# ES|QL Invoke-WebRequest how to

**URL:** <https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848>\
**Category:** Elasticsearch\
**Tags:** esql\
**Created:** [February 2, 2026, 8:53am UTC](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848 "2026-02-02T08:53:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![a11](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a11/32/100458_2.png) [@a11](https://discuss.elastic.co/u/a11)\
**Post date:** [February 2, 2026, 8:53am UTC](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848/1 "2026-02-02T08:53:25Z")

</div>

Hello,

I’m trying to send a webrequest with a powershell script:

```json
{
"query": 
"""
FROM packetbeat-tls 
| WHERE dnsdomain.keyword == "%domain%" AND @timestamp > NOW() - 7days 
| KEEP host.name.keyword, source.ip.keyword 
| STATS 
 all = COUNT(*) WHERE NOT host.name.keyword:"%target%", 
 target = COUNT(*) WHERE host.name.keyword:"%target%" BY source.ip.keyword 
| EVAL present = CASE( 
  all > 0 AND target >= 0, "OK", 
  all == 0 AND target > 0, "ERROR", 
  all == 0 AND target == 0, "WARN" ) 
| WHERE `present`=="ERROR" 
| KEEP present, source.ip.keyword
"""
}

```

\*%x% == Variables

The request works well with DevTools but not within powershell.

The request:

```powershell
Invoke-WebRequest -Method Post -Uri "$url/_query/async?allow_partial_results=true" -Body $body -Headers $Headers -UseBasicParsing -ContentType 'application/json'

```

I get this error:

> Invoke-WebRequest : {"error":{"root\_cause":[{"type":"x\_content\_parse\_exception","reason":"[1:13] Unexpected character ('"' (code 34)): was expecting comma to separate Object entries\n at [Source: (byte[])"{"query": """FROM…etc

How can I send powershell query for ESQL ?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [February 5, 2026, 3:24pm UTC](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848/2 "2026-02-05T15:24:19Z")

</div>

Hello @a11

Created a ps1 file with the script and was able to launch it via PowerShell using below command :

```auto
.\esql-test.ps1

Output :

    present | ip
---------------+---------------
ERROR |93.9.229.168
ERROR |90.44.97.144
ERROR |226.154.89.231
ERROR |160.20.100.193
ERROR |96.239.18.242

```

Below is the ps1 file with code :

```auto
$Headers = @{
  Authorization = "ApiKey <apikey>"
}

$esql = @"
FROM kibana_sample_data_logs
| WHERE geo.dest : "US"
  AND @timestamp > NOW() - 7days
| KEEP host, ip
| STATS
    all = COUNT(*) WHERE NOT host :"%artifacts%",
    target = COUNT(*) WHERE host :"%elastic%"
  BY ip
| EVAL present = CASE(
    all < 4 AND target >= 0, "OK",
    all == 4 AND target >= 0, "ERROR",
    all == 0 AND target == 0, "WARN"
  )
| WHERE present == "ERROR"
| KEEP present, ip
| LIMIT 100
"@

$body = @{
  query = $esql
} | ConvertTo-Json

$url = "http://localhost:9200"

$response = Invoke-WebRequest `
  -Method Post `
  -Uri "$url/_query?format=txt" `
  -Headers $Headers `
  -ContentType "application/json" `
  -Body $body

$response.Content

```

Thanks!!
