Create a search for IOCs

Trying to create a query search for IPs found in the last 24 hours.
I have been testing with:

GET /index/_search

  "query": {
    "match": {
      "event.category": "network"

POST /*index_name*/_async_search

  "query": {
    "range": {
      "@timestamp": {
        "gte": "now-24h",
        "lt": "now"
  "size": 10


POST /index_name*/_async_search?size=0
POST /index_name*/_async_search?wait_for_completion_timeout=200ms

  "query": {
    "range": {
      "@timestamp": {
        "gte": "now-24h",
        "lt": "now"
  "size": 10

I have also used GET /_search and POST /_search but in some cases Im able to get an id but the hits are 0. I can search for the id by using the: GET /_async_search/ but once again I get 0 for hits.

From Elastic Search to Elasticsearch

Removed elastic-app-search

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.