# Incomplete response JSON

**URL:** <https://discuss.elastic.co/t/incomplete-response-json/164454>\
**Category:** Elasticsearch\
**Created:** [January 16, 2019, 11:40am UTC](https://discuss.elastic.co/t/incomplete-response-json/164454 "2019-01-16T11:40:47Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 11:40am UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/1 "2019-01-16T11:40:48Z")

</div>

> **Summary**
>
> ![48%20PM](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3cc43ac9bde3a7556ac075819fcd26db689cdffc.png) ![02%20PM](https://us1.discourse-cdn.com/elastic/original/3X/5/3/5356941bdd2df751d7a2f09430a4b9c34a195130.png)

When I fire the query ( using curl -X GET ) from my Linux machine the output JSON is not complete.  
the aggregation output is missing.  
screenshots attached. Please help

```
 curl -X GET "http://10.5.245.31:9200/response_hdd11*/_search?pretty" -H 'Content-Type: application/json' -d'
{
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {
    "1": {
      "sum": {
        "script": {
          "source": "doc['AB1C_response.keyword'].length",
          "lang": "painless"
        }
      }
    }
  },
  "stored_fields": [
    "*"
  ],
  "script_fields": {
    "number_of_requests": {
      "script": {
        "source": "doc['AB1C_request.keyword'].length",
        "lang": "painless"
      }
    },
    "success_response": {
      "script": {
        "source": "doc['AB1C_response.keyword'].length",
        "lang": "painless"
      }
    },
    "Timeouts": {
      "script": {
        "source": "doc['failure_response.keyword'].length",
        "lang": "painless"
      }
    }
  },
  "docvalue_fields": [
    "@timestamp",
    "formatted_time"
  ],
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "gte": 1547592761660,
              "lte": 1547635961660,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "filter": [
        {
          "match_all": {}
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}'
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 16, 2019, 11:43am UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/2 "2019-01-16T11:43:12Z")

</div>

It looks like it is missing as it did not find any results. It would probably help if you also showed the query and which indices it targets.

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 11:51am UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/3 "2019-01-16T11:51:32Z")

</div>

Yes, thanks. I noticed it as soon as I posted the question. Apologies

I think I have accidentally posted the query back in the main question ( just getting use to the interface 😉 )

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 16, 2019, 11:52am UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/4 "2019-01-16T11:52:44Z")

</div>

What does the query run in Kibana Console look like?

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 11:56am UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/5 "2019-01-16T11:56:10Z")

</div>

```
GET /response_hdd11*/_search?pretty
{
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {
    "1": {
      "sum": {
        "script": {
          "source": "doc['AB1C_response.keyword'].length",
          "lang": "painless"
        }
      }
    }
  },
  "stored_fields": [
    "*"
  ],
  "script_fields": {
    "number_of_requests": {
      "script": {
        "source": "doc['AB1C_request.keyword'].length",
        "lang": "painless"
      }
    },
    "success_response": {
      "script": {
        "source": "doc['AB1C_response.keyword'].length",
        "lang": "painless"
      }
    },
    "Timeouts": {
      "script": {
        "source": "doc['failure_response.keyword'].length",
        "lang": "painless"
      }
    }
  },
  "docvalue_fields": [
    "@timestamp",
    "formatted_time"
  ],
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "gte": 1547592761660,
              "lte": 1547635961660,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "filter": [
        {
          "match_all": {}
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 16, 2019, 12:02pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/6 "2019-01-16T12:02:57Z")

</div>

Are these queries both being sent to the same node? How many nodes do you have in the cluster?

If you have multiple nodes in the cluster, do you get the same response if you send the request to different nodes using curl?

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 12:17pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/7 "2019-01-16T12:17:44Z")

</div>

its a 3 node cluster ( attached screenshot). I pointed the query to other nodes as well. But still the same response ![43%20PM](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d82c12e3c35c0dba1635d378663f8a0241669f19.png)

```
curl -X GET "http://10.5.245.26:9200/response_hdd11*/_search?pretty" -H 'Content-Type: application/json' -d'
> {
> "size": 0,
> "_source": {
> "excludes": []
> },
> "aggs": {
> "1": {
> "sum": {
> "script": {
> "source": "doc['AB1C_response.keyword'].length",
> "lang": "painless"
> }
> }
> }
> },
> "stored_fields": [
> "*"
> ],
> "script_fields": {
> "number_of_requests": {
> "script": {
> "source": "doc['AB1C_request.keyword'].length",
> "lang": "painless"
> }
> },
> "success_response": {
> "script": {
> "source": "doc['AB1C_response.keyword'].length",
> "lang": "painless"
> }
> },
> "Timeouts": {
> "script": {
> "source": "doc['failure_response.keyword'].length",
> "lang": "painless"
> }
> }
> },
> "docvalue_fields": [
> "@timestamp",
> "formatted_time"
> ],
> "query": {
> "bool": {
> "must": [
> {
> "range": {
> "@timestamp": {
> "gte": 1547592761660,
> "lte": 1547635961660,
> "format": "epoch_millis"
> }
> }
> }
> ],
> "filter": [
> {
> "match_all": {}
> }
> ],
> "should": [],
> "must_not": []
> }
> }
> }'
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 0,
    "successful" : 0,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 0,
    "max_score" : 0.0,
    "hits" : []
  }
}
```

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 1:45pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/8 "2019-01-16T13:45:08Z")

</div>

we are past the previous scenario , now we are getting some error . I tried with a different query this time  
 ![55%20PM%201](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b76c5215add4b01fb0fe1bccceb24f23afe44708.png)

query at the backend:

```
   curl -X GET "http://10.5.245.31:9200/response_hdd11*/_search?pretty" -H 'Content-Type: application/json' -d'
> {
> "size": 0,
> "_source": {
> "excludes": []
> },
> "aggs": {},
> "stored_fields": [
> "*"
> ],
> "script_fields": {
> "number_of_requests": {
> "script": {
> "source": "doc['AB1C_request.keyword'].length",
> "lang": "painless"
> }
> },
> "success_response": {
> "script": {
> "source": "doc['AB1C_response.keyword'].length",
> "lang": "painless"
> }
> },
> "Timeouts": {
> "script": {
> "source": "doc['failure_response.keyword'].length",
> "lang": "painless"
> }
> }
> },
> "docvalue_fields": [
> "@timestamp",
> "formatted_time"
> ],
> "query": {
> "bool": {
> "must": [
> {
> "range": {
> "@timestamp": {
> "gte": 1547558066609,
> "lte": 1547644466609,
> "format": "epoch_millis"
> }
> }
> },
> {
> "exists": {
> "field": "AB1C_request.keyword"
> }
> }
> ],
> "filter": [
> {
> "match_all": {}
> }
> ],
> "should": [],
> "must_not": []
> }
> }
> }'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "script_exception",
        "reason" : "compile error",
        "script_stack" : [
          "doc[AB1C_request.keyword].l ...",
          " ^---- HERE"
        ],
        "script" : "doc[AB1C_request.keyword].length",
        "lang" : "painless"
      }
    ],
    "type" : "search_phase_execution_exception",
    "reason" : "all shards failed",
    "phase" : "query",
    "grouped" : true,
    "failed_shards" : [
      {
        "shard" : 0,
        "index" : "recharge_hdd11-2019.01.01",
        "node" : "gdHoshwiQ1-7SFIrxoNbsg",
        "reason" : {
          "type" : "script_exception",
          "reason" : "compile error",
          "script_stack" : [
            "doc[AB1C_request.keyword].l ...",
            " ^---- HERE"
          ],
          "script" : "doc[AB1C_request.keyword].length",
          "lang" : "painless",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "Variable [AB1C_request] is not defined."
          }
        }
      }
    ]
  },
  "status" : 500

```

query at kibana:

```
GET /response_hdd11*/_search?pretty
{
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {},
  "stored_fields": [
    "*"
  ],
  "script_fields": {
    "number_of_requests": {
      "script": {
        "source": "doc['AB1C_request.keyword'].length",
        "lang": "painless"
      }
    },
    "success_response": {
      "script": {
        "source": "doc['AB1C_response.keyword'].length",
        "lang": "painless"
      }
    },
    "Timeouts": {
      "script": {
        "source": "doc['failure_response.keyword'].length",
        "lang": "painless"
      }
    }
  },
  "docvalue_fields": [
    "@timestamp",
    "formatted_time"
  ],
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "gte": 1547558066609,
              "lte": 1547644466609,
              "format": "epoch_millis"
            }
          }
        },
        {
          "exists": {
            "field": "AB1C_request.keyword"
          }
        }
      ],
      "filter": [
        {
          "match_all": {}
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

the output at kibana is attached

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 16, 2019, 1:53pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/9 "2019-01-16T13:53:17Z")

</div>

I one you have quotes around the field name and in the other you don't. Why don't you simply copy the query body so you are sure you are comparing the same thing?

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 2:13pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/10 "2019-01-16T14:13:39Z")

</div>

i have some sensitive information in the code. Can i somehow blur it ?

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 2:19pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/11 "2019-01-16T14:19:49Z")

</div>

the only changes which I made to the query before posting was to change the name of some confidential content. Nothing else apart from that

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 3:02pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/12 "2019-01-16T15:02:44Z")

</div>

I think I have got it figured out.

Looks like you can only query scripted fields from Kibana console. I removed the scripted fields part from the query and then fired it. I got the count

```
    $ curl -X GET "http://10.5.245.31:9200/response_hdd11*/_search?pretty" -H 'Content-Type: application/json' -d'
    > {
    > "size": 0,
    > "_source": {
    > "excludes": []
    > },
    > "aggs": {},
    > "stored_fields": [
    > "*"
    > ],
    > "docvalue_fields": [
    > "@timestamp",
    > "formatted_time"
    > ],
    > "query": {
    > "bool": {
    > "must": [
    > {
    > "range": {
    > "@timestamp": {
    > "gte": 1547558066609,
    > "lte": 1547644466609,
    > "format": "epoch_millis"
    > }
    > }
    > },
    > {
    > "exists": {
    > "field": "AB1C_request"
    > }
    > }
    > ],
    > "filter": [
    > {
    > "match_all": {}
    > }
    > ],
    > "should": [],
    > "must_not": []
    > }
    > }
    > }'
    {
      "took" : 43,
      "timed_out" : false,
      "_shards" : {
        "total" : 80,
        "successful" : 80,
        "skipped" : 0,
        "failed" : 0
      },
      "hits" : {
        "total" : 267594,
        "max_score" : 0.0,
        "hits" : []
      }
    }
```

---

<div class="post-metadata">

**Author:** ![shikhar\_singh](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@shikhar\_singh](https://discuss.elastic.co/u/shikhar_singh)\
**Post date:** [January 16, 2019, 3:07pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/13 "2019-01-16T15:07:29Z")

</div>

Christian, Thank you for your quick responses. Also, please let me know if my hypothesis about the querying the scripted fields via curl is right or wrong.

cheers 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 3:07pm UTC](https://discuss.elastic.co/t/incomplete-response-json/164454/14 "2019-02-13T15:07:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
