# DSL query from investigate timeline

**URL:** <https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997>\
**Category:** Elastic Security\
**Created:** [July 12, 2024, 6:57am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997 "2024-07-12T06:57:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vhs](https://avatars.discourse-cdn.com/v4/letter/v/58f4c7/32.png) [@vhs](https://discuss.elastic.co/u/vhs)\
**Post date:** [July 12, 2024, 6:57am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/1 "2024-07-12T06:57:32Z")

</div>

Please tell me, is it possible to take information from the "investigate in timeline" elastic security alert, which is located in the Inspect-\>Request tab?

Or maybe it is possible to universally convert the request received from /api/detection\_engine/signals/search to DSL?

---

<div class="post-metadata">

**Author:** ![Jatin\_Kathuria](https://avatars.discourse-cdn.com/v4/letter/j/d6d6ee/32.png) [@Jatin\_Kathuria](https://discuss.elastic.co/u/Jatin_Kathuria)\
**Post date:** [July 12, 2024, 8:26am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/2 "2024-07-12T08:26:10Z")

</div>

Yes, check for the `query` key in the `Inspect -> Request` tab. It is query dsl only.

For example if you see below in timeline tab. It is QueryDSL and can be used as is.

Let me know if you wanted to ask something else.

```json
{
  "aggregations": {
    "producers": {
      "terms": {
        "field": "kibana.alert.rule.producer",
        "exclude": [
          "alerts"
        ]
      }
    }
  },
  "query": {
    "bool": {
      "filter": [
        {
          "bool": {
            "must": [],
            "filter": [
              {
                "query_string": {
                  "query": "*"
                }
              }
            ],
            "should": [],
            "must_not": []
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "2024-04-18T12:26:40.838Z",
              "lte": "2024-07-11T12:26:28.838Z",
              "format": "strict_date_optional_time"
            }
          }
        },
        {
          "match_all": {}
        }
      ]
    }
  },
  "runtime_mappings": {},
  "from": 0,
  "size": 500,
  "track_total_hits": true,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "date"
      }
    }
  ],
  "_source": false
}

```

---

<div class="post-metadata">

**Author:** ![vhs](https://avatars.discourse-cdn.com/v4/letter/v/58f4c7/32.png) [@vhs](https://discuss.elastic.co/u/vhs)\
**Post date:** [July 12, 2024, 8:35am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/3 "2024-07-12T08:35:50Z")

</div>

> [@Jatin\_Kathuria](#):
>
> Yes, check for the `query` key in the `Inspect -> Request` tab. It is query dsl only.
> 
> For example if you see below in timeline tab. It is QueryDSL and can be used as is.
> 
> Let me know if you wanted to ask something else.

I want to receive this, maybe via api, knowing the \_id of the document elastic security alert. Is it possible to receive this somehow not through the Kibana web interface?

---

<div class="post-metadata">

**Author:** ![vhs](https://avatars.discourse-cdn.com/v4/letter/v/58f4c7/32.png) [@vhs](https://discuss.elastic.co/u/vhs)\
**Post date:** [July 12, 2024, 8:48am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/4 "2024-07-12T08:48:47Z")

</div>

Or maybe it’s possible to use the API to get the \_id of events that were included in "investigate in timeline"?

---

<div class="post-metadata">

**Author:** ![Jatin\_Kathuria](https://avatars.discourse-cdn.com/v4/letter/j/d6d6ee/32.png) [@Jatin\_Kathuria](https://discuss.elastic.co/u/Jatin_Kathuria)\
**Post date:** [July 12, 2024, 9:25am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/5 "2024-07-12T09:25:27Z")

</div>

> [@vhs](#):
>
> I want to receive this, maybe via api, knowing the \_id of the document elastic security alert. Is it possible to receive this somehow not through the Kibana web interface?

> [@vhs](#):
>
> Or maybe it’s possible to use the API to get the \_id of events that were included in "investigate in timeline"?

I am not 100% sure, I will check and get back to you.

---

<div class="post-metadata">

**Author:** ![vhs](https://avatars.discourse-cdn.com/v4/letter/v/58f4c7/32.png) [@vhs](https://discuss.elastic.co/u/vhs)\
**Post date:** [July 16, 2024, 7:11am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/6 "2024-07-16T07:11:20Z")

</div>

Hello, Jatin, no ideas?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2024, 7:12am UTC](https://discuss.elastic.co/t/dsl-query-from-investigate-timeline/362997/7 "2024-08-13T07:12:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
