# How can i extract data from elasticsearch

**URL:** <https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347>\
**Category:** Elasticsearch\
**Created:** [March 16, 2018, 6:05pm UTC](https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347 "2018-03-16T18:05:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![djobes31770](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@djobes31770](https://discuss.elastic.co/u/djobes31770)\
**Post date:** [March 16, 2018, 6:05pm UTC](https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347/1 "2018-03-16T18:05:04Z")

</div>

I need to extract/export all winlogbeat data from once elk instance and reload/replay it into another for testing. What is the best and easiest way to get this done.

---

<div class="post-metadata">

**Author:** ![murlin99](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@murlin99](https://discuss.elastic.co/u/murlin99)\
**Post date:** [March 16, 2018, 6:11pm UTC](https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347/2 "2018-03-16T18:11:23Z")

</div>

You could use the Reindex from Remote option explained in this document.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#reindex-from-remote](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#reindex-from-remote)

---

<div class="post-metadata">

**Author:** ![djobes31770](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@djobes31770](https://discuss.elastic.co/u/djobes31770)\
**Post date:** [March 19, 2018, 5:56pm UTC](https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347/3 "2018-03-19T17:56:56Z")

</div>

This is nice, i guess though what i am trying to do, is i need to pull data from the elk data for a set of computernames and from winlogbeat only, then input that into excel or just a text file so i can then feed it into and event server for testing. i have been trying to use the reindex, and even the query language, but i can not get it to see the systems, an di know they are there. I know sql but this is not sql, any ideas or hints, i can script it up in bash or python if needed.

---

<div class="post-metadata">

**Author:** ![murlin99](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@murlin99](https://discuss.elastic.co/u/murlin99)\
**Post date:** [March 19, 2018, 6:56pm UTC](https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347/4 "2018-03-19T18:56:30Z")

</div>

The initial question sounded like you were trying to index from one cluster  
to another this seems a little different. Yes the queries can be a bit  
confusing if you are coming from SQL, when I first started with Elastic I  
had been doing only SQL for a long time.

Kibana is a good reference for building a query and then then seeing how  
that query was built. below is a very simple query to pull documents for  
one host from a logstash index.

```
curl -XGET "http://localhost:9200/logstash-2018*/_search" -H 'Content-Type:
application/json' -d'
{
    "query": {
        "match" : {
            "host" : "yourhostname"
        }
    }
}'

```

To get every document you will have to use scroll mode in your client  
otherwise it will only return a maximum of 10000 documents if you use  
"count":10000 Once you pull the data with your client then its just in a  
JSON object that you can manipulate however you want. Most clients support  
a similar query syntax.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2018, 6:56pm UTC](https://discuss.elastic.co/t/how-can-i-extract-data-from-elasticsearch/124347/5 "2018-04-16T18:56:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
