# Elasticsearch search

**URL:** <https://discuss.elastic.co/t/elasticsearch-search/308315>\
**Category:** Elasticsearch\
**Created:** [June 28, 2022, 4:34am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315 "2022-06-28T04:34:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![chandramouli\_ravi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandramouli_ravi/32/107222_2.png) [@chandramouli\_ravi](https://discuss.elastic.co/u/chandramouli_ravi)\
**Post date:** [June 28, 2022, 4:34am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/1 "2022-06-28T04:34:51Z")

</div>

Hi,

There is a document in this way in ElasticSearch 6.8 Version  
"\_index": "XYZ-1582934400000",  
"\_type": "XYZ",  
"\_id": "bn1top/10006979936515",  
"\_score": 11.2877655,

**When i run the below command, its running ok and returning one document**  
**curl "[http://username:password@hostname:8080/XYZ/\_search?default\_operator=AND&q=rmaid%3Abn1top&size=2](http://username:password@hostname:8080/XYZ/_search?default_operator=AND&q=rmaid%3Abn1top&size=2)"**

But when i run this command, its giving error  
**curl "[http://username:password@hostname:8080/\_sql?format=txt](http://username:password@hostname:8080/_sql?format=txt)" -d "{"query" : "select \* from XYZ limit 10" }"**

403 Forbidden
# 403 Forbidden

* * *
nginx/1.10.3 (Ubuntu)

Could you please help me identify what's the issue.

Thanks,  
Chandra

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2022, 4:34am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/2 "2022-06-28T04:34:51Z")

</div>

ElasticSearch 6.8 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 28, 2022, 4:48am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/3 "2022-06-28T04:48:30Z")

</div>

Wrong syntax see here

> **[Overview | Elasticsearch Guide \[6.8\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/sql-rest-overview.html#sql-rest-overview)**

And please upgrade as a matter of urgency

```auto
POST /_xpack/sql?format=txt
{
    "query": "SELECT * FROM library ORDER BY page_count DESC LIMIT 5"
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2022, 4:51am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/4 "2022-06-28T04:51:43Z")

</div>

There looks to be nginx proxy in front of Elasticsearch, you might want to talk directly to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![chandramouli\_ravi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandramouli_ravi/32/107222_2.png) [@chandramouli\_ravi](https://discuss.elastic.co/u/chandramouli_ravi)\
**Post date:** [June 28, 2022, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/5 "2022-06-28T08:49:44Z")

</div>

I will talk to my team about ES Version.

Revised my command but its still failing

**curl -v "[http://username:password@hostname:8080/\_xpack/sql?format=txt](http://username:password@hostname:8080/_xpack/sql?format=txt)" -d "{"query" : "select fieldname from xyz limit 10" }" -H "Content-Type: application/json"**

- Trying 10.0.71.26:8080...
- Connected to [mt.analytical-elasticsearch.service.prod1.riskmatch.com](http://mt.analytical-elasticsearch.service.prod1.riskmatch.com) (10.0.71.26) port 8080 (#0)

```auto
* Server auth using Basic with user '...'
> POST /_xpack/sql?format=txt HTTP/1.1
> Host: ...
> Authorization: Basic ...
> User-Agent: curl/7.79.1
> Accept: */*
> Content-Type: application/json
> Content-Length: 55
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 403 Forbidden
< Server: nginx/1.10.3 (Ubuntu)
< Date: Tue, 28 Jun 2022 08:47:57 GMT
< Content-Type: text/html
< Content-Length: 178
< Connection: keep-alive
<
<html>
<head><title>403 Forbidden</title></head>
<body bgcolor="white">
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/1.10.3 (Ubuntu)</center>
</body>
</html>
* Connection #0 to host ... left intact

```

Thanks,  
Chandra

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2022, 10:36am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/6 "2022-06-28T10:36:54Z")

</div>

Again, you are talking to an nginx proxy. You need to talk to Elasticsearch on port 9200 to make sure this is not an nginx issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2022, 10:37am UTC](https://discuss.elastic.co/t/elasticsearch-search/308315/7 "2022-07-26T10:37:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
