# ElasticSearch Query with Powershell Invoke-RestMethod

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228>\
**Category:** Elasticsearch\
**Created:** [February 6, 2020, 5:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228 "2020-02-06T17:13:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Post date:** [February 6, 2020, 5:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/1 "2020-02-06T17:13:04Z")

</div>

Hi-  
I have a Elastic Search Rest API to query along with range condition, which would need to be executed thru Powershell using Invoke-RestMethod command, but it fails. It works alright using Curl.

**Curl command:**

curl -u User:Password -X GET "localhost:9200/test\_data-\*/\_count" -H 'Content-Type: application/json' -d'  
{  
"query": {  
"range" : {  
"@timestamp" : {  
"gte" : "now-15m/m",  
"lte" : "now"  
}  
}  
}  
}  
'

I have written the below powershell script:

$response = Invoke-RestMethod "[http://localhost:9200/test\_data-\*/\_count](http://localhost:9200/test_data-*/_count)" -Method Get ` -Headers @{Authorization=("Basic {0}" -f $authHeaderValue)}`  
-Body "{  
`"query`": {  
`"range`" : {  
`"@timestamp`" : {  
`"gte`" : `"now-15m/m`",  
`"lte`" : `"now`"  
}  
}  
}  
}"

I get this error:

> ```
> Invoke-RestMethod : Cannot send a content-body with this verb-type.
> At line:1 char:13
> 
> ```

Could someone help me how do I make a GET request with body block in Powershell? Thanks !

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 6, 2020, 8:01pm UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/2 "2020-02-06T20:01:46Z")

</div>

Use `POST` instead.

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [February 6, 2020, 8:18pm UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/3 "2020-02-06T20:18:52Z")

</div>

PowerShell doesn't support a GET request with a body, so you need to use POST instead as @dadoonet suggests.

If you need to work with Elasticsearch frequently with PowerShell, you may be interested in using [Elastic.Console](https://www.powershellgallery.com/packages/Elastic.Console/7.5.0-rc1), a small PowerShell module that provides cmdlets for

1. executing requests
2. API path autocompletion
3. ability to convert from and execute Kibana Console examples.

---

<div class="post-metadata">

**Author:** ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Post date:** [February 7, 2020, 4:20am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/4 "2020-02-07T04:20:29Z")

</div>

Sure @forloop. I'd use the console going forward. I find it very useful. Thanks !

@dadoonet - POST call worked, am able to get the same output as GET calls. I hope the POST method doesn't make any impact to the data we already collected ? thanks !

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [February 7, 2020, 4:24am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/5 "2020-02-07T04:24:48Z")

</div>

> [@paul1243](#):
>
> I hope the POST method doesn't make any impact to the data we already collected ? thanks !

It won't. Elasticsearch supports `POST` for APIs that accept `GET` with a request body for languages that don't support `GET` with a request body.

---

<div class="post-metadata">

**Author:** ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Post date:** [February 7, 2020, 5:02am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/6 "2020-02-07T05:02:34Z")

</div>

Great, and thanks for confirming @forloop 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 5:02am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-powershell-invoke-restmethod/218228/7 "2020-03-06T05:02:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
