# REST calls for elastic search

**URL:** <https://discuss.elastic.co/t/rest-calls-for-elastic-search/41272>\
**Category:** Elasticsearch\
**Created:** [February 9, 2016, 12:31pm UTC](https://discuss.elastic.co/t/rest-calls-for-elastic-search/41272 "2016-02-09T12:31:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bharath\_meka](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@bharath\_meka](https://discuss.elastic.co/u/bharath_meka)\
**Post date:** [February 9, 2016, 12:31pm UTC](https://discuss.elastic.co/t/rest-calls-for-elastic-search/41272/1 "2016-02-09T12:31:44Z")

</div>

Hi,

We would like to do a REST call to Elasticsearch from a custom logstash plugin to pull the logs. These logs needs to be restricted on certain fields like userid and sessionid (we have these fields added while parsing the log messages). We are using the following URL to get these logs.

**http://\<\<elk\_server\>\>:9200/logstash-2016.02.08/\_search?q=([userid:abc@abc.com](mailto:userid:abc@abc.com))AND(sessionid:eNIw36\_pT3ptVTAJSmYiov0)&fields=message**

When we post this URL through a REST Client (mozilla Addon) we are getting the response. Now, we would like to do the same REST call from within a custom logstash plugin. We are using the following code to do a GET to the URL. But while parsing the response we see an error **JSON::ParserError: unexpected token at ..**  
Note that, when I print the response code, it is 200.

> @elk\_url = 'http://\<\<elk\_server\>\>:9200/logstash-2016.02.08/\_search?q=([userid:abc@abc.com](mailto:userid:abc@abc.com))AND(sessionid:eNIw36\_pT3ptVTAJSmYiov0)&fields=message'  
> response\_elk = RestClient.get @elk\_url  
> log\_messages = JSON.parse(response\_elk)

Couple of questions:

1. Are we using the correct URL for getting the logs we want?
2. How to fix the parse error and get the "message" field from the response?
3. Is there any example code where a REST call is made to Elasticsearch from a logstash plugin?

\*\*Note: \*\*We are using Elasticsearch 1.7.0, Logstash 1.4.5

Any pointers is appreciated.

Regards,  
Bharath

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 9, 2016, 12:34pm UTC](https://discuss.elastic.co/t/rest-calls-for-elastic-search/41272/2 "2016-02-09T12:34:48Z")

</div>

Have you looked at the [elasticsearch filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:17pm UTC](https://discuss.elastic.co/t/rest-calls-for-elastic-search/41272/3 "2017-07-05T23:17:57Z")

</div>


