--- aliases: - ../../data-sources/elasticsearch/template-variables/ description: Using template variables with Elasticsearch in Grafana keywords: - grafana - elasticsearch - templates - variables - queries labels: products: - cloud - enterprise - oss menuTitle: Template variables title: Elasticsearch template variables weight: 400 refs: variables: - pattern: /docs/grafana/ destination: /docs/grafana//dashboards/variables/ - pattern: /docs/grafana-cloud/ destination: /docs/grafana//dashboards/variables/ add-template-variables-add-ad-hoc-filters: - pattern: /docs/grafana/ destination: /docs/grafana//dashboards/variables/add-template-variables/#add-ad-hoc-filters - pattern: /docs/grafana-cloud/ destination: /docs/grafana//dashboards/variables/add-template-variables/#add-ad-hoc-filters add-template-variables-multi-value-variables: - pattern: /docs/grafana/ destination: /docs/grafana//dashboards/variables/add-template-variables/#multi-value-variables - pattern: /docs/grafana-cloud/ destination: /docs/grafana//dashboards/variables/add-template-variables/#multi-value-variables add-template-variables: - pattern: /docs/grafana/ destination: /docs/grafana//dashboards/variables/add-template-variables/ - pattern: /docs/grafana-cloud/ destination: /docs/grafana//dashboards/variables/add-template-variables/ --- # Elasticsearch template variables Instead of hard-coding details such as server, application, and sensor names in metric queries, you can use variables. Grafana lists these variables in drop-down select boxes at the top of the dashboard to help you change the data displayed in your dashboard. Grafana refers to such variables as template variables. For an introduction to templating and template variables, refer to the [Templating](ref:variables) and [Add and manage variables](ref:add-template-variables) documentation. ## Use ad hoc filters Elasticsearch supports the **Ad hoc filters** variable type. You can use this variable type to specify any number of key/value filters, and Grafana applies them automatically to all of your Elasticsearch queries. Ad hoc filters support the following operators: | Operator | Description | | -------- | ------------------------------------------------------------- | | `=` | Equals. Adds `AND field:"value"` to the query. | | `!=` | Not equals. Adds `AND -field:"value"` to the query. | | `=~` | Matches regex. Adds `AND field:/value/` to the query. | | `!~` | Does not match regex. Adds `AND -field:/value/` to the query. | | `>` | Greater than. Adds `AND field:>value` to the query. | | `<` | Less than. Adds `AND field:}} In the above example, a Lucene query filters documents based on the `hostname` property using a variable named `$hostname`. The example also uses a variable in the _Terms_ group by field input box, which you can use to quickly change how data is grouped. ## Create a query Write the query using a custom JSON string, with the field mapped as a [keyword](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html#keyword) in the Elasticsearch index mapping. If the query is [multi-field](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html) with both a `text` and `keyword` type, use `"field":"fieldname.keyword"` (sometimes `fieldname.raw`) to specify the keyword field in your query. | Query | Description | | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | | `{"find": "fields", "type": "keyword"}` | Returns a list of field names with the index type `keyword`. | | `{"find": "fields", "type": "number"}` | Returns a list of numeric field names (includes `float`, `double`, `integer`, `long`, `scaled_float`). | | `{"find": "fields", "type": "date"}` | Returns a list of date field names. | | `{"find": "terms", "field": "hostname.keyword", "size": 1000}` | Returns a list of values for a keyword field. Uses the current dashboard time range. | | `{"find": "terms", "field": "hostname", "query": ""}` | Returns a list of values filtered by a Lucene query. Uses the current dashboard time range. | | `{"find": "terms", "field": "status", "orderBy": "doc_count"}` | Returns values sorted by document count (descending by default). | | `{"find": "terms", "field": "status", "orderBy": "doc_count", "order": "asc"}` | Returns values sorted by document count in ascending order. | Queries of `terms` have a 500-result limit by default. To set a custom limit, set the `size` property in your query. ### Sort query results By default, queries return results in term order (which can then be sorted alphabetically or numerically using the variable's Sort setting). To produce a list of terms sorted by document count (a top-N values list), add an `orderBy` property of `doc_count`. This automatically selects a descending sort: ```json { "find": "terms", "field": "status", "orderBy": "doc_count" } ``` You can also use the `order` property to explicitly set ascending or descending sort: ```json { "find": "terms", "field": "hostname", "orderBy": "doc_count", "order": "asc" } ``` {{< admonition type="note" >}} Elasticsearch [discourages](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-order) sorting by ascending doc count because it can return inaccurate results. {{< /admonition >}} To keep terms in the document count order, set the variable's Sort drop-down to **Disabled**. You can alternatively use other sorting criteria, such as **Alphabetical**, to re-sort them.