# Graylog4 rest api search export

**URL:** <https://community.graylog.org/t/graylog4-rest-api-search-export/18727>\
**Category:** Graylog Central (peer support)\
**Created:** [February 8, 2021, 3:43pm UTC](https://community.graylog.org/t/graylog4-rest-api-search-export/18727 "2021-02-08T15:43:45Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [February 17, 2021, 11:15am UTC](https://community.graylog.org/t/graylog4-rest-api-search-export/18727/4 "2021-02-17T11:15:40Z")

</div>

he

search via API is different in 4.0 and the documentation lacks behind …

The “best” way currently is to use the export API:

```auto
## Search via Export API
curl -X "POST" "https://graylog/api/views/search/messages" \
     -H 'X-Requested-By: Mamamia' \
     -H 'Content-Type: application/json' \
     -H 'Accept: text/csv' \
     -u 'USER:PASSWORD' \
     -d $'{
  "streams": [
    "5e569003c793163fea1b3373"
  ],
  "query_string": {
    "type": "elasticsearch",
    "query_string": "section:boulder"
  },
  "timerange": {
    "type": "relative",
    "range": 30000
  }
}'

```

You might want to adjust the `streams` you want/can search in and the `query_string` - an your Graylog URL and username/passwort or token.

---

_[View the full topic](https://community.graylog.org/t/graylog4-rest-api-search-export/18727)._
