# Dumping requests

**URL:** <https://discuss.elastic.co/t/dumping-requests/319462>\
**Category:** Elasticsearch\
**Created:** [November 21, 2022, 2:15pm UTC](https://discuss.elastic.co/t/dumping-requests/319462 "2022-11-21T14:15:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Georgi\_Danov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgi_danov/32/113592_2.png) [@Georgi\_Danov](https://discuss.elastic.co/u/Georgi_Danov)\
**Post date:** [November 21, 2022, 2:15pm UTC](https://discuss.elastic.co/t/dumping-requests/319462/1 "2022-11-21T14:15:06Z")

</div>

I'm reverse engineering and optimizing ES instance.  
One of the things that would help me enormously is to understand what operations (updates and queries) are coming in.  
What's the best way do dump & analyze the operations initiated by clients?

Additionally I'd like to audit client calls to make sure some of my prescriptions are followed — want to catch "rogue" requests that don't follow rules we set. For whatever reasons code reviews won't do.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 21, 2022, 5:59pm UTC](https://discuss.elastic.co/t/dumping-requests/319462/2 "2022-11-21T17:59:51Z")

</div>

There isn't really a way to do this directly within Elasticsearch itself. You can get some information from `GET _nodes/stats` and `GET <index>/_stats` but that seems like it won't be enough detail to answer your questions. The simplest way to get hold of the requests themselves is probably to stick a proxy in front of ES and capture the requests there.

---

<div class="post-metadata">

**Author:** ![Georgi\_Danov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgi_danov/32/113592_2.png) [@Georgi\_Danov](https://discuss.elastic.co/u/Georgi_Danov)\
**Post date:** [November 22, 2022, 10:17am UTC](https://discuss.elastic.co/t/dumping-requests/319462/3 "2022-11-22T10:17:20Z")

</div>

actually there is. It's two-step process:

```auto
put /<index>/_settings/
{
  "index.search.slowlog.threshold.query.trace": "0s",
  "index.indexing.slowlog.threshold.index.trace": "0s",
  "index.indexing.slowlog.source": true,
}

```

plus

```auto
PUT _cluster/settings
{
  "persistent": {
    "logger.org.elasticsearch.http.HttpTracer": "trace",
    "http.tracer.include": "*"
  },
  "transient": {
    "logger.org.elasticsearch.http.HttpTracer": "trace",
    "http.tracer.include": [
      "*"
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 22, 2022, 12:10pm UTC](https://discuss.elastic.co/t/dumping-requests/319462/4 "2022-11-22T12:10:23Z")

</div>

If that's enough detail for you then great 👍 It won't show you all operations, nor can you see the body of HTTP requests using that tracer.

---

<div class="post-metadata">

**Author:** ![Georgi\_Danov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgi_danov/32/113592_2.png) [@Georgi\_Danov](https://discuss.elastic.co/u/Georgi_Danov)\
**Post date:** [November 22, 2022, 1:39pm UTC](https://discuss.elastic.co/t/dumping-requests/319462/5 "2022-11-22T13:39:03Z")

</div>

the slow log shows the body (I guess the parsed one).

installing reverse proxy so I just get idea what's going on with my server is ridiculous. I see you are team member — maybe instead of telling me what won't work, file & prioritise issue that would fix it? I doubt I'm the only one needing this.
