# How to retrieve the documents(records) of a saved search in elastic search

**URL:** <https://discuss.elastic.co/t/how-to-retrieve-the-documents-records-of-a-saved-search-in-elastic-search/119812>\
**Category:** Kibana\
**Created:** [February 14, 2018, 2:09pm UTC](https://discuss.elastic.co/t/how-to-retrieve-the-documents-records-of-a-saved-search-in-elastic-search/119812 "2018-02-14T14:09:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sachidananda\_VS](https://avatars.discourse-cdn.com/v4/letter/s/e47774/32.png) [@Sachidananda\_VS](https://discuss.elastic.co/u/Sachidananda_VS)\
**Post date:** [February 14, 2018, 2:09pm UTC](https://discuss.elastic.co/t/how-to-retrieve-the-documents-records-of-a-saved-search-in-elastic-search/119812/1 "2018-02-14T14:09:10Z")

</div>

Hi All,

I started exploring the ELK stack and was very happy to learn and implement the ELK features for my requirements. Currently I need a help in retrieving the documents (records) of a saved search.  
I am pushing my jenkins pipeline jobs console logs to elasticsearch using jenkins-logstash plugin and it's pumping the data without any problem. I am filtering my jenkins console data using a field called "ISSUE\_ID".I created a saved search with the output fields being  
"time" "ISSUE\_ID" "message" "BUILD\_ID" "JOB\_NAME". In kibana, I can see that my saved search is returning around 13 records for last 24 hrs. I used the content available in "Request" tab to retrieve the same no of documents(records) inside my ubuntu host using the below curl command. But it's dumping a huge amount of data.

How to retrieve the records with just the fields mentioned in saved search.

example output data what I am expecting is

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4bec395b34d711fec91d1108d181c5c93e0fbfde.png)

The curl command is:  
curl -X GET [http://localhost:9200/logstash-\*/\_search](http://localhost:9200/logstash-*/_search) -d request.json

The content of the request.json (the Request kibana sent to Elasticsearch from the saved search) is:

{  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"_": {}  
},  
"require\_field\_match": false,  
"fragment\_size": 2147483647  
},  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"analyze\_wildcard": true,  
"query": "ISSUE\_ID"  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": 1518515132440,  
"lte": 1518601532440,  
"format": "epoch\_millis"  
}  
}  
}  
],  
"must\_not": []  
}  
}  
}  
},  
"size": 500,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "30m",  
"time\_zone": "Asia/Kolkata",  
"min\_doc\_count": 0,  
"extended\_bounds": {  
"min": 1518515132440,  
"max": 1518601532440  
}  
}  
}  
},  
"fields": [  
"_",  
"\_source"  
],  
"script\_fields": {},  
"fielddata\_fields": [  
"@timestamp",  
"@buildTimestamp",  
"post\_date"  
]  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 16, 2018, 9:43am UTC](https://discuss.elastic.co/t/how-to-retrieve-the-documents-records-of-a-saved-search-in-elastic-search/119812/2 "2018-02-16T09:43:25Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

Please edit your post.

I moved your question to #kibana as I think you want to export from the UI not from the CLI.

Note that there is a CSV export available in xpack (commercial plugin).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2018, 9:43am UTC](https://discuss.elastic.co/t/how-to-retrieve-the-documents-records-of-a-saved-search-in-elastic-search/119812/3 "2018-03-16T09:43:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
