# Need Clarification on incoming request's to ES

**URL:** <https://discuss.elastic.co/t/need-clarification-on-incoming-requests-to-es/63014>\
**Category:** Elasticsearch\
**Created:** [October 14, 2016, 3:01am UTC](https://discuss.elastic.co/t/need-clarification-on-incoming-requests-to-es/63014 "2016-10-14T03:01:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [October 14, 2016, 3:01am UTC](https://discuss.elastic.co/t/need-clarification-on-incoming-requests-to-es/63014/1 "2016-10-14T03:01:28Z")

</div>

Through packet beats I am monitoring 9200 port and giving to ES. I am seeing so many unexpected incoming events to ES. In my elastic search setup I am using kibana, Sense & elastic head. I want to know which application is sending this queries and why???

Some of Most repeated requests are here:

`"ip": "172.16.22.14", "method": "HEAD", "params": "", "path": "/", "port": 9200, "proc": "", "query": "HEAD /", "responsetime": 0, "server": "", "status": "OK", "type": "http"`

`"ip": "172.16.22.14", "method": "POST", "params": "", "path": "/_bulk", "port": 9200, "proc": "", "query": "POST /_bulk", "responsetime": 19, "server": "", "status": "OK", "type": "http"`

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 14, 2016, 5:13am UTC](https://discuss.elastic.co/t/need-clarification-on-incoming-requests-to-es/63014/2 "2016-10-14T05:13:56Z")

</div>

Packetbeat is send data to Elasticsearch as bulk requests over HTTP, so I suspect that is what all the \_bulk requests is from. As Packetbeat is monitoring its own traffic, you have created a feedback loop that will continuously generate results. When I built a similar test to look at Kibana traffic, I introduces a small client node on the same host that only listened to localhost, to which Packetbeat alone would send data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:12pm UTC](https://discuss.elastic.co/t/need-clarification-on-incoming-requests-to-es/63014/3 "2017-07-05T22:12:29Z")

</div>


