# Get data from Kibana using Elasticsearch API

**URL:** <https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672>\
**Category:** Elasticsearch\
**Created:** [February 18, 2021, 9:42am UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672 "2021-02-18T09:42:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_Patricio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_patricio/32/84100_2.png) [@Carlos\_Patricio](https://discuss.elastic.co/u/Carlos_Patricio)\
**Post date:** [February 18, 2021, 9:42am UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/1 "2021-02-18T09:42:42Z")

</div>

Hi,

I'm trying to retrieve data from one Kibana view using the API request.

The request from the view:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e8a32ddb7150ee64b9c7f1823ca571c3bde548a.png)

The response with the expected result:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f3dcd5fe27735df145dd9185c032a8379ecb528.png)

And then I tried to paste the request to Kibana \> Dev Tools \> Console, as I saw in this [topic](https://discuss.elastic.co/t/get-data-from-visualize-dashboard-using-the-api/83684/6), but the response it's totally different:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3cb4d89366a3f669d9f7c523e6641bdea844e037.png)

How can I do to retrieve this info using Kibana dev tools and Rest API?

Thanks,

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 18, 2021, 8:26pm UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/2 "2021-02-18T20:26:11Z")

</div>

Most of the requests Kibana does to get data from Elasticsearch are searches against an index. So if I copy the request from Kibana Discover, and paste that into the Kibana dev tools console, I need to add `GET /your-index-name-here/_search` before the body.

For example;

```auto
GET /gatling-data/_search
{
  "version": true,
  "size": 500,
  "sort": [
    {
      "timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "timestamp",
        "fixed_interval": "5s",
        "time_zone": "America/Chicago",
        "min_doc_count": 1
      }
    }
  },
...

```

---

<div class="post-metadata">

**Author:** ![Carlos\_Patricio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_patricio/32/84100_2.png) [@Carlos\_Patricio](https://discuss.elastic.co/u/Carlos_Patricio)\
**Post date:** [February 19, 2021, 8:30am UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/3 "2021-02-19T08:30:27Z")

</div>

Thanks for your help LeeDR. I'm using the index:

```auto
get /default-2018.02/_search

{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "*",
            "analyze_wildcard": true
          }
        },
        {
          "match_phrase": {
            "message": {
              "query": "transaction_success"
            }
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": 1612134000000,
              "lte": 1614553199999,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": []
    }
  },
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {}
}

```

But if I use  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e2316c5ece0b40efbcb80d2c56162e887ed28c5.png)  
or  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a4199385eb74a2c7f8c77878a0ad2b0d14d3dd7.png)  
the returning hits are always the same.

I feel that the query it's not working and I'm retrieving all the values. Response:

```auto
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 195451,
    "max_score": 1,
    "hits": [
      {
        "_index": "default-2018.02",
        "_type": "logEvent",
        "_id": " ************ _",
        "_score": 1,
        "_source": {
          "@timestamp": "2021-01-01T00:30:12.5268305Z",
          "level": "Info",
          "message": "New mail messages in folder Input for : 0. process is already running: False",
          "levelOrdinal": 2,
          "timeStamp": "2021-01-01T00:30:12.5268305Z",
          "Source": "Robot",
          "organizationUnitId": 1,
          "logType": "User",
...

```

Thanks.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 23, 2021, 3:44pm UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/4 "2021-02-23T15:44:38Z")

</div>

I can't really tell what the name of the field is that contains `transaction_success`. If you go to the index pattern in Kibana and look at the fields, can you tell me what you see for that field. Do you see that field listed twice, once with `.keyword` appended to the end?

I think your issue is that the field containing `transaction_success` is analyzed which splits it into `transaction` and `success`. But I would have thought the `match_phrase` you're doing would have then correctly matched on `transaction success`.  
But if you could use the `.keyword` field that wouldn't be analyzed.

---

<div class="post-metadata">

**Author:** ![Carlos\_Patricio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_patricio/32/84100_2.png) [@Carlos\_Patricio](https://discuss.elastic.co/u/Carlos_Patricio)\
**Post date:** [February 23, 2021, 4:06pm UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/5 "2021-02-23T16:06:32Z")

</div>

Today I solve it with a help of someone more knowledge about it. He change the query and now I can retrieve the data needed.

```auto
post index/_search
{
  "query": {
    "match": {
          "message": {
            "query": "transaction_error",
            "type": "phrase"
          }
        }
  }
}

```

I was expecting to copy the request directly from the view, like I saw in the topic that I mentioned before, but it doesn't work.

Next step it's to retrieve the data using the API.

Many thanks for your help.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [February 23, 2021, 4:11pm UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/6 "2021-02-23T16:11:38Z")

</div>

> [@Carlos\_Patricio](#):
>
> But if I use  
> ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e2316c5ece0b40efbcb80d2c56162e887ed28c5.png)  
> or  
> ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a4199385eb74a2c7f8c77878a0ad2b0d14d3dd7.png)  
> the returning hits are always the same.

Match\_phrase will use the default analyzer to split the query in terms, so in your case it will split it in `transaction` and `success` respectively `transaction` and `error` so it wouldn't find a different number of results due to `transaction` being the highest number. I would suggest using match for a term like that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2021, 4:12pm UTC](https://discuss.elastic.co/t/get-data-from-kibana-using-elasticsearch-api/264672/7 "2021-03-23T16:12:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
