# Little help understanding a document query issue

**URL:** <https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, fleet\
**Created:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198 "2024-01-02T07:29:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oscar\_Llerena](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oscar_llerena/32/125520_2.png) [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Post date:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198/1 "2024-01-02T07:29:47Z")

</div>

Hi everyone, happy new year!

Can somebody please help me understanding the following issue?  
I have Elasticsearch (Elastic Defend) & Kibana in one server and Fleet in other separated. The monitoring agents are in a virtual-machine Windows-10 host and, to test the Elastic Defense Detection Rules, I'm launching an aggressive scans towards the windows host. Then, it produced the following alarm (For obvious reasons, I will put only the labels of interest) which information is extracted from the Kibana Dev Tools:

**The originating event info (ancestors info) in the alert document**:

> ```
> "_index": ".internal.alerts-security.alerts-default-000001",
> "kibana.alert.rule.name": "Potential Network Scan Detected",
> "kibana.alert.ancestors": [
> {
> "id": "125f7f14-0f76-5717-bf69-742ea3e57fd1",
> "type": "event",
> "index": "logs-endpoint.events.network-*,logs-network_traffic.*,packetbeat-*,filebeat-*,auditbeat-*",
> "depth": 0
> }
> ],
> 
> ```

As you can see this alarm is "Potential Network Scan Detected" and it gives as ancestor (which I understand is the event that originated the alarm) the

document id "125f7f14-0f76-5717-bf69-742ea3e57fd1"

and the index I think is one of  
index: "logs-endpoint.events.network-_,logs-network\_traffic._,packetbeat-_,filebeat-_,auditbeat-\*"

But I'm trying to look for that document ID with the query:

**The query for the alarm's ancestor** :

```auto
GET /*/_search
{
  "query": {
    "terms": {
      "_id": ["125f7f14-0f76-5717-bf69-742ea3e57fd1"]
    }
  }
}

```

**and there are no results**

so, my question is ... where is this document id "125f7f14-0f76-5717-bf69-742ea3e57fd1"?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2024, 7:30am UTC](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198/2 "2024-01-30T07:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
