# Call Elastic API to get an info on a parameter

**URL:** <https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762>\
**Category:** Elasticsearch\
**Created:** [November 9, 2020, 1:32pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762 "2020-11-09T13:32:04Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Baptiste\_Orsoni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baptiste_orsoni/32/45225_2.png) [@Baptiste\_Orsoni](https://discuss.elastic.co/u/Baptiste_Orsoni)\
**Post date:** [November 9, 2020, 1:32pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/1 "2020-11-09T13:32:04Z")

</div>

Hello,

I would like to use the Elastic Search API in order to get information on a parameter I have in one of my index.

In concrete terms, I would like to know if there have been any hits for a particular client . ( parameter called "data.client") in the last 5 minutes calling the API.

I've made it this far:

```auto
    GET app-sms-smpp-serversmpp-prd-7.4.2-2020.11.09/_msearch
    {}
    { "query": { "match_phrase": { "smpp.serversmpp.data.client": "KDEV" } }}
    {}
    { "query": {
        "range": {
          "timestamp": {
            "time_zone": "+01:00",        
            "gte": "now-5m/m", 
            "lte": "now"                  
          }
        }
      }
    }

```

But looks like the multi search is not working, I have an error like :

```auto
 "error": {
        "root_cause": [
          {
            "type": "json_e_o_f_exception",
            "reason": "Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@5d626c59; line: 1, column: 13])\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@5d626c59; line: 1, column: 27]"

```

Thank you very much in advance for your help.

Best regards,

Baptiste

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 9, 2020, 6:43pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/2 "2020-11-09T18:43:10Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 9, 2020, 6:45pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/3 "2020-11-09T18:45:20Z")

</div>

You should try a simple `_search` using a `bool` query with a `must` array which contains a `term` query and a `range` query.

If you don't know how to do it, please share a minimal reproduction script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script is something anyone can copy and paste in Kibana dev console, click on the run button to reproduce your use case. It will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![Baptiste\_Orsoni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baptiste_orsoni/32/45225_2.png) [@Baptiste\_Orsoni](https://discuss.elastic.co/u/Baptiste_Orsoni)\
**Post date:** [November 10, 2020, 8:55am UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/4 "2020-11-10T08:55:40Z")

</div>

Hello @dadoonet

Thank you very much for your answer. Sorry for the bad formatting of my code. I corrected it.

---

<div class="post-metadata">

**Author:** ![Baptiste\_Orsoni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baptiste_orsoni/32/45225_2.png) [@Baptiste\_Orsoni](https://discuss.elastic.co/u/Baptiste_Orsoni)\
**Post date:** [November 10, 2020, 9:05am UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/5 "2020-11-10T09:05:57Z")

</div>

@dadoonet, please see the full reproduction script I wrote after following your advice:

```auto
GET /app-sms-smpp-serversmpp-prd-7.4.2-2020.11.09/_search
{
  "query": {
    "bool": {
      "must": [
      {
        "term": {
          "smpp.serversmpp.data.client": {
          "value": "KDEV"
          }
        }
      },
      {
        "range": {
          "timestamp": {
            "time_zone": "+01:00",        
            "gte": "now-5m/m", 
            "lte": "now"
          }
        }
      }
      ]
    } 
  }

```

It's seems to work, but I don't get any hits in response :

```auto
  "hits" : {
    "total" : {
      "value" : 0,

```

whereas when I check on the discover panel I can clearly see that there are some hits for this client in the last 5 minutes.

Do you know where this problem could come from?

Thanks very much in advance.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 10, 2020, 9:16am UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/6 "2020-11-10T09:16:42Z")

</div>

It depends on your mapping.

May be try with `kdev` instead of `KDEV`.

But that might not work for all your customers. In which case you should change the mapping and use a `keyword` datatype.

---

<div class="post-metadata">

**Author:** ![Baptiste\_Orsoni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baptiste_orsoni/32/45225_2.png) [@Baptiste\_Orsoni](https://discuss.elastic.co/u/Baptiste_Orsoni)\
**Post date:** [November 10, 2020, 10:05am UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/7 "2020-11-10T10:05:17Z")

</div>

I've tried `kdev` , not working. I've checked the mapping, and a `keyword` datatype is already used for the data.client :

```auto
"data" : {
                  "properties" : {
                    "client" : {
                      "type" : "keyword",
                      "ignore_above" : 1024

```

Can this be related to the fact that we use in our company the free basic version of Elastic Stack ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 10, 2020, 10:49am UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/8 "2020-11-10T10:49:50Z")

</div>

> [@Baptiste\_Orsoni](#):
>
> Can this be related to the fact that we use in our company the free basic version of Elastic Stack ?

Absolutely not.

The only way to debug this is by reproducing your error. So please provide a script as I mentioned earlier.  
A script is something we can copy/paste in Kibana dev console and reproduce the problem.

In the meantime, you can try few things to check where the error is coming from.  
Run:

```auto
GET /app-sms-smpp-serversmpp-prd-7.4.2-2020.11.09/_search
{
  "query": {
    "bool": {
      "must": [
      {
        "term": {
          "smpp.serversmpp.data.client": {
          "value": "KDEV"
          }
        }
        }
      }
      ]
    } 
  }

```

And

```auto
GET /app-sms-smpp-serversmpp-prd-7.4.2-2020.11.09/_search
{
  "query": {
    "bool": {
      "must": [
      {
        "range": {
          "timestamp": {
            "time_zone": "+01:00",        
            "gte": "now-5m/m", 
            "lte": "now"
          }
        }
      }
      ]
    } 
  }

```

And share the output for all.

Also may be remove the `time_zone` part. It might not have the effect you think.

---

<div class="post-metadata">

**Author:** ![Baptiste\_Orsoni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baptiste_orsoni/32/45225_2.png) [@Baptiste\_Orsoni](https://discuss.elastic.co/u/Baptiste_Orsoni)\
**Post date:** [November 10, 2020, 2:45pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/9 "2020-11-10T14:45:22Z")

</div>

Thanks very much for your help, I've found the problem, this part :

> [@dadoonet](#):
>
> And

was the origin of the problem only because an `@` was missing in `@timestamp`.

It's working now but there now another problem :  
When I run my script at 15:31 for example, I'm only getting hits that have a `@timestamp` during the 15:26 minute, (31-5 = 26) but I don't get any hits between 15:26 and 15:31. It should be related to

```auto
          "timestamp": {      
            "gte": "now-5m/m", 
            "lte": "now"

```

but I don't know what is not correct with this. I'll check again the documentation about date range but if you have any idea of what could be the problem I would be glad to hear it.

Thank you

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 10, 2020, 4:37pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/10 "2020-11-10T16:37:04Z")

</div>

Again:

> The only way to debug this is by reproducing your error. So please provide a script as I mentioned earlier.  
> A script is something we can copy/paste in Kibana dev console and reproduce the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2020, 4:37pm UTC](https://discuss.elastic.co/t/call-elastic-api-to-get-an-info-on-a-parameter/254762/11 "2020-12-08T16:37:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
