View last indexed data on elasticsearch

(Sara Thomas) #1


How can I see the last or the latest indexed data on elasticsearch?

I tried out the url


But I can only see the the field names which I had filtered in logstash and not any data.

(Adrien Grand) #2

Do something like

curl -XGET `http://x.x.x.x:9200/myindex_name/_search -d '
  "sort": [ {"_doc": "desc"} ]

(Sara Thomas) #3

Hi Adrien,

I had tried this out. But I am not getting the current indexed data.

In kibana, I could see the latest data indexed. But through the url I am only able to see data which dates some 2 weeks ago. Moreover, I could even see the exact total counts using the url


Why is that I am not able to see the current indexed data?

(Adrien Grand) #4

I think you are just not sorting based on the appropriate field? I did not know you had a timestamp field, so maybe what you are looking after is the following API call:

curl -XGET `http://x.x.x.x:9200/myindex_name/_search -d '
  "sort": [ {"timestamp": "desc"} ]

Just make sure to replace timestamp with the actual name of your timestamp field.

(Sara Thomas) #5

Thanks Adrien. It worked

(system) #6