# Does doing a POST query via the devtools alter any elastic data or database?

**URL:** <https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936>\
**Category:** Elasticsearch\
**Created:** [April 19, 2026, 8:59am UTC](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936 "2026-04-19T08:59:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [April 19, 2026, 8:59am UTC](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936/1 "2026-04-19T08:59:08Z")

</div>

Its been brought to my attention that my post query is updating the database. I would like to seek clarification that such queries like below are purely querying instead of altering or updating any data in the elastics each database.

```auto
POST /_query?format=txt
{
  "query": """
  FROM .ml-notifications*
| WHERE (job_id) == "kibana-logs"
    AND message IN ("Datafeed stopped", "Job opened")
| LIMIT 10
    """
}

```

```auto
POST /_query?format=txt
{
  "query": """
  FROM ABCD:.monitoring-*
| WHERE @timestamp > NOW() - 8 hours
    AND (node_stats.process.cpu.percent) > 50
    OR (node_stats.jvm.mem.heap_used_percent) > 50
| STATS 
      process_cpu = AVG(node_stats.process.cpu.percent),
      jvm_mem = AVG(node_stats.jvm.mem.heap_used_percent),
      fs_avail = AVG(elasticsearch.node.stats.fs.total.available_in_bytes)
    BY elasticsearch.node.name
    EVAL fs_avail_gb = ROUND((TO_DOUBLE(fs_avail) / 1,073,741,824) * 100, 2)
| WHERE process_cpu > 50
| SORT process_cpu DESC
| LIMIT 100
    """
}

```

Also, how can I do an audit on who run what query that may update the database?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 19, 2026, 2:02pm UTC](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936/2 "2026-04-19T14:02:08Z")

</div>

> [@Whoami1980](#):
>
> Its been brought to my attention that my post query is updating the database. I would like to seek clarification that such queries like below are purely querying instead of altering or updating any data in the elastics each database

> Its been brought to my attention that my post query is updating the database.

What is the context for this? It is not correct.

None of the queries you shared will alter anything, they are only retrieving data.

To alter data you would need to use the `_update_by_query` or `_delete_by_query` endpoints and use a DSL query.

> [@Whoami1980](#):
>
> Also, how can I do an audit on who run what query that may update the database?

You would need to enable audit logs which requires a paid license, do you have one? If you have a platinum or enterprise license you can enable audit logs, but keep in mind that logging all queries being made can be pretty noisy and require a lot of space in your monitoring cluster.

---

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [April 28, 2026, 4:07am UTC](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936/3 "2026-04-28T04:07:00Z")

</div>

@leandrojmp

I was looking at the audit events it doesnt seems to show such events for `_update_by_query` or `_delete_by_query`

[Elasticsearch audit events | Elasticsearch Reference](https://www.elastic.co/docs/reference/elasticsearch/elasticsearch-audit-events)

Could you further elaborate on how this can be achieved? Thanks
