# Curl query from json

**URL:** <https://discuss.elastic.co/t/curl-query-from-json/293650>\
**Category:** Elasticsearch\
**Created:** [January 6, 2022, 2:03pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650 "2022-01-06T14:03:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rusty\_cole](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Post date:** [January 6, 2022, 2:03pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650/1 "2022-01-06T14:03:04Z")

</div>

Hi guys,  
I have some query(witch works fine in kibana debugger), my goal is to make this query work from curl command line(windows). i have other queries with no issues.  
I think the problem is with the """ in the "reduce\_script" part. it breaks the json structure.  
The working query:

```auto
{
   "id":"index_compare",
   "source":{
      "index":[
         "mitre",
         "winlogbeat-7.14.0-2022.01.06-000001"
      ],
      "query":{
         "match_all":{
            
         }
      }
   },
   "dest":{
      "index":"compare"
   },
   "pivot":{
      "group_by":{
         "unique-id":{
            "terms":{
               "field":"winlog.event_id"
            }
         }
      },
      "aggregations":{
         "compare":{
            "scripted_metric":{
               "map_script":"state.doc = new HashMap(params['_source'])",
               "combine_script":"return state",
               "reduce_script":""" 
            if (states.size() != 2) {
return ""count_mismatch""
            }
return ""match""
            """
            }
         }
      }
   }
}

```

What i have tried:  
command :

```auto
curl -XPOST --header "Content-Type: application/json" "http://localhost:9200/_transform/_preview?pretty" -d @2.json

```

json file:

```auto
{
  "id": "index_compare",
  "source": {
    "index": [
      "mitre",
      "winlogbeat-7.14.0-2022.01.06-000001"
    ],
    "query": {
      "match_all": {}
    }
  },
  "dest": {
    "index": "compare"
  },
  "pivot": {
    "group_by": {
      "unique-id": {
        "terms": {
          "field": "winlog.event_id"
        }
      }
    },
    "aggregations": {
      "compare": {
        "scripted_metric": {
          "map_script": "state.doc = new HashMap(params['_source'])",
          "combine_script": "return state",
"reduce_script": """ 
            if (states.size() != 2) {
return "count_mismatch"
            }
return "match"
            """
        }
      }
    }
  }
}

```

Any ideas?

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [January 6, 2022, 2:27pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650/2 "2022-01-06T14:27:14Z")

</div>

If you are already using Kibana Dev Tools, you can click on the wrench icon for the request and toggle through the 'Auto indent' or use the 'Copy as cURL' option and it will format it as valid JSON for you to use. The triple double quotes are only usable in Dev Tools to help make things easily readable with CR/LF characters, etc.

You should end up with something like the following:  
`"reduce_script":" \n if (states.size() != 2) {\nreturn \"\"count_mismatch\"\"\n }\nreturn \"\"match\"\"\n "`

You could also clean that up even more if you wanted.

---

<div class="post-metadata">

**Author:** ![rusty\_cole](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Post date:** [January 6, 2022, 2:38pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650/3 "2022-01-06T14:38:27Z")

</div>

Hi angelo,  
Thanks for your response !  
I have just tried 2 things:

1. 'Copy as cURL from the wrench button - did not work - "Unrecognized character escape '''
2. replaced the reduce\_script with the string you suggested - also did not work. json parse exception.

Thanks again

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [January 6, 2022, 2:46pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650/4 "2022-01-06T14:46:29Z")

</div>

Can you post your updated version of your JSON file and any additional error details - ie: listing failing line or column number?

---

<div class="post-metadata">

**Author:** ![rusty\_cole](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Post date:** [January 6, 2022, 2:48pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650/5 "2022-01-06T14:48:57Z")

</div>

I got it working by only using the "reduce\_script" part from the wrench.  
Something is wrong with the escaping output from the wrench.  
The working request:

```auto
{
  "id": "index_compare",
  "source": {
    "index": [
      "mitre",
      "winlogbeat-7.14.0-2022.01.06-000001"
    ],
    "query": {
      "match_all": {}
    }
  },
  "dest": {
    "index": "compare"
  },
  "pivot": {
    "group_by": {
      "unique-id": {
        "terms": {
          "field": "winlog.event_id"
        }
      }
    },
    "aggregations": {
      "compare": {
        "scripted_metric": {
          "map_script": "state.doc = new HashMap(params['_source'])",
          "combine_script": "return state",
"reduce_script": " \r\n if (states.size() != 2) {\r\nreturn \"count_mismatch\"\r\n }\r\nreturn \"match\"\r\n "
        }
      }
    }
  }
}'

```

Thanks for your solution angelo !!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2022, 2:49pm UTC](https://discuss.elastic.co/t/curl-query-from-json/293650/6 "2022-02-03T14:49:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
