# API to query elastic search data

**URL:** <https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359>\
**Category:** Elasticsearch\
**Created:** [February 24, 2017, 6:48am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359 "2017-02-24T06:48:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![agrawalsaurabh](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@agrawalsaurabh](https://discuss.elastic.co/u/agrawalsaurabh)\
**Post date:** [February 24, 2017, 6:48am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/1 "2017-02-24T06:48:20Z")

</div>

Hi,

I have been able to set up Filebeat, Logstash, ES to read the Apache logs and index it in ES. I, however, want to leverage indexed data to build some sort of analytics.

For instance; how many requests came from a specific IP in last 30 minutes, etc.

Does ES provide some API which we can leverage to query the indexed data?

Saurabh

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 7:16am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/2 "2017-02-24T07:16:53Z")

</div>

Why not use Kibana?

---

<div class="post-metadata">

**Author:** ![agrawalsaurabh](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@agrawalsaurabh](https://discuss.elastic.co/u/agrawalsaurabh)\
**Post date:** [February 24, 2017, 7:21am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/3 "2017-02-24T07:21:08Z")

</div>

I have set up kibana also but will it allow putting logic around logs.

For instance; consider the following use cases:

1. Show a graph depicting requests coming from IPs. Example: IP0001 15 requests, so on and so forth
2. Display time taken by requests in last 1 hour

Also we would like to show a dashboard to our dev ops. team to monitor all these scenarios.

Can we achieve this in kibana?

Saurabh

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 7:21am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/4 "2017-02-24T07:21:30Z")

</div>

Yes, that is the whole premise of it 🙂

---

<div class="post-metadata">

**Author:** ![agrawalsaurabh](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@agrawalsaurabh](https://discuss.elastic.co/u/agrawalsaurabh)\
**Post date:** [February 24, 2017, 7:24am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/5 "2017-02-24T07:24:28Z")

</div>

In Kibana, i see my data under "DISCOVER" option only and that too in a simple raw form, the same way I see it in log files.

My intent is to get more meaninful data and apply aggregation on top of it which I am not sure how to do it.

can you point me to resource or guide me on how to achieve it?

Thanks.  
Saurabh

---

<div class="post-metadata">

**Author:** ![avr](https://avatars.discourse-cdn.com/v4/letter/a/c77e96/32.png) [@avr](https://discuss.elastic.co/u/avr)\
**Post date:** [February 24, 2017, 7:37am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/6 "2017-02-24T07:37:45Z")

</div>

@agrawalsaurabh Hope the following URL will help you to play around with Kibana!  
[https://www.elastic.co/guide/en/kibana/current/createvis.html#createvis](https://www.elastic.co/guide/en/kibana/current/createvis.html#createvis)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 7:43am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/7 "2017-02-24T07:43:49Z")

</div>

Have a read of [https://www.elastic.co/guide/en/kibana/current/index.html](https://www.elastic.co/guide/en/kibana/current/index.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2017, 7:44am UTC](https://discuss.elastic.co/t/api-to-query-elastic-search-data/76359/8 "2017-03-24T07:44:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
