Spaces method and path for this operation:
Refer to Spaces for more information.
Runs an ES|QL query as the current user. The server applies a space filter and limits the response to at most 1000 rows.
The query determines which indices it reads. Elasticsearch index privileges limit which indices the current user can access.
The space comes from the request URL (/s/{spaceId}/…) or defaults to the default space. The request body cannot change the space or replace the space filter.
Returns a 404 response when Context Engine is turned off in this space (contextEngine:enabled).
For more information, refer to the Context Engine documentation.
[Required authorization] Route required privileges: contextEngine:read.
Body
-
Maximum rows to return. Defaults to 100; a trailing
LIMITin the query is capped to this value.Minimum value is
1, maximum value is1000. -
Values for
?nameplaceholders in the query. -
The ES|QL query to run. Its FROM decides which Elasticsearch indices are read (normally
ai-index-*); the server adds the space filter and a row limit.Minimum length is
1, maximum length is10000.
curl \
-X POST "https://${KIBANA_URL}/api/context_engine/ai_index/_query" \
-H "Authorization: ApiKey ${API_KEY}" \
-H "kbn-xsrf: true" \
-H "Content-Type: application/json" \
-d '{
"query": "FROM ai-index-* | WHERE type == ?type | KEEP title, type, attributes | LIMIT 10",
"params": { "type": "faq" },
"limit": 10
}'
POST kbn:/api/context_engine/ai_index/_query
{
"query": "FROM ai-index-* | WHERE type == ?type | KEEP title, type, attributes | LIMIT 10",
"params": { "type": "faq" },
"limit": 10
}
{
"limit": 10,
"params": {
"type": "faq"
},
"query": "FROM ai-index-* | WHERE type == ?type | KEEP title, type, attributes | LIMIT 10"
}
{
"columns": [
{
"name": "title",
"type": "text"
},
{
"name": "type",
"type": "keyword"
},
{
"name": "attributes",
"type": "flattened"
}
],
"values": [
[
"How to reset a password",
"faq",
{
"source": "zendesk"
}
],
[
"Billing cycle explained",
"faq",
{
"source": "zendesk"
}
]
]
}
{
"error": "Bad Request",
"message": "verification_exception\n\tRoot causes:\n\t\tverification_exception: Found 1 problem\nline 1:46: Unknown column [titel], did you mean [title]?",
"statusCode": 400
}
{
"error": "Forbidden",
"message": "security_exception\n\tRoot causes:\n\t\tsecurity_exception: action [indices:data/read/esql] is unauthorized for user [jdoe] with effective roles [support_reader], this action is granted by the index privileges [read_cross_cluster,read,all]",
"statusCode": 403
}
{
"error": "Not Found",
"message": "Not Found",
"statusCode": 404
}