Elasticsearch v9
Elasticsearch v9 is a distributed search and analytics engine used for real-time data processing and retrieval.
Elasticsearch v9 is a powerful search and analytics engine that allows users to store, search, and analyze large volumes of data quickly and in near real-time. The connector enables seamless integration with Swimlane Turbine, allowing users to execute complex queries, retrieve search results, and manage asynchronous searches efficiently. This integration empowers security teams to automate data retrieval and analysis, enhancing threat detection and response capabilities within the Swimlane platform.
Limitations
None to date.
Supported Versions
The Elasticsearch connector leverages version 9 APIs.
Prerequisites
Before you can use the Elasticsearch v9 connector for Turbine, you'll need access to the Elasticsearch API. This requires the following:
- HTTP Basic authentication using the following parameters:
- URL: The endpoint for your Elasticsearch instance.
- Username: Your Elasticsearch username.
- Password: Your Elasticsearch password.
- API Key authentication using the following parameters:
- URL: The endpoint for your Elasticsearch instance.
- API Key: A valid API key for accessing Elasticsearch.
- HTTP Bearer authentication using the following parameters:
- URL: The endpoint for your Elasticsearch instance.
- Token: A bearer token such as a JWT for accessing Elasticsearch.
Capabilities
This Connector provides the following capabilities:
- Delete an async EQL search
- Delete an async ES|QL query
- Delete an async search
- Get a specific running ES|QL query information
- Get an ES|QL view
- Get async EQL search results
- Get async ES|QL query results
- Get async search results
- Get EQL search results
- Get running ES|QL queries information
- Get the async EQL status
- Get the async search status
- Run a search
- Run an async ES|QL query
- Run an async search ... and so on
Delete an async EQL search
Delete an async EQL search or a stored synchronous EQL search.
Elasticsearch documentation for this action can be found here.
Delete an async ES|QL query
If the query is still running, it is cancelled. Otherwise, the stored results are deleted.
Elasticsearch documentation for this action can be found here.
Delete an async search
If the asynchronous search is still running, it is cancelled. Otherwise, the saved search results are deleted.
Elasticsearch documentation for this action can be found here.
Get a specific running ES|QL query information
Returns extended information about a running ES|QL query.
Elasticsearch documentation for this action can be found here.
Get an ES|QL view
Get the current status and available results or stored results for an ES|QL view.
Elasticsearch documentation for this action can be found here.
Get async EQL search results
Get the current status and available results for an async EQL search or a stored synchronous EQL search.
Elasticsearch documentation for this action can be found here.
Get async ES|QL query results
Get the current status and available results or stored results for an ES|QL asynchronous query.
Elasticsearch documentation for this action can be found here.
Get async search results
Retrieve the results of a previously submitted asynchronous search request.
Elasticsearch documentation for this action can be found here.
Get EQL search results
Returns search results for an Event Query Language (EQL) query.
Elasticsearch documentation for this action can be found here.
Get running ES|QL queries information
Returns an object containing IDs and other information about the running ES|QL queries.
Elasticsearch documentation for this action can be found here.
Get the async EQL status
Get the current status for an async EQL search or a stored synchronous EQL search without returning results.
Elasticsearch documentation for this action can be found here.
Get the async search status
Get the status of a previously submitted async search request given its identifier, without retrieving search results.
Elasticsearch documentation for this action can be found here.
Run a search
Get search hits that match the query defined in the request.
Elasticsearch documentation for this action can be found here.
Run an async ES|QL query
Asynchronously run an ES|QL query, monitor its progress, and retrieve results when they become available.
Elasticsearch documentation for this action can be found here.
Run an async search
Runs a search asynchronously and returns partial results as shards complete, sorted by the requested indexed field.
Elasticsearch documentation for this action can be found here.
Run an ES|QL query
Get search results for an ES|QL query.
Elasticsearch documentation for this action can be found here.
Stop async ES|QL query
Interrupts the query execution and returns the results collected so far.
Elasticsearch documentation for this action can be found here.
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
apikey | API Key for the Elastic Search V8 instance. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Username for the HTTP Basic Authentication. | string | Required |
password | Password for the HTTP Basic Authentication. | string | Required |
verify_ssl | Verify SSL certificate. | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
HTTP Bearer Authentication
Authenticates using bearer token such as a JWT, etc.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The bearer token. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Delete an async EQL search
Delete an asynchronous or stored synchronous EQL search in Elasticsearch v9 using the specified ID as a path parameter.
Endpoint
- URL: /_eql/search/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Identifier for the search to delete. |
Input Example
{"path_parameters":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
acknowledged | boolean | Output field: acknowledged |
Output Example
{"status_code":200,"reason":"OK","json_body":{"acknowledged":true}}
Delete an async ES|QL query
Cancel a running Elasticsearch v9 query or delete stored results using the query ID.
Endpoint
- URL: /_query/async/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The unique identifier of the query. |
Input Example
{"path_parameters":{"id":"FmdMX2pIang3UWhLRU5QS0lqdlppYncaMUpYQ05oSkpTc3kwZ21EdC1tbFJXQToxOTI"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
acknowledged | boolean | Output field: acknowledged |
Output Example
{"status_code":200,"reason":"OK","json_body":{"acknowledged":true}}
Delete an async search
Cancel a running asynchronous search or delete saved search results in Elasticsearch v9 using the search ID.
Endpoint
- URL: /_async_search/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | A unique identifier for the async search. |
Input Example
{"path_parameters":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc="}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
acknowledged | boolean | Output field: acknowledged |
Output Example
{"status_code":200,"reason":"OK","json_body":{"acknowledged":true}}
Get a specific running ES|QL query information
Retrieve detailed information about a running ES|QL query in Elasticsearch v9 using the query ID.
Endpoint
- URL: /_query/queries/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The query ID. |
Input Example
{"path_parameters":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
start_time_millis | number | Output field: start_time_millis |
running_time_nanos | number | Output field: running_time_nanos |
query | string | Output field: query |
coordinating_node | string | Output field: coordinating_node |
data_nodes | array | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE","name":"test1,test2","start_time_millis":1611690235000,"running_time_nanos":1000000000,"query":"SELECT * FROM test1, test2","coordinating_node":"node1","data_nodes":["node1","node2","node3"]}}
Get an ES|QL view
Get the current status and available or stored results for an ES|QL view in Elasticsearch v9 using the specified name.
Endpoint
- URL: /_query/view/{{name}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.name | string | Required | The comma-separated view names to retrieve. Can be blank to return all views. |
Input Example
{"path_parameters":{"name":"test1,test2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
views | array | Output field: views |
views.name | string | Name of the resource |
views.query | string | Output field: views.query |
Output Example
{"status_code":200,"reason":"OK","json_body":{"views":[{},{}]}}
Get async EQL search results
Get the current status and available results for an async EQL search or a stored synchronous EQL search in Elasticsearch v9 using the specified ID.
Endpoint
- URL: /_eql/search/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.keep_alive | string | Optional | Period for which the search and its results are stored on the cluster. |
parameters.wait_for_completion_timeout | string | Optional | Timeout duration to wait for the request to finish; defaults to no timeout. |
path_parameters.id | string | Required | Identifier for the async or stored synchronous EQL search. |
Input Example
{"parameters":{"keep_alive":"1m","wait_for_completion_timeout":"30s"},"path_parameters":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
is_partial | boolean | Output field: is_partial |
is_running | boolean | Output field: is_running |
took | number | Output field: took |
timed_out | boolean | Output field: timed_out |
hits | object | Output field: hits |
hits.total | object | Output field: hits.total |
hits.total.value | number | Value for the parameter |
hits.total.relation | string | Output field: hits.total.relation |
hits.events | array | Output field: hits.events |
hits.events._index | string | Output field: hits.events._index |
hits.events._id | string | Unique identifier |
hits.events._source | object | Output field: hits.events._source |
hits.events._source.@timestamp | string | Output field: hits.events._source.@timestamp |
hits.events._source.event | object | Output field: hits.events._source.event |
hits.events._source.event.category | string | Output field: hits.events._source.event.category |
hits.events._source.event.id | string | Unique identifier |
hits.events._source.event.sequence | number | Output field: hits.events._source.event.sequence |
hits.events._source.process | object | Output field: hits.events._source.process |
hits.events._source.process.pid | number | Unique identifier |
hits.events._source.process.name | string | Name of the resource |
hits.events._source.process.command_line | string | Output field: hits.events._source.process.command_line |
hits.events._source.process.executable | string | Output field: hits.events._source.process.executable |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE","is_partial":false,"is_running":false,"took":6,"timed_out":false,"hits":{"total":{},"events":[]},"shard_failures":[]}}
Get async ES|QL query results
Get the current status and available or stored results for an ES|QL asynchronous query in Elasticsearch v9 using the query ID.
Endpoint
- URL: /_query/async/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description | |
|---|---|---|---|---|
parameters.drop_null_columns | boolean | Optional | Parameters for the Get async ES | QL query results action |
parameters.format | string | Optional | Parameters for the Get async ES | QL query results action |
parameters.keep_alive | string | Optional | Parameters for the Get async ES | QL query results action |
parameters.wait_for_completion_timeout | string | Optional | Parameters for the Get async ES | QL query results action |
path_parameters.id | string | Required | The unique identifier of the query. |
Input Example
{"parameters":{"drop_null_columns":true,"format":"json","keep_alive":"1m","wait_for_completion_timeout":"30s"},"path_parameters":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
is_running | boolean | Output field: is_running |
took | number | Output field: took |
is_partial | boolean | Output field: is_partial |
columns | array | Output field: columns |
columns.name | string | Name of the resource |
columns.type | string | Type of the resource |
values | array | Value for the parameter |
values.0 | string | Value for the parameter |
values.1 | string | Value for the parameter |
values.2 | string | Value for the parameter |
values.3 | string | Value for the parameter |
values.4 | string | Value for the parameter |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE","is_running":false,"took":48,"is_partial":false,"columns":[{"name":"author","type":"text"},{"name":"name","type":"text"},{"name":"page_count","type":"integer"}],"values":[["Peter F. Hamilton","Vernor Vinge","Frank Herbert","Alastair Reynolds","James S.A. Corey"],["Pandora's Star","A Deepness in the Sky","Dune","Revelation Space","Leviathan Wakes"],[768,613,604,585,561]]}}
Get async search results
Retrieve results of a previously submitted asynchronous search request in Elasticsearch v9 using the search ID.
Endpoint
- URL: /_async_search/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.keep_alive | string | Optional | The length of time that the async search should be available in the cluster. |
parameters.typed_keys | boolean | Optional | Specify whether aggregation and suggester names should be prefixed by their respective types in the response. |
parameters.wait_for_completion_timeout | string | Optional | Specifies to wait for the search to be completed up until the provided timeout. |
parameters.return_intermediate_results | boolean | Optional | Specifies whether the response should contain intermediate results if the query is still running when the wait_for_completion_timeout expires or if no wait_for_completion_timeout is specified. |
path_parameters.id | string | Required | A unique identifier for the async search. |
Input Example
{"parameters":{"keep_alive":"1m","typed_keys":false,"wait_for_completion_timeout":"30s","return_intermediate_results":false},"path_parameters":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
is_partial | boolean | Output field: is_partial |
is_running | boolean | Output field: is_running |
start_time_in_millis | number | Output field: start_time_in_millis |
expiration_time_in_millis | number | Output field: expiration_time_in_millis |
completion_time_in_millis | number | Output field: completion_time_in_millis |
response | object | Output field: response |
response.took | number | Output field: response.took |
response.timed_out | boolean | Output field: response.timed_out |
response.num_reduce_phases | number | Output field: response.num_reduce_phases |
response._shards | object | Output field: response._shards |
response._shards.total | number | Output field: response._shards.total |
response._shards.successful | number | Whether the operation was successful |
response._shards.skipped | number | Output field: response._shards.skipped |
response._shards.failed | number | Output field: response._shards.failed |
response.hits | object | Output field: response.hits |
response.hits.total | object | Output field: response.hits.total |
response.hits.total.value | number | Value for the parameter |
response.hits.total.relation | string | Output field: response.hits.total.relation |
response.hits.max_score | object | Score value |
response.hits.hits | array | Output field: response.hits.hits |
response.hits.hits.file_name | string | Name of the resource |
response.hits.hits.file | string | Output field: response.hits.hits.file |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc=","is_partial":false,"is_running":false,"start_time_in_millis":1583945890986,"expiration_time_in_millis":1584377890986,"completion_time_in_millis":1583945903130,"response":{"took":12144,"timed_out":false,"num_reduce_phases":46,"_shards":{},"hits":{},"aggregations":{}}}}
Get EQL search results
Retrieve search results for an Event Query Language (EQL) query in Elasticsearch v9 using specified index and query parameters.
Endpoint
- URL: /{{index}}/_eql/search
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.allow_no_indices | boolean | Optional | If true, index expressions that resolve to no indices are allowed and return an empty result. |
parameters.allow_partial_search_results | boolean | Optional | If true, returns partial results on shard failures; if false, returns an error. |
parameters.allow_partial_sequence_results | boolean | Optional | If true, sequence queries return partial results on shard failures; only applies when allow_partial_search_results is true. |
parameters.expand_wildcards | string | Optional | Whether to expand wildcard expressions to concrete indices (all, open, closed, hidden, or none). |
parameters.ccs_minimize_roundtrips | boolean | Optional | Whether network round-trips should be minimized for cross-cluster search requests. |
parameters.ignore_unavailable | boolean | Optional | If false, errors on unavailable concrete targets; if true, silently ignores them. |
parameters.keep_alive | string | Optional | Period for which the search and its results are stored on the cluster. |
parameters.keep_on_completion | boolean | Optional | If true, the search and its results are stored on the cluster. |
parameters.wait_for_completion_timeout | string | Optional | Timeout duration to wait for the request to finish; defaults to no timeout. |
path_parameters.index | string | Required | Data stream, index, or alias to search. |
query | string | Optional | EQL query to run. |
case_sensitive | boolean | Optional | Whether the EQL query is case sensitive. |
event_category_field | string | Optional | Field containing the event classification, such as process, file, or network. |
tiebreaker_field | string | Optional | Field used to sort hits with the same timestamp in ascending order. |
timestamp_field | string | Optional | Field containing event timestamp. |
fetch_size | number | Optional | Maximum number of events to search at a time for sequence queries. |
filter | object | Optional | Query DSL filter applied to events on which the EQL query runs. |
filter.term | object | Optional | Parameter for Get EQL search results |
filter.term.event.type | string | Optional | Type of the resource |
keep_alive | string | Optional | Duration to keep the search and results stored on the cluster. |
keep_on_completion | boolean | Optional | If true, stores the search and its results on the cluster. |
wait_for_completion_timeout | string | Optional | Duration to wait for the request to finish. |
allow_partial_search_results | boolean | Optional | If true, query continues on shard failures and returns results from available shards. |
allow_partial_sequence_results | boolean | Optional | For sequences only; if true, returns results from available shards when allow_partial_search_results is true. |
size | number | Optional | For basic queries, maximum number of matching events to return. |
Input Example
{"parameters":{"allow_no_indices":true,"allow_partial_search_results":true,"allow_partial_sequence_results":true,"expand_wildcards":"open","ccs_minimize_roundtrips":true,"ignore_unavailable":false,"keep_alive":"1m","keep_on_completion":true,"wait_for_completion_timeout":"30s"},"json_body":{"query":"process where process.name == \"regsvr32.exe\"","case_sensitive":true,"event_category_field":"event.category","tiebreaker_field":"event.sequence","timestamp_field":"@timestamp","fetch_size":1000,"filter":{"term":{"event.type":"start"}},"keep_alive":"1m","keep_on_completion":true,"wait_for_completion_timeout":"30s","allow_partial_search_results":true,"allow_partial_sequence_results":false,"size":10,"fields":[{"field":"process.name","format":"text","include_unmapped":false}],"result_position":"tail","runtime_mappings":{"process_label":{"type":"keyword","script":{"source":"emit(doc['process.name'].value)","lang":"painless"}}},"max_samples_per_key":1},"path_parameters":{"index":"my-data-stream"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
is_partial | boolean | Output field: is_partial |
is_running | boolean | Output field: is_running |
took | number | Output field: took |
timed_out | boolean | Output field: timed_out |
hits | object | Output field: hits |
hits.total | object | Output field: hits.total |
hits.total.value | number | Value for the parameter |
hits.total.relation | string | Output field: hits.total.relation |
hits.sequences | array | Output field: hits.sequences |
hits.sequences.join_keys | array | Output field: hits.sequences.join_keys |
hits.sequences.events | array | Output field: hits.sequences.events |
hits.sequences.events._index | string | Output field: hits.sequences.events._index |
hits.sequences.events._id | string | Unique identifier |
hits.sequences.events._source | object | Output field: hits.sequences.events._source |
hits.sequences.events._source.@timestamp | string | Output field: hits.sequences.events._source.@timestamp |
hits.sequences.events._source.event | object | Output field: hits.sequences.events._source.event |
hits.sequences.events._source.process | object | Output field: hits.sequences.events._source.process |
Output Example
{"status_code":200,"reason":"OK","json_body":{"is_partial":false,"is_running":false,"took":6,"timed_out":false,"hits":{"total":{},"sequences":[]}}}
Get running ES|QL queries information
Returns an object containing IDs and other details about the running ES|QL queries in Elasticsearch v9.
Endpoint
- URL: /_query/queries
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
queries | object | Output field: queries |
queries.id | number | Unique identifier |
queries.node | string | Output field: queries.node |
queries.start_time_millis | number | Output field: queries.start_time_millis |
queries.running_time_nanos | number | Output field: queries.running_time_nanos |
queries.query | string | Output field: queries.query |
Output Example
{"status_code":200,"reason":"OK","json_body":{"queries":{"id":1111,"node":"node1","start_time_millis":1611690235000,"running_time_nanos":1000000000,"query":"SELECT * FROM test1, test2"}}}
Get the async EQL status
Retrieve the current status of an asynchronous or stored synchronous EQL search in Elasticsearch v9 using the search ID.
Endpoint
- URL: /_eql/search/status/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Get the current status for an async EQL search or a stored synchronous EQL search without returning results. |
Input Example
{"path_parameters":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
is_running | boolean | Output field: is_running |
is_partial | boolean | Output field: is_partial |
start_time_in_millis | number | Output field: start_time_in_millis |
expiration_time_in_millis | number | Output field: expiration_time_in_millis |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE=","is_running":true,"is_partial":true,"start_time_in_millis":1611690235000,"expiration_time_in_millis":1611690295000}}
Get the async search status
Retrieve the status of a previously submitted async search request in Elasticsearch v9 using its identifier, without fetching the search results.
Endpoint
- URL: /_async_search/status/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.keep_alive | string | Optional | The length of time that the async search needs to be available. |
path_parameters.id | string | Required | A unique identifier for the async search. |
Input Example
{"parameters":{"keep_alive":"1m"},"path_parameters":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
is_running | boolean | Output field: is_running |
is_partial | boolean | Output field: is_partial |
start_time_in_millis | number | Output field: start_time_in_millis |
expiration_time_in_millis | number | Output field: expiration_time_in_millis |
_shards | object | Output field: _shards |
_shards.total | number | Output field: _shards.total |
_shards.successful | number | Whether the operation was successful |
_shards.skipped | number | Output field: _shards.skipped |
_shards.failed | number | Output field: _shards.failed |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc=","is_running":true,"is_partial":true,"start_time_in_millis":1583945890986,"expiration_time_in_millis":1584377890986,"_shards":{"total":562,"successful":188,"skipped":0,"failed":0}}}
Run a search
Retrieve search hits from Elasticsearch v9 that match the specified query in the request, using index as a path parameter.
Endpoint
- URL: /{{index}}/_search
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.allow_no_indices | boolean | Optional | If true, index expressions that resolve to no indices are allowed and return an empty result. |
parameters.allow_partial_search_results | boolean | Optional | If true, returns partial results on shard timeouts or failures; if false, returns an error. |
parameters.analyzer | string | Optional | Analyzer for the query string; only valid when q is specified. |
parameters.analyze_wildcard | boolean | Optional | If true, wildcard and prefix queries are analyzed; only valid when q is specified. |
parameters.batched_reduce_size | number | Optional | Number of shard results reduced at once on the coordinating node. |
parameters.ccs_minimize_roundtrips | boolean | Optional | If true, minimizes network round-trips for cross-cluster search requests. |
parameters.default_operator | string | Optional | Default operator for query string query (and or or); only valid when q is specified. |
parameters.df | string | Optional | Default field when no field prefix is given in the query string; only valid when q is specified. |
parameters.docvalue_fields | array | Optional | Comma-separated list of fields to return as docvalue representation for each hit. |
parameters.expand_wildcards | string | Optional | Index types wildcard patterns can match (all, open, closed, hidden, or none). |
parameters.explain | boolean | Optional | If true, returns detailed score computation information as part of a hit. |
parameters.ignore_throttled | boolean | Optional | If true, concrete, expanded, or aliased indices are ignored when frozen. |
parameters.ignore_unavailable | boolean | Optional | If false, errors on unavailable concrete targets; if true, silently ignores them. |
parameters.include_named_queries_score | boolean | Optional | If true, includes score contribution from named queries in the response. |
parameters.lenient | boolean | Optional | If true, format-based query failures in the query string are ignored; only valid when q is specified. |
parameters.max_concurrent_shard_requests | number | Optional | Concurrent shard requests per node; limits search impact on the cluster. |
parameters.preference | string | Optional | Nodes and shards used for the search (e.g. _local, _only_local, _shards). |
parameters.pre_filter_shard_size | number | Optional | Threshold to enforce a pre-filter roundtrip when shard count exceeds this value. |
parameters.request_cache | boolean | Optional | If true, enables search result caching for requests where size is 0. |
parameters.routing | array | Optional | Custom routing value to route operations to a specific shard. |
parameters.scroll | string | Optional | Period to retain the search context for scrolling. |
parameters.search_type | string | Optional | How distributed term frequencies are calculated for relevance scoring. |
parameters.stats | array | Optional | Tags for logging and statistical purposes. |
parameters.stored_fields | array | Optional | Comma-separated list of stored fields to return as part of a hit. |
parameters.suggest_field | string | Optional | Field to use for suggestions. |
Input Example
{"parameters":{"allow_no_indices":true,"allow_partial_search_results":true,"analyzer":"standard","analyze_wildcard":false,"batched_reduce_size":5,"ccs_minimize_roundtrips":true,"default_operator":"OR","df":"_all","docvalue_fields":["date"],"expand_wildcards":"open","explain":false,"ignore_throttled":true,"ignore_unavailable":false,"include_named_queries_score":false,"lenient":false,"max_concurrent_shard_requests":5,"preference":"_local","pre_filter_shard_size":128,"request_cache":true,"routing":[],"scroll":"1m","search_type":"query_then_fetch","stats":["search"],"stored_fields":[],"suggest_field":"title.suggest","suggest_mode":"missing","suggest_size":5,"suggest_text":"elasticsearch","terminate_after":0,"timeout":"1m","track_total_hits":true,"track_scores":false,"typed_keys":false,"rest_total_hits_as_int":false,"version":false,"_source":true,"_source_excludes":[],"_source_exclude_vectors":false,"_source_includes":["date"],"seq_no_primary_term":false,"q":"*:*","size":10,"from":0,"sort":"date:asc"},"json_body":{"aggregations":{"sale_date":{"date_histogram":{"field":"date","calendar_interval":"1d"}}},"collapse":{"field":"user.id","inner_hits":{"name":"recent_sales","size":3,"from":0,"collapse":{"field":"category.id"},"docvalue_fields":[{"field":"date","format":"epoch_millis","include_unmapped":false}],"explain":false,"highlight":{"fields":{"title":{}}},"ignore_unmapped":false,"script_fields":{"amount_usd":{"script":{"source":"doc['amount'].value","lang":"painless"},"ignore_failure":false}},"seq_no_primary_term":false,"fields":[{"field":"amount","format":"0.00","include_unmapped":false}],"sort":[{"date":{"order":"desc"}}],"_source":true,"stored_fields":["title"],"track_scores":false,"version":false}},"explain":false,"ext":{},"from":0,"highlight":{"type":"unified","boundary_chars":".,!? \t\n","boundary_max_scan":20,"boundary_scanner":"sentence","boundary_scanner_locale":"en-US","fragmenter":"span","fragment_size":100,"highlight_filter":true,"highlight_query":{"match":{"title":"elasticsearch"}},"max_fragment_length":0,"max_analyzed_offset":1000000,"no_match_size":0,"number_of_fragments":5,"options":{},"order":"score","phrase_limit":256,"post_tags":["</em>"],"pre_tags":["<em>"],"require_field_match":true,"encoder":"html","fields":{"title":{"type":"unified","fragment_size":150,"number_of_fragments":3}}},"track_total_hits":true,"indices_boost":[{"sales-*":1.5}],"docvalue_fields":[{"field":"date","format":"epoch_millis","include_unmapped":false}],"knn":{"field":"image_vector","query_vector":[0.12,0.34,0.56],"k":10,"num_candidates":100,"visit_percentage":50,"boost":1,"similarity":0.7,"filter":{"term":{"status":"published"}},"inner_hits":{"name":"knn_hits","size":3,"from":0,"_source":true,"track_scores":false,"version":false,"seq_no_primary_term":false}},"rescore_vector":{"oversample":2},"rank":{"rrf":{"retrievers":[{"standard":{"query":{"match":{"title":"elasticsearch"}}}},{"knn":{"field":"image_vector","query_vector":[0.12,0.34,0.56],"k":10,"num_candidates":100}}],"rank_constant":60,"rank_window_size":100}},"_name":"daily_sales_search","min_score":0.5,"post_filter":{"term":{"status":"published"}},"profile":false,"query":{"match_all":{}},"retriever":{"standard":{"query":{"match":{"title":"elasticsearch"}},"filter":{"term":{"status":"published"}},"min_score":0.5,"_name":"standard_retriever"}},"rescore":{"window_size":10,"query":{"rescore_query":{"match":{"title":"elasticsearch"}},"query_weight":1,"rescore_query_weight":2,"score_mode":"multiply"},"learning_to_rank":{"model_id":"ltr-model-1","params":{"keywords":"elasticsearch"}},"script":{"source":"return _score * 2;","lang":"painless"}},"script_fields":{"day_of_week":{"script":{"source":"doc['date'].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT)","lang":"painless"},"ignore_failure":false}},"search_after":[1583945890986,"sale-001"],"size":10,"slice":{"id":"0","max":5,"field":"date"},"sort":[{"date":{"order":"asc"}}],"_source":{"includes":["date","amount"],"excludes":["internal_notes"]},"fields":[{"field":"date","format":"strict_date_optional_time","include_unmapped":false}],"suggest":{"text":"elasticsearch","simple_phrase":{"phrase":{"field":"title.trigram","size":1,"gram_size":3,"direct_generator":[{"field":"title.trigram","suggest_mode":"missing"}]}}},"terminate_after":0,"timeout":"1m","track_scores":false,"version":false,"seq_no_primary_term":false,"stored_fields":["title"],"pit":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc","keep_alive":"1m"},"runtime_mappings":{"day_of_week":{"type":"keyword","script":{"source":"emit(doc['date'].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT))","lang":"painless"}}},"stats":["search"]},"path_parameters":{"index":"_all"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
took | number | Output field: took |
timed_out | boolean | Output field: timed_out |
_shards | object | Output field: _shards |
_shards.total | number | Output field: _shards.total |
_shards.successful | number | Whether the operation was successful |
_shards.skipped | number | Output field: _shards.skipped |
_shards.failed | number | Output field: _shards.failed |
hits | object | Output field: hits |
hits.total | object | Output field: hits.total |
hits.total.value | number | Value for the parameter |
hits.total.relation | string | Output field: hits.total.relation |
hits.max_score | number | Score value |
hits.hits | array | Output field: hits.hits |
hits.hits._index | string | Output field: hits.hits._index |
hits.hits._id | string | Unique identifier |
hits.hits._score | number | Score value |
hits.hits._source | object | Output field: hits.hits._source |
hits.hits._source.@timestamp | string | Output field: hits.hits._source.@timestamp |
hits.hits._source.http | object | Output field: hits.hits._source.http |
hits.hits._source.http.request | object | Output field: hits.hits._source.http.request |
hits.hits._source.http.response | object | Output field: hits.hits._source.http.response |
hits.hits._source.http.version | string | Output field: hits.hits._source.http.version |
hits.hits._source.source | object | Output field: hits.hits._source.source |
Output Example
{"status_code":200,"reason":"OK","json_body":{"took":5,"timed_out":false,"_shards":{"total":1,"successful":1,"skipped":0,"failed":0},"hits":{"total":{},"max_score":1.3862942,"hits":[]}}}
Run an async ES|QL query
Asynchronously execute an ES|QL query in Elasticsearch v9, monitor its progress, and retrieve results upon completion. Requires a JSON body with the query.
Endpoint
- URL: /_query/async
- Method: POST
Input
Argument Name | Type | Required | Description | |
|---|---|---|---|---|
parameters.allow_partial_results | boolean | Optional | If true, returns partial results on shard failures; if false, the query fails on any failure. | |
parameters.delimiter | string | Optional | Character between values in a CSV row; valid only when format is csv. | |
parameters.drop_null_columns | boolean | Optional | If true, removes all-null columns from results and includes an all_columns section. | |
parameters.format | string | Optional | Short version of the Accept header for the response format. | |
query | string | Optional | ES | QL query string to run. |
columnar | boolean | Optional | If true, returns results in columnar format for JSON, YAML, CBOR, and smile formats. | |
filter | object | Optional | Query DSL filter for the set of documents the ES | QL query runs on. |
filter.term | object | Optional | Parameter for Run an async ES | QL query |
filter.term.event.dataset | string | Optional | Response data | |
time_zone | string | Optional | Default timezone for the query. | |
locale | string | Optional | Locale used to format results, especially dates. | |
params | array | Optional | Parameter values for question mark (?) placeholders in the query string. | |
profile | boolean | Optional | If true, includes a profile object with query execution debugging information. | |
tables | object | Optional | Tables to use with the LOOKUP operation, keyed by table name and column name. | |
tables.threat_list | object | Optional | Parameter for Run an async ES | QL query |
tables.threat_list.ip | array | Optional | Parameter for Run an async ES | QL query |
tables.threat_list.name | array | Optional | Name of the resource | |
include_ccs_metadata | boolean | Optional | If true, includes _clusters metadata for cross-cluster/cross-project queries. | |
include_execution_metadata | boolean | Optional | If true, includes execution metadata for CCS and non-CCS queries. | |
wait_for_completion_timeout | string | Optional | Period to wait for results before returning an async query ID. | |
keep_alive | string | Optional | Period the query and results are stored in the cluster. | |
keep_on_completion | boolean | Optional | If true, always stores the query and results on the cluster. |
Input Example
{"parameters":{"allow_partial_results":true,"delimiter":",","drop_null_columns":false,"format":"json"},"json_body":{"query":"FROM logs | WHERE status == ? AND @timestamp > ? | LIMIT 10","columnar":false,"filter":{"term":{"event.dataset":"logs"}},"time_zone":"UTC","locale":"en-US","params":["published","2024-01-01T00:00:00.000Z"],"profile":false,"tables":{"threat_list":{"ip":["1.2.3.4","5.6.7.8"],"name":["malware","phishing"]}},"include_ccs_metadata":false,"include_execution_metadata":false,"wait_for_completion_timeout":"1s","keep_alive":"5d","keep_on_completion":false}}
Output
Parameter | Type | Description | |
|---|---|---|---|
status_code | number | HTTP status code of the response | |
reason | string | Response reason phrase | |
query | string | ES | QL query string that was executed. |
wait_for_completion_timeout | string | Timeout used when waiting for query completion. | |
include_ccs_metadata | boolean | Whether cross-cluster metadata was requested in the query. |
Output Example
{"status_code":200,"reason":"OK","json_body":{"query":"FROM library,remote-*:library | EVAL year = DATE_TRUNC(1 YEARS, release_date) | ...","wait_for_completion_timeout":"2s","include_ccs_metadata":true}}
Run an async search
Execute a search asynchronously in Elasticsearch v9, returning partial results as shards complete. Requires path parameters including the index.
Endpoint
- URL: /{{index}}/_async_search
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.wait_for_completion_timeout | string | Optional | Blocks and waits until the search is completed up to a certain timeout. |
parameters.keep_alive | string | Optional | Specifies how long the async search needs to be available. |
parameters.keep_on_completion | boolean | Optional | If true, results are stored for later retrieval when the search completes within the wait_for_completion_timeout. |
parameters.allow_no_indices | boolean | Optional | A setting that does two separate checks on the index expression. |
parameters.allow_partial_search_results | boolean | Optional | Indicate if an error should be returned if there is a partial search failure or timeout. |
parameters.analyzer | string | Optional | The analyzer to use for the query string. |
parameters.analyze_wildcard | boolean | Optional | Specify whether wildcard and prefix queries should be analyzed. |
parameters.batched_reduce_size | number | Optional | Affects how often partial results become available, which happens whenever shard results are reduced. |
parameters.ccs_minimize_roundtrips | boolean | Optional | The default value is the only supported value. |
parameters.default_operator | string | Optional | The default operator for query string query (AND or OR). |
parameters.df | string | Optional | The field to use as default where no field prefix is given in the query string. |
parameters.docvalue_fields | array | Optional | Comma-separated list of fields to return as docvalue representation for each hit. |
parameters.expand_wildcards | string | Optional | Whether to expand wildcard expressions to concrete indices (all, open, closed, hidden, or none). |
parameters.explain | boolean | Optional | Whether to return detailed score computation information as part of a hit. |
parameters.ignore_throttled | boolean | Optional | Whether concrete, expanded, or aliased indices should be ignored when throttled. |
parameters.ignore_unavailable | boolean | Optional | If false, returns an error for missing or unavailable concrete indices; if true, silently ignores them. |
parameters.lenient | boolean | Optional | Whether format-based query failures (e.g. text on a numeric field) should be ignored. |
parameters.max_concurrent_shard_requests | number | Optional | Number of concurrent shard requests per node; use to limit search impact on the cluster. |
parameters.preference | string | Optional | Specifies the node or shard the operation should be performed on. |
parameters.request_cache | boolean | Optional | Whether request cache should be used for this request (defaults to true). |
parameters.routing | array | Optional | Comma-separated list of specific routing values. |
parameters.search_type | string | Optional | Search operation type. |
parameters.stats | array | Optional | Tags for logging and statistical purposes. |
parameters.stored_fields | array | Optional | Comma-separated list of stored fields to return as part of a hit. |
parameters.suggest_field | string | Optional | Field to use for suggestions. |
Input Example
{"parameters":{"wait_for_completion_timeout":"30s","keep_alive":"1m","keep_on_completion":true,"allow_no_indices":true,"allow_partial_search_results":true,"analyzer":"standard","analyze_wildcard":false,"batched_reduce_size":5,"ccs_minimize_roundtrips":true,"default_operator":"OR","df":"_all","docvalue_fields":["date"],"expand_wildcards":"open","explain":false,"ignore_throttled":true,"ignore_unavailable":false,"lenient":false,"max_concurrent_shard_requests":5,"preference":"_local","request_cache":true,"routing":[],"search_type":"query_then_fetch","stats":["async_search"],"stored_fields":[],"suggest_field":"title.suggest","suggest_mode":"missing","suggest_size":5,"suggest_text":"elasticsearch","terminate_after":0,"timeout":"1m","track_total_hits":true,"track_scores":false,"typed_keys":false,"rest_total_hits_as_int":false,"version":false,"_source":true,"_source_excludes":[],"_source_includes":["date"],"seq_no_primary_term":false,"q":"*:*","size":10,"from":0,"sort":"date:asc"},"json_body":{"aggregations":{"sale_date":{"date_histogram":{"field":"date","calendar_interval":"1d"}}},"collapse":{"field":"user.id","inner_hits":{"name":"recent_sales","size":3,"from":0,"collapse":{"field":"category.id"},"docvalue_fields":[{"field":"date","format":"epoch_millis","include_unmapped":false}],"explain":false,"highlight":{"fields":{"title":{}}},"ignore_unmapped":false,"script_fields":{"amount_usd":{"script":{"source":"doc['amount'].value","lang":"painless"},"ignore_failure":false}},"seq_no_primary_term":false,"fields":[{"field":"amount","format":"0.00","include_unmapped":false}],"sort":[{"date":{"order":"desc"}}],"_source":true,"stored_fields":["title"],"track_scores":false,"version":false}},"explain":false,"ext":{},"from":0,"highlight":{"type":"unified","boundary_chars":".,!? \t\n","boundary_max_scan":20,"boundary_scanner":"sentence","boundary_scanner_locale":"en-US","fragmenter":"span","fragment_size":100,"highlight_filter":true,"highlight_query":{"match":{"title":"elasticsearch"}},"max_fragment_length":0,"max_analyzed_offset":1000000,"no_match_size":0,"number_of_fragments":5,"options":{},"order":"score","phrase_limit":256,"post_tags":["</em>"],"pre_tags":["<em>"],"require_field_match":true,"encoder":"html","fields":{"title":{"type":"unified","fragment_size":150,"number_of_fragments":3}}},"track_total_hits":true,"indices_boost":[{"sales-*":1.5}],"docvalue_fields":[{"field":"date","format":"epoch_millis","include_unmapped":false}],"knn":{"field":"image_vector","query_vector":[0.12,0.34,0.56],"query_vector_builder":{"text_embedding":{"model_id":"sentence-transformers__all-minilm-l6-v2","model_text":"search query text"}},"k":10,"num_candidates":100,"visit_percentage":50,"boost":1,"similarity":0.7,"filter":{"term":{"status":"published"}},"inner_hits":{"name":"knn_hits","size":3,"from":0,"_source":true,"track_scores":false,"version":false,"seq_no_primary_term":false}},"rescore_vector":{"oversample":2},"_name":"daily_sales_async_search","min_score":0.5,"post_filter":{"term":{"status":"published"}},"profile":false,"query":{"match_all":{}},"rescore":{"window_size":10,"query":{"rescore_query":{"match":{"title":"elasticsearch"}},"query_weight":1,"rescore_query_weight":2,"score_mode":"multiply"},"learning_to_rank":{"model_id":"ltr-model-1","params":{"keywords":"elasticsearch"}},"script":{"source":"return _score * 2;","lang":"painless"}},"script_fields":{"day_of_week":{"script":{"source":"doc['date'].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT)","lang":"painless"},"ignore_failure":false}},"search_after":[1583945890986,"sale-001"],"size":10,"slice":{"id":"0","max":5,"field":"date"},"sort":[{"date":{"order":"asc"}}],"_source":{"includes":["date","amount"],"excludes":["internal_notes"]},"fields":[{"field":"date","format":"strict_date_optional_time","include_unmapped":false}],"suggest":{"text":"elasticsearch","simple_phrase":{"phrase":{"field":"title.trigram","size":1,"gram_size":3,"direct_generator":[{"field":"title.trigram","suggest_mode":"missing"}]}}},"terminate_after":0,"timeout":"1m","track_scores":false,"version":false,"seq_no_primary_term":false,"stored_fields":["title"],"pit":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc","keep_alive":"1m"},"runtime_mappings":{"day_of_week":{"type":"keyword","script":{"source":"emit(doc['date'].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT))","lang":"painless"}}},"stats":["async_search"]},"path_parameters":{"index":"_all"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
is_partial | boolean | Output field: is_partial |
is_running | boolean | Output field: is_running |
start_time_in_millis | number | Output field: start_time_in_millis |
expiration_time_in_millis | number | Output field: expiration_time_in_millis |
response | object | Output field: response |
response.took | number | Output field: response.took |
response.timed_out | boolean | Output field: response.timed_out |
response.num_reduce_phases | number | Output field: response.num_reduce_phases |
response._shards | object | Output field: response._shards |
response._shards.total | number | Output field: response._shards.total |
response._shards.successful | number | Whether the operation was successful |
response._shards.skipped | number | Output field: response._shards.skipped |
response._shards.failed | number | Output field: response._shards.failed |
response.hits | object | Output field: response.hits |
response.hits.total | object | Output field: response.hits.total |
response.hits.total.value | number | Value for the parameter |
response.hits.total.relation | string | Output field: response.hits.total.relation |
response.hits.max_score | object | Score value |
response.hits.hits | array | Output field: response.hits.hits |
response.hits.hits.file_name | string | Name of the resource |
response.hits.hits.file | string | Output field: response.hits.hits.file |
Output Example
{"status_code":200,"reason":"OK","json_body":{"id":"FmRldE8zREVEUzA2ZVpUeGs2ejJFUFEaMkZ5QTVrSTZSaVN3WlNFVmtlWHJsdzoxMDc=","is_partial":true,"is_running":true,"start_time_in_millis":1583945890986,"expiration_time_in_millis":1584377890986,"response":{"took":1122,"timed_out":false,"num_reduce_phases":0,"_shards":{},"hits":{}}}}
Run an ES|QL query
Get search results for an ES|QL query in Elasticsearch v9 using the specified JSON body containing the query.
Endpoint
- URL: /_query
- Method: POST
Input
Argument Name | Type | Required | Description | |
|---|---|---|---|---|
parameters.format | string | Optional | Short version of the Accept header for the response format. | |
parameters.delimiter | string | Optional | Character between values in a CSV row; valid only when format is csv. | |
parameters.drop_null_columns | boolean | Optional | If true, removes all-null columns from results and includes an all_columns section. | |
parameters.allow_partial_results | boolean | Optional | If true, returns partial results on shard failures; if false, the query fails on any failure. | |
query | string | Optional | ES | QL query string to run. |
columnar | boolean | Optional | If true, returns results in columnar format for JSON, YAML, CBOR, and smile formats. | |
filter | object | Optional | Query DSL filter for the set of documents the ES | QL query runs on. |
filter.term | object | Optional | Parameter for Run an ES | QL query |
filter.term.event.dataset | string | Optional | Response data | |
time_zone | string | Optional | Default timezone for the query. | |
locale | string | Optional | Locale used to format results, especially dates. | |
params | array | Optional | Parameter values for question mark (?) placeholders in the query string. | |
profile | boolean | Optional | If true, includes a profile object with query execution debugging information. | |
tables | object | Optional | Tables to use with the LOOKUP operation, keyed by table name and column name. | |
tables.threat_list | object | Optional | Parameter for Run an ES | QL query |
tables.threat_list.ip | array | Optional | Parameter for Run an ES | QL query |
tables.threat_list.name | array | Optional | Name of the resource | |
include_ccs_metadata | boolean | Optional | If true, includes _clusters metadata for cross-cluster/cross-project queries. | |
include_execution_metadata | boolean | Optional | If true, includes execution metadata for CCS and non-CCS queries. |
Input Example
{"parameters":{"format":"json","delimiter":",","drop_null_columns":false,"allow_partial_results":true},"json_body":{"query":"FROM logs | WHERE status == ? AND @timestamp > ? | LIMIT 10","columnar":false,"filter":{"term":{"event.dataset":"logs"}},"time_zone":"UTC","locale":"en-US","params":["published","2024-01-01T00:00:00.000Z"],"profile":false,"tables":{"threat_list":{"ip":["1.2.3.4","5.6.7.8"],"name":["malware","phishing"]}},"include_ccs_metadata":false,"include_execution_metadata":false}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Stop async ES|QL query
Interrupt an Elasticsearch v9 asynchronous query execution and return the results obtained so far. Requires the query ID as a path parameter.
Endpoint
- URL: /_query/async/{{id}}/stop
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.drop_null_columns | boolean | Optional | Indicates whether columns that are entirely null will be removed from the columns and values portion of the results. |
path_parameters.id | string | Required | The unique identifier of the query. |
Input Example
{"parameters":{"drop_null_columns":true},"path_parameters":{"id":"FkpMRkJGS1gzVDRlM3g4ZzMyRGlLbkEaTXlJZHdNT09TU2VTZVBoNDM3cFZMUToxMDM"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
took | number | Output field: took |
is_partial | boolean | Output field: is_partial |
all_columns | array | Output field: all_columns |
all_columns.name | string | Name of the resource |
all_columns.type | string | Type of the resource |
columns | array | Output field: columns |
columns.name | string | Name of the resource |
columns.type | string | Type of the resource |
values | array | Value for the parameter |
values.0 | string | Value for the parameter |
values.1 | string | Value for the parameter |
values.2 | string | Value for the parameter |
_clusters | object | Output field: _clusters |
_clusters.total | number | Output field: _clusters.total |
_clusters.successful | number | Whether the operation was successful |
_clusters.running | number | Output field: _clusters.running |
_clusters.skipped | number | Output field: _clusters.skipped |
_clusters.partial | number | Output field: _clusters.partial |
_clusters.failed | number | Output field: _clusters.failed |
_clusters.details | object | Output field: _clusters.details |
_clusters.details.(local) | object | Output field: _clusters.details.(local) |
_clusters.details.(local).status | string | Status value |
_clusters.details.(local).indices | string | Output field: _clusters.details.(local).indices |
Output Example
{"status_code":200,"reason":"OK","json_body":{"took":48,"is_partial":true,"all_columns":[{"name":"author","type":"text"},{"name":"name","type":"text"},{"name":"page_count","type":"integer"}],"columns":[{"name":"author","type":"text"},{"name":"name","type":"text"},{"name":"page_count","type":"integer"}],"values":[["Peter F. Hamilton","Vernor Vinge","Frank Herbert"],["Pandora's Star","A Deepness in the Sky","Dune"],[768,613,604]],"_clusters":{"total":2,"successful":2,"running":0,"skipped":0,"parti...
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |