# Exploring an index

**URL:** <https://discuss.elastic.co/t/exploring-an-index/8046>\
**Category:** Elasticsearch\
**Created:** [June 11, 2012, 9:49pm UTC](https://discuss.elastic.co/t/exploring-an-index/8046 "2012-06-11T21:49:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![llowder](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@llowder](https://discuss.elastic.co/u/llowder)\
**Post date:** [June 11, 2012, 9:49pm UTC](https://discuss.elastic.co/t/exploring-an-index/8046/1 "2012-06-11T21:49:35Z")

</div>

I'm pretty new to elasticsearch, and I have an index I did not create that  
I am trying to explore and learn about.

Most of the examples I have seen on the website seem to assume that "id" is  
known when using a get (it's generated, based on some sort of hashing)

I tried doing a search to get a listing:

curl -XPOST '[http://localhost:9200/graylog2/message?pretty=true](http://localhost:9200/graylog2/message?pretty=true)' -d '{  
"fields" : ["\_level", "\_severity", "\_Severity", "facility", "\_loglevel",  
"level"], "query" : { "facility" : "TeamMemberStatusChange" } }  
}'  
{  
"ok" : true,  
"\_index" : "graylog2",  
"\_type" : "message",  
"\_id" : "FvOjHTRvQj-F6\_T3f5Rkxw",  
"\_version" : 1  
}  
and

curl -XPOST '[http://localhost:9200/graylog2/m\_search?pretty=true](http://localhost:9200/graylog2/m_search?pretty=true)' -d '{  
"fields" : ["\_level", "\_severity", "\_Severity", "facility", "\_loglevel",  
"level"], "query" : { "facility" : "TeamMemberStatusChange" } } }'  
{  
"ok" : true,  
"\_index" : "graylog2",  
"\_type" : "m\_search",  
"\_id" : "X6gushGRQyq87yQp4A2r\_A",  
"\_version" : 1  
}

Am I not understanding what I've read in the docs, or is there something  
else I am doing wrong?

Any suggestions or pointers would be much appreciated.

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [June 11, 2012, 10:27pm UTC](https://discuss.elastic.co/t/exploring-an-index/8046/2 "2012-06-11T22:27:45Z")

</div>

First of all, you should be using GET requests and not POST. Not sure  
if POST works (I do not use REST), but it is best to stick with GET.

Most importantly, you are missing the actual endpoint for a service.  
The URL you are using has graylog2 as the index and m\_search as the  
type. After that, you need to specify a service endpoint such as  
\_search.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Your query is also incorrect. Not sure what you are after, but you can  
view a few examples here:  
[Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/) Any of those  
queries will go inside you query block.

Cheers,

Ivan

On Mon, Jun 11, 2012 at 2:49 PM, [llowder@oreillyauto.com](mailto:llowder@oreillyauto.com)  
[llowder@oreillyauto.com](mailto:llowder@oreillyauto.com) wrote:

> I'm pretty new to elasticsearch, and I have an index I did not create that I  
> am trying to explore and learn about.
> 
> Most of the examples I have seen on the website seem to assume that "id" is  
> known when using a get (it's generated, based on some sort of hashing)
> 
> I tried doing a search to get a listing:
> 
> curl -XPOST '[http://localhost:9200/graylog2/message?pretty=true](http://localhost:9200/graylog2/message?pretty=true)' -d '{  
> "fields" : ["\_level", "\_severity", "\_Severity", "facility", "\_loglevel",  
> "level"], "query" : { "facility" : "TeamMemberStatusChange" } }  
> }'  
> {  
> "ok" : true,  
> "\_index" : "graylog2",  
> "\_type" : "message",  
> "\_id" : "FvOjHTRvQj-F6\_T3f5Rkxw",  
> "\_version" : 1  
> }  
> and
> 
> curl -XPOST '[http://localhost:9200/graylog2/m\_search?pretty=true](http://localhost:9200/graylog2/m_search?pretty=true)' -d '{  
> "fields" : ["\_level", "\_severity", "\_Severity", "facility", "\_loglevel",  
> "level"], "query" : { "facility" : "TeamMemberStatusChange" } } }'  
> {  
> "ok" : true,  
> "\_index" : "graylog2",  
> "\_type" : "m\_search",  
> "\_id" : "X6gushGRQyq87yQp4A2r\_A",  
> "\_version" : 1  
> }
> 
> Am I not understanding what I've read in the docs, or is there something  
> else I am doing wrong?
> 
> Any suggestions or pointers would be much appreciated.

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [June 12, 2012, 8:21am UTC](https://discuss.elastic.co/t/exploring-an-index/8046/3 "2012-06-12T08:21:47Z")

</div>

On Mon, 2012-06-11 at 15:27 -0700, Ivan Brusic wrote:

> First of all, you should be using GET requests and not POST. Not sure  
> if POST works (I do not use REST), but it is best to stick with GET.

POST works for search too, because Javascript doesn't allow GET requests  
with a body.

clint

---

<div class="post-metadata">

**Author:** ![llowder](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@llowder](https://discuss.elastic.co/u/llowder)\
**Post date:** [June 12, 2012, 1:53pm UTC](https://discuss.elastic.co/t/exploring-an-index/8046/4 "2012-06-12T13:53:43Z")

</div>

On Monday, June 11, 2012 5:27:45 PM UTC-5, Ivan Brusic wrote:

> First of all, you should be using GET requests and not POST. Not sure  
> if POST works (I do not use REST), but it is best to stick with GET.
> 
> Most importantly, you are missing the actual endpoint for a service.  
> The URL you are using has graylog2 as the index and m\_search as the  
> type. After that, you need to specify a service endpoint such as  
> \_search.

The m\_search was actually a typo, but I've corrected that.

> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/)
> 
> Your query is also incorrect. Not sure what you are after, but you can  
> view a few examples here:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/) Any of those  
> queries will go inside you query block.

I had looked at those, but am still somewhat confused.

I have a field that has various webapps that we host as it's value. I'm  
trying to do a query based on the app names.

The field name is facility.

I tried:

curl -XPOST '[http://localhost:9200/graylog2/message/\_search?pretty=true](http://localhost:9200/graylog2/message/_search?pretty=true)' -d  
'{ "query\_string" : { "default\_field" : "facility", "query" :  
"TeamMemberStatusChange" } }'

but got:

{  
"error" : "SearchPhaseExecutionException[Failed to execute phase  
[query\_fetch], total failure; shardFailures  
{[z\_9NhCT0TfCuibOP4trExQ][graylog2][0]: SearchParseException[[graylog2][0]:  
from[-1],size[-1]: Parse Failure [Failed to parse source [{  
"query\_string" : { "default\_field" : "facility", "query" :  
"TeamMemberStatusChange" } }]]]; nested:  
SearchParseException[[graylog2][0]: from[-1],size[-1]: Parse Failure [No  
parser for element [query\_string]]]; }]",  
"status" : 500  
}

This was based off the example found at:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

I also tried the example from  
[Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/field-query.html) :

curl -XPOST '[http://localhost:9200/graylog2/message/\_search?pretty=true](http://localhost:9200/graylog2/message/_search?pretty=true)' -d  
'{ field" : { "facility" : "+TeamMemberStatusChange" } }'

{  
"error" : "SearchPhaseExecutionException[Failed to execute phase  
[query\_fetch], total failure; shardFailures  
{[z\_9NhCT0TfCuibOP4trExQ][graylog2][0]: SearchParseException[[graylog2][0]:  
from[-1],size[-1]: Parse Failure [Failed to parse source [{ "field" : {  
"facility" : "+TeamMemberStatusChange" } }]]]; nested:  
SearchParseException[[graylog2][0]: from[-1],size[-1]: Parse Failure [No  
parser for element [field]]]; }]",  
"status" : 500  
}

I'm going to try watching some of the videos, but so far I am thoroughly  
confused at this point.

---

<div class="post-metadata">

**Author:** ![Crwe](https://avatars.discourse-cdn.com/v4/letter/c/898d66/32.png) [@Crwe](https://discuss.elastic.co/u/Crwe)\
**Post date:** [June 12, 2012, 3:38pm UTC](https://discuss.elastic.co/t/exploring-an-index/8046/5 "2012-06-12T15:38:16Z")

</div>

> I tried:
> 
> curl -XPOST '[http://localhost:9200/graylog2/message/\_search?pretty=true'-d](http://localhost:9200/graylog2/message/_search?pretty=true'-d)  
> '{ "query\_string" : { "default\_field" : "facility", "query" :  
> "TeamMemberStatusChange" } }'

I think you need to wrap the data part in a `"query": { ... }` block.  
The examples on the web are a bit tricky that way -- getting the whole  
syntax to a working state is sometimes not trivial. And it gets even  
crazier with more advanced syntax, like `custom_score` 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:24am UTC](https://discuss.elastic.co/t/exploring-an-index/8046/6 "2017-07-06T03:24:45Z")

</div>


