Docs
  • Release notes
  • Troubleshoot
  • Reference
  1. Docs /
  2. Explore and analyze /
  3. Machine learning

NLP

You can use Elastic Stack machine learning features to analyze natural language data and make predictions.

  • Overview
  • Deploy trained models
  • Add NLP inference to ingest pipelines
  • API quick reference
  • ELSER
  • Elastic Rerank
  • E5
  • Language identification
  • Examples
  • Limitations
Previous
Limitations
Next
Overview
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
  • Elastic fundamentals
  • Solutions and use cases
  • Manage data
  • Explore and analyze
  • Deploy and manage
  • Manage your Cloud account
  • Troubleshoot
  • Release notes
  • Reference
  • Extend and contribute
  • Contribute to the docs
  • Learn data exploration and visualization
  • Querying and filtering
    • Query languages
      • Query DSL
      • ES|QL
      • SQL
      • EQL
        • Example: Detect threats with EQL
      • KQL
      • Lucene query syntax
    • Query tools
      • Saved queries
      • Console
      • Search profiler
      • Grok debugger
    • Aggregations
      • Basics
    • Filtering in Kibana
  • Geospatial analysis
  • Transforming data
    • Overview
    • Setup
    • When to use transforms
    • Generating alerts for transforms
    • Transforms at scale
    • How checkpoints work
    • API quick reference
    • Tutorial: Transforming the eCommerce sample data
    • Examples
    • Painless examples
    • Limitations
  • Elastic Inference
    • Elastic Inference Service (EIS)
      • Supported models
      • Region and hosting
      • Rate limits
      • EIS for self-managed clusters
    • External inference
    • Default endpoints, adaptive allocations, and chunking
  • Machine learning
    • Setup and security
    • Anomaly detection
      • Finding anomalies
        • Plan your analysis
        • Run a job
        • View the results
        • Forecast future behavior
      • Tutorial
      • Advanced concepts
        • Anomaly detection algorithms
        • Anomaly score explanation
        • Job types
        • Working with anomaly detection at scale
        • Handling delayed data
        • Daylight saving time calendars
      • API quick reference
      • How-tos
        • Generating alerts for anomaly detection jobs
        • Aggregating data for faster performance
        • Altering data in your datafeed with runtime fields
        • Customizing detectors with custom rules
        • Detecting anomalous categories of data
        • Performing population analysis
        • Reverting to a model snapshot
        • Detecting anomalous locations in geographic data
        • Mapping anomalies by location
        • Adding custom URLs to machine learning results
        • Anomaly detection jobs from visualizations
      • Resources
        • Limitations
        • Analysis function reference
        • Supplied configurations
        • Troubleshooting and FAQ
    • Data frame analytics
      • Overview
      • Finding outliers
      • Predicting numerical values with regression
      • Predicting classes with classification
      • Advanced concepts
        • How data frame analytics analytics jobs work
        • Working with data frame analytics at scale
        • Adding custom URLs to data frame analytics jobs
        • Feature encoding
        • Feature processors
        • Feature importance
        • Loss functions for regression analyses
        • Hyperparameter optimization
        • Trained models
      • API quick reference
      • Resources
        • Limitations
    • NLP
      • Overview
        • Extract information
        • Classify text
        • Search and compare text
      • Deploy trained models
        • Select a trained model
        • Import the trained model and vocabulary
        • Deploy the model in your cluster
        • Try it out
      • Add NLP inference to ingest pipelines
      • API quick reference
      • Built-in NLP models
        • ELSER
        • Jina
        • Elastic Rerank
        • E5
        • Language identification
      • Compatible third party models
      • Examples
        • End-to-end tutorial
        • Named entity recognition
        • Text embedding and semantic search
      • Limitations
    • ML in Kibana
      • AIOps Labs
      • Inference processing
  • Scripting
    • Painless
      • How to write Painless scripts
        • Write your first script
        • Use parameters
        • Shorten scripts
        • Store and retrieve scripts
        • Update documents using scripts
      • Painless script tutorials
        • Accessing document fields and special variables
        • Accessing fields in a document
        • Converting data types
        • Dissecting data
        • Extracting fields
        • Grokking grok
        • Scripts, caching, and search speed
        • Updating documents
        • Using Painless regular expressions
        • Working with dates
      • Painless syntax-context bridge
      • Scripting and security in Painless
      • Painless lab
      • Debugging Painless scripts
        • Array manipulation errors
        • Date math errors
        • Field not found errors
        • Ingest pipeline failures
        • Null pointer exceptions
        • Regex pattern matching failures
        • Runtime field exceptions
        • Sandbox limitations
        • Script score calculation errors
        • Subfield access
        • Type casting issues
    • Lucene expressions language
    • Implementing custom scripting language in Elasticsearch
  • Cross-cluster search
    • Resolve a cluster before cross-cluster search
  • Cross-project search
    • Search
    • Tags
    • Project routing
    • CPS scope in project apps
    • CPS in ES|QL
  • AI-powered features
    • Automatic Import
    • Agent Builder
      • Get started
      • Models
      • Chat
        • Chat UI modes
        • Dashboards and visualizations
      • Agents
        • Custom agents
        • Built-in agents
        • Prompting best practices
        • Connect agents and workflows
      • Skills
        • Built-in skills
        • Custom skills
        • Skill creation guidelines
      • Plugins
      • Tools
        • Built-in tools
        • Custom tools
          • ES|QL tools
          • Index search tools
          • MCP tools
          • Workflow tools
      • Connectors
      • Programmatic access
        • Kibana APIs
          • Kibana API tutorial
        • A2A server
        • MCP server
          • API key authentication
          • OAuth authentication
      • Monitor usage and costs
        • Collect agent traces
        • Overview dashboard
        • Create alerts on trace data
      • Permissions
      • Troubleshooting
        • Context length exceeded
        • 403 Forbidden
      • Limitations
      • Glossary
    • AI chat experiences
      • Compare Agent Builder and AI Assistant
      • AI assistants
      • Knowledge base artifact repo for AI Assistant
    • Manage access to AI features
    • AI agent skills
    • Configure access to LLMs
      • Connect to Azure OpenAI
      • Connect to Amazon Bedrock
      • Connect to OpenAI
      • Connect to Google Vertex
      • Self-managed custom LLMs
        • Connect to LM Studio for Observability
        • Connect to LM Studio for Elastic Security
        • Connect to vLLM for Elastic Security
  • Discover
    • Explore fields and data with Discover
    • Customize the Discover view
    • Search for relevance
    • Save a Discover session for reuse
    • View field statistics
    • Run a pattern analysis on your log data
    • Detect change points
    • Run queries in the background
    • Using ES|QL
  • Dashboards
    • Exploring dashboards
    • Building dashboards
      • Create from the UI
      • Create programmatically
      • Create using AI
      • Edit a dashboard
      • Add drilldowns
      • Organize dashboard panels
      • Duplicate a dashboard
    • Managing dashboards
      • Share and export dashboards
      • Import a dashboard
      • Manage as code
    • Tutorials
      • Create a simple dashboard to monitor website logs
      • Create a dashboard with time series charts
  • Panels and visualizations
    • Visualizations
      • Area charts
      • Bar charts
      • Heat map charts
      • Gauge charts
      • Line charts
      • Metric charts
      • Mosaic charts
      • Pie charts
      • Region map charts
      • Tables
      • Waffle charts
      • Tag cloud charts
      • Treemap charts
    • Visualizations (ES|QL query)
    • Custom visualizations with Vega
    • Text panels
    • Image panels
    • Link panels
    • Alert panels
    • Controls
      • Add controls
      • Add time slider controls
      • Add variable controls
      • Control settings
    • Canvas
      • Edit workpads
      • Present your workpad
      • Tutorial: Create a workpad for monitoring sales
      • Canvas function reference
        • TinyMath functions
    • Maps
      • Build a map to compare metrics by country or region
      • Track, visualize, and alert on assets in real time
      • Map custom regions with reverse geocoding
      • Heat map layer
      • Tile layer
      • Vector layer
        • Vector styling
        • Vector style properties
        • Vector tooltips
      • Plot big data
        • Clusters
        • Display the most relevant documents per entity
        • Point to point
        • Term join
      • Search geographic data
        • Create filters from a map
        • Filter a single layer
        • Search across multiple indices
      • Configure map settings
      • Connect to Elastic Maps Service
      • Import geospatial data
        • Clean your data
        • Tutorial: Index GeoJSON data
      • Troubleshoot
    • Graph
      • Configure Graph
      • Troubleshooting and limitations
    • Legacy editors
      • Aggregation-based
      • TSVB
      • Timelion
    • Visualize Library
    • Manage panels
  • Find and organize content
    • The Kibana interface
    • Data views
    • Saved objects
    • Files
    • Reports
    • Tags
    • Find apps and objects
    • Customize your navigation menu
  • Reporting and sharing
    • Automatically generate reports
    • Troubleshoot reporting
      • CSV
      • PDF/PNG
  • Alerting
    • Compare alerting systems
    • Experimental alerting system
      • How it works
      • Glossary
      • Get started
        • Set up
        • Configure access
        • Create your first rule
      • Authorization
      • Rules
        • Create a rule
          • Create an ES|QL rule
            • YAML rule schema reference
          • Create rules using Agent Builder
          • Create rules using the rule builder
          • Create from Discover
        • Configure a rule
          • Rule mode
          • ES|QL query
          • Schedule and lookback
          • Severity
          • Grouping
          • Alert delay (Alert mode only)
          • Recovery condition
          • No-data handling
          • Tags and runbooks (Alert mode only)
        • View and manage rules
        • Review rule execution history
        • ES|QL query patterns
          • Your first rule query
          • Threshold queries
          • No-data detection
          • SLO burn rate
          • Persistent breach detection
        • Rule events
      • Alerts
        • Alert data model
        • View and manage alerts
          • Triage alert episodes
          • Investigate alert episodes
        • Query alert history
        • Field reference
      • Notifications and actions
        • Connect workflows
        • About action policies
        • Examples and common scenarios
          • Route by severity
          • Severity escalation
          • Re-notification
        • Create an action policy
        • Action policy reference
        • Manage action policies
        • Review action policy execution history
        • Reduce notification noise
    • Kibana alerting
      • Getting started with alerts
      • Set up
      • Rules and Elastic Cloud API keys in Serverless
      • Create and manage rules
      • View and manage alerts
      • Query alert indices
      • Rule types
        • Index threshold
        • Elasticsearch query
        • Tracking containment
      • Rule action variables
      • Notifications domain allowlist
      • Troubleshooting and limitations
        • Common issues
        • Troubleshoot rule behavior
        • Event log index
        • Test connectors
      • Maintenance windows
    • Watcher
      • Getting started with Watcher
      • How Watcher works
      • Enable Watcher
      • Watcher UI
      • Encrypting sensitive data in Watcher
      • Inputs
        • Simple input
        • Search input
        • HTTP input
        • Chain input
      • Triggers
        • Schedule trigger
        • Throttling
        • Schedule Types
      • Conditions
        • Always condition
        • Never condition
        • Compare condition
        • Array compare condition
        • Script condition
      • Actions
        • Running an action for each element in an array
        • Adding conditions to actions
        • Email action
        • Webhook action
        • Index action
        • Logging action
        • Slack action
        • PagerDuty action
        • Jira action
      • Transforms
        • Search payload transform
        • Script payload transform
        • Chain payload transform
      • Managing watches
      • Example watches
        • Watching the status of an Elasticsearch cluster
        • Execute a watch
      • Limitations
  • Cases
    • Control access
    • Create cases
    • Manage cases
    • Analyze with AI
    • Attach objects
    • Search and share
    • Configure settings
    • Case templates
      • Create field library fields
      • Create templates
      • Edit and share templates
      • YAML schema reference
    • Case analytics
      • Indices
      • Explore and visualize
      • Query with ES|QL
      • Analyze fields
      • Field reference
      • Administer
  • Workflows
    • Get started
      • Set up Workflows
      • Build your first workflow
    • Use cases
      • Security
        • Automate security operations
          • Alert analysis workflow
          • Triage alerts into cases
          • AI-driven alert triage
          • Enrich with threat intel
        • Manage detection rules at scale
          • Run rules on demand
      • Observability
        • Root cause analysis
      • AI-augmented workflows
        • Classify and route alerts
    • Concepts
      • Managed workflows
      • Authorization
      • Triggers
        • Manual triggers
        • Scheduled triggers
        • Alert triggers
        • Event-driven triggers
      • Steps
        • Action steps
          • Elasticsearch
          • Kibana
          • Cases
          • Entity store
          • Security
            • Detection rules
            • Alert triage
            • Attack triage
          • Streams
          • External systems and apps
        • Flow control
          • If
          • Foreach
          • While
          • Switch
          • Parallel
          • Wait
          • Wait for input
          • Wait for approval
          • Loop break
          • Loop continue
        • AI
        • Data
        • Composition
      • Templating engine
      • Reference
        • Cheat sheet
        • Context variables
        • Glossary
        • Liquid filters
        • Step type index
    • Workflow authoring techniques
      • Use natural language
      • Use the YAML editor
      • Anatomy of a workflow
      • Workflow settings
      • Choose the right step
      • Pass data and handle errors
      • Compose workflows
      • Human-in-the-loop
      • Monitor workflow execution
      • Manage and organize workflows
      • Troubleshooting
      • Migrate workflows from 9.3 to 9.4
    • Workflow templates
      • Start from a template
  • Numeral formatting
Elastic logo
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© 2026 Elasticsearch B.V. All Rights Reserved.

This content is available in different formats for convenience only. All original licensing terms apply.

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries. Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.