# A very simple query with CURL from a Windows box

**URL:** <https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339>\
**Category:** Elasticsearch\
**Created:** [April 5, 2016, 7:45am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339 "2016-04-05T07:45:34Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ameconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameconi/32/8999_2.png) [@ameconi](https://discuss.elastic.co/u/ameconi)\
**Post date:** [April 5, 2016, 7:45am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/1 "2016-04-05T07:45:34Z")

</div>

Hello all.  
I’m a beginner so start with a very simple question about searching.  
A customer of mine is running an ELK solution to collect Netflow packets coming from Cisco devices.  
I try to search using the CURL tool from a Windows box to the remote system. I need to extract flows where an IP address is source or destination but I’m unable to create a correct boolean search starting from an example on documentation (Elasticsearch 2.2).  
This makes me crazy!  
Thanks for understanding.  
Andrea

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 8, 2016, 7:15am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/2 "2016-04-08T07:15:24Z")

</div>

If you show us what you have so far it'll be easier to help.

---

<div class="post-metadata">

**Author:** ![ameconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameconi/32/8999_2.png) [@ameconi](https://discuss.elastic.co/u/ameconi)\
**Post date:** [April 8, 2016, 10:32am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/3 "2016-04-08T10:32:06Z")

</div>

Good morning Magnus.  
I believe I need to create a URI search.  
I need to select all packets where a specific IP is source or destination address starting from this basic working search

curl '[http://localhost:9200/logstash\_netflow5-\*/\_search?q=netflow.ipv4\_dst\_addr:10.0.0.2&pretty=true](http://localhost:9200/logstash_netflow5-*/_search?q=netflow.ipv4_dst_addr:10.0.0.2&pretty=true)'

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 8, 2016, 10:38am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/4 "2016-04-08T10:38:35Z")

</div>

Okay. And in what way doesn't this work? Do you get too many documents? Or too few?

---

<div class="post-metadata">

**Author:** ![ameconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameconi/32/8999_2.png) [@ameconi](https://discuss.elastic.co/u/ameconi)\
**Post date:** [April 8, 2016, 11:43am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/5 "2016-04-08T11:43:46Z")

</div>

This is an example. I need to create a query with a boolean OR.

netflow.ipv4\_dst\_addr:10.0.0.2 OR netflow.ipv4\_src\_addr:10.0.0.2

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 8, 2016, 11:58am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/6 "2016-04-08T11:58:20Z")

</div>

I repeat: What doesn't work? Do you get too many documents? Or too few?

---

<div class="post-metadata">

**Author:** ![ameconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameconi/32/8999_2.png) [@ameconi](https://discuss.elastic.co/u/ameconi)\
**Post date:** [April 8, 2016, 12:02pm UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/7 "2016-04-08T12:02:17Z")

</div>

I'm not able to create the correct query Magnus.

---

<div class="post-metadata">

**Author:** ![ameconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameconi/32/8999_2.png) [@ameconi](https://discuss.elastic.co/u/ameconi)\
**Post date:** [April 15, 2016, 9:53am UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/8 "2016-04-15T09:53:07Z")

</div>

Solved. Simply use the Boolean operator OR.  
Thanks for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:58pm UTC](https://discuss.elastic.co/t/a-very-simple-query-with-curl-from-a-windows-box/46339/9 "2017-07-05T22:58:59Z")

</div>


