will return you the terms object in the response-JSON. 🙂

I hope this helped 🙂

Greetings - Phil

---

<div class="post-metadata">

**Author:** ![steven.cherry](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/steven.cherry/32/3148_2.png) [@steven.cherry](https://community.graylog.org/u/steven.cherry)\
**Post date:** [July 19, 2017, 8:49am UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772/5 "2017-07-19T08:49:59Z")

</div>

Thanks Philipp, that worked for me 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 2, 2017, 8:49am UTC](https://community.graylog.org/t/retrieving-quick-values-using-the-api/1772/6 "2017-08-02T08:49:59Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
