# Need a little help for elasticsearch query

**URL:** <https://discuss.elastic.co/t/need-a-little-help-for-elasticsearch-query/285794>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [October 4, 2021, 9:02am UTC](https://discuss.elastic.co/t/need-a-little-help-for-elasticsearch-query/285794 "2021-10-04T09:02:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![FALEN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/falen/32/82754_2.png) [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Post date:** [October 4, 2021, 9:02am UTC](https://discuss.elastic.co/t/need-a-little-help-for-elasticsearch-query/285794/1 "2021-10-04T09:02:57Z")

</div>

Hi everyone,

Need help to convert this kibana query body to elastic query api format.  
My goal is to create an api query, that returns all the data between spesific times.  
So i can reingest this data to logstash, and parse them properly.

Query api example;

```auto
GET /web_transaction-2021.09.*/_search
{
    "query": {
        "range" : {
            "publish_date": {
             "gte": "2021-09-14T03:47:31.000Z",
             "lte": "2021-09-24T07:00:11.595Z",
             "format": "strict_date_optional_time"
            }
        }
    }
}

```

and need this in single line format etc;  
example: query =\> '{ "query": { "match": { "statuscode": 200 } }, "sort": ["\_doc"] }'

Body from kibana;

```auto
{
  "version": true,
  "size": 500,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "fixed_interval": "3h",
        "time_zone": "Europe/Istanbul",
        "min_doc_count": 1
      }
    }
  },
  "stored_fields": [
    "*"
  ],
  "script_fields": {},
  "docvalue_fields": [
    {
      "field": "@timestamp",
      "format": "date_time"
    },
    {
      "field": "graylogTimestamp",
      "format": "date_time"
    },
    {
      "field": "graylogtimestamp",
      "format": "date_time"
    }
  ],
  "_source": {
    "excludes": []
  },
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "match_all": {}
        },
        {
          "range": {
            "@timestamp": {
              "gte": "2021-09-14T03:47:31.000Z",
              "lte": "2021-09-24T07:00:11.595Z",
              "format": "strict_date_optional_time"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2021, 9:03am UTC](https://discuss.elastic.co/t/need-a-little-help-for-elasticsearch-query/285794/2 "2021-11-01T09:03:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
