# CSV Response Data Format from SQL Rest API

**URL:** <https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224>\
**Category:** Elasticsearch\
**Created:** [May 11, 2023, 3:45pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224 "2023-05-11T15:45:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akaash\_Mukherjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akaash_mukherjee/32/119513_2.png) [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Post date:** [May 11, 2023, 3:45pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224/1 "2023-05-11T15:45:22Z")

</div>

Hi, I was told in a previous post: that Elasticsearch cannot return csv as response data:

> [@Return JSON Array of Arrays from elastic](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971):
>
> Hi, We've noticed that the overhead of the JSON object structure is creating some performance problems for us. One of the largest parts of this overhead is the repetitiveness of the object properties in each object. We'd like to see if it's possible to retrieve data from Elasticsearch as a JSON array of arrays instead of array of objects. Any insight would be greatly appreciated. The example below is what we'd like to do, in this example the object properties are not listed, we would have some…

Then I found this:

> **[Response Data Formats | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-rest-format.html)**

I've been trying to play around with it, but must admit I'm a little lost.

I have a Kibana query that looks like this:

```auto
GET transactions/_search
{
  "query":{
      "bool":{
        "filter":[
          {"term":{"elastic_tag_subdomain" : "utilizetestdev"}},
          {"term":{"elastic_tag_module": "invoice"}}
        ]
      }
  }
}

```

I was wondering if/how it would be possible to use the SQL Rest API to return the exact same result. If that's possible, I assume I would need to change the format from format=json to format=csv.

Thanks for any and all help

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 11, 2023, 5:24pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224/2 "2023-05-11T17:24:15Z")

</div>

Yes ... please look at the docs and try 🙂

There is a nice example [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-getting-started.html)

Example I loaded the sample web logs which comes with every elasticsearch installation

```auto
POST /_sql?format=csv
{
  "query": "SELECT host, clientip, url FROM kibana_sample_data_logs WHERE host = 'www.elastic.co' AND url = 'https://www.elastic.co/downloads/apm' LIMIT 15"
}

# Result
host,clientip,url
www.elastic.co,184.19.167.161,https://www.elastic.co/downloads/apm
www.elastic.co,104.32.0.154,https://www.elastic.co/downloads/apm
www.elastic.co,4.167.5.34,https://www.elastic.co/downloads/apm
www.elastic.co,190.234.218.253,https://www.elastic.co/downloads/apm
www.elastic.co,157.4.76.38,https://www.elastic.co/downloads/apm
www.elastic.co,96.199.208.145,https://www.elastic.co/downloads/apm
www.elastic.co,23.203.186.61,https://www.elastic.co/downloads/apm
www.elastic.co,187.105.79.140,https://www.elastic.co/downloads/apm
www.elastic.co,255.205.14.152,https://www.elastic.co/downloads/apm
www.elastic.co,198.72.109.109,https://www.elastic.co/downloads/apm
www.elastic.co,1.149.149.212,https://www.elastic.co/downloads/apm
www.elastic.co,215.67.92.140,https://www.elastic.co/downloads/apm
www.elastic.co,187.55.100.154,https://www.elastic.co/downloads/apm
www.elastic.co,243.233.91.124,https://www.elastic.co/downloads/apm
www.elastic.co,179.153.116.46,https://www.elastic.co/downloads/apm

```

Results

and translate so you can see...

```auto
POST /_sql/translate
{
  "query": "SELECT host, clientip, url FROM kibana_sample_data_logs WHERE host = 'www.elastic.co' AND url = 'https://www.elastic.co/downloads/apm' LIMIT 15"
}

# Result

{
  "size": 15,
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "host.keyword": {
              "value": "www.elastic.co"
            }
          }
        },
        {
          "term": {
            "url.keyword": {
              "value": "https://www.elastic.co/downloads/apm"
            }
          }
        }
      ],
      "boost": 1
    }
  },
  "_source": false,
  "fields": [
    {
      "field": "host"
    },
    {
      "field": "clientip"
    },
    {
      "field": "url"
    }
  ],
  "sort": [
    {
      "_doc": {
        "order": "asc"
      }
    }
  ],
  "track_total_hits": -1
}

```

---

<div class="post-metadata">

**Author:** ![Akaash\_Mukherjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akaash_mukherjee/32/119513_2.png) [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Post date:** [May 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224/3 "2023-05-12T14:20:12Z")

</div>

Ok great! I'll try this out and let you know, thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2023, 2:20pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224/4 "2023-06-09T14:20:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
