I am running this query to get the IP addresses from ES indices however I noticed that I am unable to get all the src_ips and then found the scroll parameter.
Can someone please confirm if scroll API will help me find all the src_ips since beginning?
If you want just the IPs and none of the docs you should use the composite aggregation and page results with the after parameter rather than use the terms aggregation
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.