# How to know what Elasticsearch endpoint is used by Kibana to make graphs?

**URL:** <https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529>\
**Category:** Kibana\
**Tags:** lens\
**Created:** [May 26, 2025, 7:27am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529 "2025-05-26T07:27:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![philyeanaeknss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philyeanaeknss/32/141241_2.png) [@philyeanaeknss](https://discuss.elastic.co/u/philyeanaeknss)\
**Post date:** [May 26, 2025, 7:27am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529/1 "2025-05-26T07:27:26Z")

</div>

I have URI like  
`../discover#/?_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now%2Fd,to:now%2Fd))&_a=(columns:!(_source),filters:!(),index:{index},interval:auto,query:(language:kuery,query:%27%27),sort:!(!(created_at,desc)))`  
at Kibana and it returns me `hits total` and hits per every half hour printed at bar graph.

If I'm right every bar returns difference between values per half hour.

I want to get plain data about it via command line.

What API Elasticsearch endpoint I should use to get such data?

I've tried to store `${index_name}/_stats/docs` data but it doesn't match with Kibana graph data.

Endpoint `/metrics` has been used but it has different from Kibana graph values too.

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [May 26, 2025, 12:18pm UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529/2 "2025-05-26T12:18:12Z")

</div>

Hi @philyeanaeknss ,

that is a little bit hard to reproduce in general.  
To be honest my recommendation here would be to switch to ES|QL mode in Discover, then open the inspector and copy the request made for the visualization in there: at that point you can be 100% sure that the table returned by the ES|QL endpoint is the same used for the bar chart.

---

<div class="post-metadata">

**Author:** ![philyeanaeknss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philyeanaeknss/32/141241_2.png) [@philyeanaeknss](https://discuss.elastic.co/u/philyeanaeknss)\
**Post date:** [May 27, 2025, 4:59am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529/3 "2025-05-27T04:59:05Z")

</div>

Hm..  
It is possible to copy request body only not its URI.

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [May 27, 2025, 8:24am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529/4 "2025-05-27T08:24:39Z")

</div>

you are quite right.  
I've opened an issue for it here you can track: [[Inspector] ES|QL Request doesn't show URL in the Request panel · Issue #221581 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/221581)

---

<div class="post-metadata">

**Author:** ![philyeanaeknss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philyeanaeknss/32/141241_2.png) [@philyeanaeknss](https://discuss.elastic.co/u/philyeanaeknss)\
**Post date:** [May 27, 2025, 8:32am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529/5 "2025-05-27T08:32:13Z")

</div>

So there's no any other way to find complete URL?

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [May 27, 2025, 9:02am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529/6 "2025-05-27T09:02:11Z")

</div>

The URL is the Elasticsearch ES|QL `/_query` as described here: [Use the ES|QL \_query API | Elastic Docs](https://www.elastic.co/docs/explore-analyze/query-filter/languages/esql-rest)

The request body can be used as is against that endpoint to get the visualization table.
