Docs
  • Release notes
  • Troubleshoot
  • Reference
  1. Docs /
  2. Reference /
  3. Elastic CLI /
  4. Command reference /
  5. stack /
  6. es

stack es fleet cli namespace

elastic stack es fleet --help
		

Elasticsearch fleet API commands

Commands

global-checkpoints

Get global checkpoints.

msearch

Run multiple Fleet searches.

search

Run a Fleet search.

Previous
reset-features
Next
global-checkpoints
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
On this page
  • Commands
  • Elastic fundamentals
  • Solutions and use cases
  • Manage data
  • Explore and analyze
  • Deploy and manage
  • Manage your Cloud account
  • Troubleshoot
  • Release notes
  • Reference
  • Extend and contribute
  • Contribute to the docs
  • Elasticsearch
    • Configuration
      • Circuit breaker settings
      • Auditing settings
      • Enrich settings
      • Cluster-level shard allocation and routing settings
      • Miscellaneous cluster settings
      • Cross-cluster replication settings
      • Discovery and cluster formation settings
      • Field data cache settings
      • Health Diagnostic settings
      • Index lifecycle management settings
      • Data stream lifecycle settings
      • Index management settings
      • Index recovery settings
      • Indexing buffer settings
      • Indexing pressure
      • Ingest settings
      • License settings
      • Local gateway
      • Machine learning settings
      • Inference settings
      • Monitoring settings
      • Node settings
      • Path settings
      • Networking settings
      • Node query cache settings
      • Remote cluster settings
      • Search settings
      • Security settings
      • Cluster state encryption
      • Shard request cache
      • Snapshot and restore settings
        • S3 repository
        • Azure repository
        • GCS repository
        • Shared file system repository
        • Read-only URL repository
        • Source-only repository
      • Transforms settings
      • Thread pool settings
      • Watcher settings
    • JVM settings
    • Built-in roles
    • Elasticsearch privileges
    • Columnar
    • Index settings
      • Serverless index settings
      • General
      • Shard allocation
        • Data tier allocation
        • Index recovery prioritization
        • Total shards per node
      • History retention
      • Index blocks
      • Mapping limit
      • Merge
      • Similarity
      • Slow log
      • Sorting
        • Use index sorting to speed up conjunctions
      • Store
        • Preloading data into the file system cache
      • Time series
      • Source settings
      • Translog
    • Index lifecycle actions
      • Allocate
      • Delete
      • Force merge
      • Migrate
      • Read only
      • Rollover
      • Downsample
      • Searchable snapshot
      • Set priority
      • Shrink
      • Unfollow
      • Wait for snapshot
    • REST APIs
      • API conventions
      • Common options
      • Compatibility
      • Guides and examples
        • Collapse search results
        • Create index from source
        • Understand the lifecycle status
        • Filter search results
        • Rescore search results
        • Find text structure API examples
        • Highlighting
          • Highlighting settings
          • Highlighting examples
          • How highlighters work internally
        • Analyze index disk usage
        • Optimistic concurrency control
        • Paginate search results
        • Query API key information
        • Reciprocal rank fusion
        • The refresh parameter
        • Reindex data stream
        • Reindex indices
        • Retrieve inner hits
        • Retrieve selected fields
        • Retrieve stored fields
        • Retrievers
          • kNN retriever
          • Linear retriever
          • Pinned retriever
          • Rescorer retriever
          • RRF retriever
          • Query rules retriever
          • Standard retriever
          • Text similarity re-ranker retriever
          • Diversify retriever
          • Examples
        • Search multiple data streams and indices
        • Profile search requests
        • Ranking evaluation
        • Search shard routing
        • Suggesters
        • Sort search results
        • Searching with query rules
        • The shard request cache
        • Term vectors API examples
        • Update By Query API
        • Update a document
        • Update cross-cluster API examples
        • Vector tile search API
    • Mapping
      • Document metadata fields
        • _doc_count field
        • _field_names field
        • _ignored field
        • _id field
        • _index field
        • _meta field
        • _routing field
        • _source field
        • _tier field
      • Field data types
        • Aggregate metric
        • Alias
        • Arrays
        • Binary
        • Boolean
        • Completion
        • Date
        • Date nanoseconds
        • Dense vector
        • Flattened
        • Geopoint
        • Geoshape
        • Histogram
        • Exponential histogram
        • T-digest
        • IP
        • Join
        • Keyword
        • Nested
        • Numeric
        • Object
        • Pass-through object
        • Percolator
        • Point
        • Range
        • Rank feature
        • Rank features
        • Rank vectors
        • Search-as-you-type
        • Semantic
          • Reference
        • Semantic text
          • Reference
          • How-to guides
            • Set up and configure
            • Ingest data
            • Search and retrieve
        • Shape
        • Sparse vector
        • Text type family
          • Text
          • Pattern Text
          • Match Only Text
        • Token count
        • Unsigned long
        • Version
      • Mapping parameters
        • analyzer
        • coerce
        • copy_to
        • doc_values
        • dynamic
        • eager_global_ordinals
        • enabled
        • format
        • ignore_above
        • ignore_above index setting
        • ignore_malformed
        • index
        • index_options
        • index_phrases
        • index_prefixes
        • meta
        • fields
        • normalizer
        • norms
        • null_value
        • position_increment_gap
        • properties
        • search_analyzer
        • similarity
        • store
        • subobjects
        • term_vector
        • Better Binary Quantization (BBQ)
    • Elasticsearch audit events
    • Command-line tools
      • elasticsearch-certgen
      • elasticsearch-certutil
      • elasticsearch-create-enrollment-token
      • elasticsearch-croneval
      • elasticsearch-keystore
      • elasticsearch-node
      • elasticsearch-reconfigure-node
      • elasticsearch-reset-password
      • elasticsearch-saml-metadata
      • elasticsearch-service-tokens
      • elasticsearch-setup-passwords
      • elasticsearch-shard
      • elasticsearch-syskeygen
      • elasticsearch-users
    • Query languages
      • Query DSL
        • Get started
        • Query and filter context
        • Compound queries
          • Boolean
          • Boosting
          • Constant score
          • Disjunction max
          • Function score
        • Full text queries
          • Intervals
          • Match
          • Match boolean prefix
          • Match phrase
          • Match phrase prefix
          • Combined fields
          • Multi-match
          • Query string
          • Simple query string
          • KQL
        • Geo queries
          • Geo-bounding box
          • Geo-distance
          • Geo-grid
          • Geo-polygon
          • Geoshape
        • Shape queries
          • Shape
        • Joining queries
          • Nested
          • Has child
          • Has parent
          • Parent ID
        • Match all
        • Span queries
          • Span containing
          • Span field masking
          • Span first
          • Span multi-term
          • Span near
          • Span not
          • Span or
          • Span term
          • Span within
        • Vector queries
          • Knn
          • Dense vector
          • Sparse vector
          • Semantic
          • Text expansion
          • Weighted tokens
        • Specialized queries
          • Distance feature
          • more_like_this
          • Percolate
          • Rank feature
          • Script
          • Script score
          • Wrapper
          • Pinned query
          • Rule
        • Term-level queries
          • Bitmap terms
          • Exists
          • Fuzzy
          • IDs
          • Prefix
          • Range
          • Regexp
          • Term
          • Terms
          • Terms set
          • Wildcard
        • minimum_should_match parameter
        • rewrite parameter
        • Regular expression syntax
      • ES|QL
        • Get started
        • Use cases
          • ES|QL for search
          • ES|QL for cybersecurity
        • REST API
        • Syntax reference
          • Basic syntax
          • Query directives
            • SET
          • Commands
            • Source commands
              • FROM
              • PROMQL
              • ROW
              • SHOW
              • TS
            • Processing commands
              • CHANGE_POINT
              • COMPLETION
              • DEDUP
              • DISSECT
              • DROP
              • ENRICH
              • EVAL
              • FORK
              • FUSE
              • GROK
              • HIGHLIGHT
              • INLINE STATS
              • IP_LOCATION
              • KEEP
              • LIMIT
              • LOOKUP JOIN
              • METRICS_INFO
              • MMR
              • MV_EXPAND
              • REGISTERED_DOMAIN
              • RENAME
              • RERANK
              • SAMPLE
              • SORT
              • STATS
              • TS_INFO
              • TS_COLLAPSE
              • USER_AGENT
              • URI_PARTS
              • WHERE
          • Functions and operators
            • Aggregation functions
              • ABSENT
              • AVG
              • COUNT
              • COUNT_DISTINCT
              • EARLIEST
              • FIRST
              • LAST
              • LATEST
              • MAX
              • MEDIAN
              • MEDIAN_ABSOLUTE_DEVIATION
              • MIN
              • PERCENTILE
              • PRESENT
              • SAMPLE
              • SPARKLINE
              • ST_CENTROID_AGG
              • ST_EXTENT_AGG
              • STD_DEV
              • SUM
              • TOP
              • VALUES
              • VARIANCE
              • WEIGHTED_AVG
            • Time series aggregation functions
              • ABSENT_OVER_TIME
              • AVG_OVER_TIME
              • COUNT_OVER_TIME
              • COUNT_DISTINCT_OVER_TIME
              • DELTA
              • DERIV
              • FIRST_OVER_TIME
              • IDELTA
              • INCREASE
              • IRATE
              • LAST_OVER_TIME
              • MAX_OVER_TIME
              • MIN_OVER_TIME
              • PERCENTILE_OVER_TIME
              • PRESENT_OVER_TIME
              • RATE
              • STDDEV_OVER_TIME
              • VARIANCE_OVER_TIME
              • SUM_OVER_TIME
            • Grouping functions
              • BUCKET
              • TBUCKET
              • CATEGORIZE
              • WITHOUT
            • Conditional functions and expressions
              • CASE
              • COALESCE
              • GREATEST
              • LEAST
              • CLAMP
              • CLAMP_MIN
              • CLAMP_MAX
            • Date-time functions
              • DATE_DIFF
              • DATE_EXTRACT
              • DATE_FORMAT
              • DATE_PARSE
              • DATE_TRUNC
              • DAY_NAME
              • MONTH_NAME
              • NOW
              • RANGE_MAX
              • RANGE_MIN
              • RANGE_WITHIN
              • RANGE_CONTAINS
              • RANGE_INTERSECTS
              • TRANGE
            • IP functions
              • CIDR_MATCH
              • IP_PREFIX
            • Math functions
              • ABS
              • ACOS
              • ACOSH
              • ASIN
              • ASINH
              • ATAN
              • ATAN2
              • ATANH
              • CBRT
              • CEIL
              • COPY_SIGN
              • COS
              • COSH
              • E
              • EXP
              • FLOOR
              • HYPOT
              • LOG
              • LOG10
              • PI
              • POW
              • ROUND
              • ROUND_TO
              • SCALB
              • SIGNUM
              • SIN
              • SINH
              • SQRT
              • TAN
              • TANH
              • TAU
            • Search functions
              • DECAY
              • KQL
              • MATCH
              • MATCH_PHRASE
              • QSTR
              • SCORE
              • TOP_SNIPPETS
            • Spatial functions
              • ST_DISTANCE
              • ST_INTERSECTS
              • ST_DISJOINT
              • ST_CONTAINS
              • ST_WITHIN
              • ST_X
              • ST_Y
              • ST_NPOINTS
              • ST_BUFFER
              • ST_SIMPLIFY
              • ST_SIMPLIFYPRESERVETOPOLOGY
              • ST_GEOMETRYTYPE
              • ST_DIMENSION
              • ST_ISEMPTY
              • ST_UNION
              • ST_INTERSECTION
              • ST_DIFFERENCE
              • ST_SYMDIFFERENCE
              • ST_ENVELOPE
              • ST_XMAX
              • ST_XMIN
              • ST_YMAX
              • ST_YMIN
              • ST_GEOTILE
              • ST_GEOHEX
              • ST_GEOHASH
            • String functions
              • BIT_LENGTH
              • BYTE_LENGTH
              • CHUNK
              • CONCAT
              • CONTAINS
              • ENDS_WITH
              • FIELD_EXTRACT
              • FROM_BASE64
              • HASH
              • JSON_EXTRACT
              • LEFT
              • LENGTH
              • LOCATE
              • LTRIM
              • MD5
              • REPEAT
              • REPLACE
              • REVERSE
              • RIGHT
              • RTRIM
              • SHA1
              • SHA256
              • SPACE
              • SPLIT
              • STARTS_WITH
              • SUBSTRING
              • TO_BASE64
              • TO_LOWER
              • TO_UPPER
              • TRIM
              • URL_ENCODE
              • URL_ENCODE_COMPONENT
              • URL_DECODE
            • Dense vector functions
              • EMBEDDING
              • KNN
              • TEXT_EMBEDDING
              • V_COSINE
              • V_DOT_PRODUCT
              • V_HAMMING
              • V_L1_NORM
              • V_L2_NORM
            • Type conversion functions
              • TO_AGGREGATE_METRIC_DOUBLE
              • TO_BOOLEAN
              • TO_CARTESIANPOINT
              • TO_CARTESIANSHAPE
              • TO_COUNTER
              • TO_DATEPERIOD
              • TO_DATETIME
              • TO_DATE_NANOS
              • TO_DATE_RANGE
              • TO_DEGREES
              • TO_DENSE_VECTOR
              • TO_DOUBLE
              • TO_DOUBLE_RANGE
              • TO_EXPONENTIAL_HISTOGRAM
              • TO_GAUGE
              • TO_GEOHASH
              • TO_GEOHEX
              • TO_GEOPOINT
              • TO_GEOSHAPE
              • TO_GEOTILE
              • TO_INTEGER
              • TO_IP
              • TO_LONG
              • TO_RADIANS
              • TO_RANGE
              • TO_STRING
              • TO_TDIGEST
              • TO_TEXT
              • TO_TIMEDURATION
              • TO_UNSIGNED_LONG
              • TO_VERSION
            • Multivalue functions
              • MV_APPEND
              • MV_AVG
              • MV_CONCAT
              • MV_CONTAINS
              • MV_COUNT
              • MV_DEDUPE
              • MV_DIFFERENCE
              • MV_FIRST
              • MV_GREATER
              • MV_IN_RANGE
              • MV_INTERSECTION
              • MV_INTERSECTS
              • MV_LAST
              • MV_LESS
              • MV_LIKE
              • MV_MAX
              • MV_MEDIAN
              • MV_MEDIAN_ABSOLUTE_DEVIATION
              • MV_MIN
              • MV_PERCENTILE
              • MV_PSERIES_WEIGHTED_SUM
              • MV_RLIKE
              • MV_SLICE
              • MV_SORT
              • MV_SUM
              • MV_UNION
              • MV_ZIP
            • Operators
        • Optimize query performance
          • Approximate STATS queries
        • Query multiple sources
          • Query multiple indices
          • Query across clusters
          • Query across serverless projects
        • Combine and reuse queries
          • Subqueries
            • Subqueries with FROM
            • Subqueries with IN / NOT IN
          • Views
        • Data Federation
          • Quickstart
          • Connect data sources
            • AWS federated identity
            • AWS static credentials
          • Add datasets
            • Resource patterns
          • Query datasets
          • Manage access
          • Cluster settings
        • Advanced workflows
          • Extract data with DISSECT and GROK
          • Combine data with ENRICH
          • Join data with LOOKUP JOIN
        • Types and fields
          • Implicit casting
          • Time spans
          • Flattened fields
          • Metadata fields
          • NULL values
          • Multivalued fields
          • Histogram fields
          • Unmapped fields
        • Tutorials
          • ES|QL for search
          • ES|QL for threat hunting
        • Troubleshooting
          • Query log
          • List running queries
        • Limitations
      • PromQL
        • HTTP API
        • Functions
          • Range vector functions
          • Aggregation functions
          • Histogram functions
          • Math functions
          • Date and time functions
          • Conversion functions
        • Operators
          • Arithmetic operators
          • Comparison operators
          • Logical/set operators
          • Unary operators
          • Label matching operators
        • Prometheus data source in Grafana
        • Limitations
      • SQL
        • Getting started
        • Conventions
        • Security
        • SQL REST API
          • Overview
          • Response data formats
          • Paginating through a large response
          • Filtering using Elasticsearch Query DSL
          • Columnar results
          • Passing parameters to a query
          • Use runtime fields
          • Run an async SQL search
        • SQL Translate API
        • SQL CLI
        • SQL JDBC
          • API usage
        • SQL ODBC
          • Driver installation
          • Configuration
        • SQL client applications
          • DBeaver
          • DbVisualizer
          • Microsoft Excel
          • Microsoft Power BI Desktop
          • Microsoft PowerShell
          • MicroStrategy Desktop
          • Qlik Sense Desktop
          • SQuirreL SQL
          • SQL Workbench/J
          • Tableau Desktop
          • Tableau Server
        • SQL language
          • Lexical structure
          • SQL commands
          • DESCRIBE TABLE
          • SELECT
          • SHOW CATALOGS
          • SHOW COLUMNS
          • SHOW FUNCTIONS
          • SHOW TABLES
          • Data types
          • Index patterns
          • Frozen indices
        • Functions and operators
          • Comparison operators
          • Logical operators
          • Math operators
          • Cast operators
          • LIKE and RLIKE operators
          • Aggregate functions
          • Grouping functions
          • Date/time and interval functions and operators
          • Full-text search functions
          • Mathematical functions
          • String functions
          • Type conversion functions
          • Geo functions
          • Conditional functions and expressions
          • System functions
        • Reserved keywords
        • SQL limitations
      • EQL
        • Syntax reference
        • Function reference
        • Pipe reference
      • Kibana Query Language
    • Text analysis components
      • Analyzer reference
        • Fingerprint
        • Keyword
        • Language
        • Pattern
        • Simple
        • Standard
        • Stop
        • Whitespace
      • Tokenizer reference
        • Character group
        • Classic
        • Edge n-gram
        • Keyword
        • Letter
        • Lowercase
        • N-gram
        • Path hierarchy
        • Pattern
        • Simple pattern
        • Simple pattern split
        • Standard
        • Thai
        • UAX URL email
        • Whitespace
      • Token filter reference
        • Apostrophe
        • ASCII folding
        • CJK bigram
        • CJK width
        • Classic
        • Common grams
        • Conditional
        • Decimal digit
        • Delimited payload
        • Dictionary decompounder
        • Edge n-gram
        • Elision
        • Fingerprint
        • Flatten graph
        • Hunspell
        • Hyphenation decompounder
        • Keep types
        • Keep words
        • Keyword marker
        • Keyword repeat
        • KStem
        • Length
        • Limit token count
        • Lowercase
        • MinHash
        • Multiplexer
        • N-gram
        • Normalization
        • Pattern capture
        • Pattern replace
        • Phonetic
        • Porter stem
        • Predicate script
        • Remove duplicates
        • Reverse
        • Shingle
        • Snowball
        • Stemmer
        • Stemmer override
        • Stop
        • Synonym
        • Synonym graph
        • Trim
        • Truncate
        • Unique
        • Uppercase
        • Word delimiter
        • Word delimiter graph
      • Character filter reference
        • HTML strip
        • Mapping
        • Pattern replace
      • Normalizers
    • Aggregations
      • Bucket
        • Adjacency matrix
        • Auto-interval date histogram
        • Categorize text
        • Children
        • Composite
        • Date histogram
        • Date range
        • Diversified sampler
        • Filter
        • Filters
        • Frequent item sets
        • Geo-distance
        • Geohash grid
        • Geohex grid
        • Geotile grid
        • Global
        • Histogram
        • IP prefix
        • IP range
        • Missing
        • Multi Terms
        • Nested
        • Parent
        • Random sampler
        • Range
        • Rare terms
        • Reverse nested
        • Sampler
        • Significant terms
        • Significant text
        • Terms
        • Time series
        • Variable width histogram
        • Subtleties of bucketing range fields
      • Metrics
        • Avg
        • Boxplot
        • Cardinality
        • Extended stats
        • Geo-bounds
        • Geo-centroid
        • Geo-line
        • Cartesian-bounds
        • Cartesian-centroid
        • Matrix stats
        • Max
        • Median absolute deviation
        • Min
        • Percentile ranks
        • Percentiles
        • Rate
        • Scripted metric
        • Stats
        • String stats
        • Sum
        • T-test
        • Top hits
        • Top metrics
        • Value count
        • Weighted avg
      • Pipeline
        • Average bucket
        • Bucket script
        • Bucket count K-S test
        • Bucket correlation
        • Bucket selector
        • Bucket sort
        • Change point
        • Cumulative cardinality
        • Cumulative sum
        • Derivative
        • Extended stats bucket
        • Inference bucket
        • Max bucket
        • Min bucket
        • Moving function
        • Moving percentiles
        • Normalize
        • Percentiles bucket
        • Serial differencing
        • Stats bucket
        • Sum bucket
    • Processor reference
      • Append
      • Attachment
      • Bytes
      • Circle
      • CEF
      • Community ID
      • Convert
      • CSV
      • Date
      • Date index name
      • Dissect
      • Dot expander
      • Drop
      • Enrich
      • Fail
      • Fingerprint
      • Foreach
      • Geo-grid
      • GeoIP
      • Grok
      • Gsub
      • HTML strip
      • Inference
      • IP Location
      • Join
      • JSON
      • KV
      • Lowercase
      • Network direction
      • Normalize for Stream
      • Pipeline
      • Redact
      • Registered domain
      • Recover Failure Document
      • Remove
      • Rename
      • Reroute
      • Script
      • Set
      • Set security user
      • Sort
      • Split
      • Terminate
      • Trim
      • Uppercase
      • URL decode
      • URI parts
      • User agent
    • Curator
      • Curator and index lifecycle management
        • ILM Actions
        • ILM or Curator?
        • ILM and Curator!
      • About
        • Origin
        • Features
        • Command-Line Interface (CLI)
        • Application Program Interface (API)
        • License
        • Site Corrections
        • Contributing
      • Installation
        • pip
        • Installation from source
        • Docker
      • Running Curator
        • Command Line Interface
        • Singleton Command Line Interface
        • Exit Codes
      • Configuration
        • Environment Variables
        • Action File
        • Configuration File
      • Actions
        • Alias
        • Allocation
        • Close
        • Cluster Routing
        • Cold2Frozen
        • Create Index
        • Delete Indices
        • Delete Snapshots
        • Forcemerge
        • Index Settings
        • open
        • Reindex
        • Replicas
        • Restore
        • Rollover
        • Shrink
        • Snapshot
      • Options
        • allocation_type
        • allow_ilm_indices
        • continue_if_exception
        • copy_aliases
        • count
        • delay
        • delete_after
        • delete_aliases
        • skip_flush
        • disable_action
        • extra_settings
        • ignore_empty_list
        • ignore_unavailable
        • include_aliases
        • include_global_state
        • include_hidden
        • indices
        • key
        • max_age
        • max_docs
        • max_size
        • max_num_segments
        • max_wait
        • migration_prefix
        • migration_suffix
        • name
        • new_index
        • node_filters
        • number_of_replicas
        • number_of_shards
        • partial
        • post_allocation
        • preserve_existing
        • refresh
        • remote_certificate
        • remote_client_cert
        • remote_client_key
        • remote_filters
        • remote_url_prefix
        • rename_pattern
        • rename_replacement
        • repository
        • requests_per_second
        • request_body
        • retry_count
        • retry_interval
        • routing_type
        • search_pattern
        • setting
        • shrink_node
        • shrink_prefix
        • shrink_suffix
        • slices
        • skip_repo_fs_check
        • timeout
        • timeout_override
        • value
        • wait_for_active_shards
        • wait_for_completion
        • wait_for_rebalance
        • wait_interval
        • warn_if_no_indices
      • Filters
        • filtertype
        • age
        • alias
        • allocated
        • closed
        • count
        • empty
        • forcemerged
        • kibana
        • none
        • opened
        • pattern
        • period
        • space
        • state
      • Filter Elements
        • aliases
        • allocation_type
        • count
        • date_from
        • date_from_format
        • date_to
        • date_to_format
        • direction
        • disk_space
        • epoch
        • exclude
        • field
        • intersect
        • key
        • kind
        • max_num_segments
        • pattern
        • period_type
        • range_from
        • range_to
        • reverse
        • source
        • state
        • stats_result
        • timestring
        • threshold_behavior
        • unit
        • unit_count
        • unit_count_pattern
        • use_age
        • value
        • week_starts_on
      • Examples
        • alias
        • allocation
        • close
        • cluster_routing
        • create_index
        • delete_indices
        • delete_snapshots
        • forcemerge
        • index_settings
        • open
        • reindex action examples
        • replicas
        • restore
        • rollover
        • shrink
        • snapshot
      • Frequently Asked Questions
        • Q: How can I report an error in the documentation?
        • Q: Can I delete only certain data from within indices?
        • Q: Can Curator handle index names with strange characters?
    • Clients
      • Eland
        • Installation
        • Data Frames
        • Machine Learning
      • Go
        • Getting started
        • Installation
        • Connecting
        • Configuration
        • Using the API
          • CRUD operations
          • Searching
          • Aggregations
          • Bulk indexing
          • Using ES|QL
          • Dense vectors and kNN search
        • Typed API
          • Conventions
          • esdsl - Elasticsearch DSL builders
        • Low-level API
          • Migrating to the typed API
        • Advanced
          • Interceptors
          • Observability
      • Java
        • Getting started
        • Setup
          • Installation
          • Connecting
          • Using OpenTelemetry
        • API conventions
          • Package structure and namespace clients
          • Method naming conventions
          • Blocking and asynchronous clients
          • Building API objects
          • Lists and maps
          • Variant types
          • Object life cycles and thread safety
          • Creating API objects from JSON data
          • Exceptions
        • Using the Java API client
          • Indexing single documents
          • Bulk: indexing multiple documents
          • Reading documents by id
          • Searching for documents
          • Aggregations
          • ES|QL in the Java client
        • Troubleshooting
          • Missing required property
          • NoSuchMethodError: removeHeader
          • IOReactor errors
          • Serializing without typed keys
          • Could not resolve dependencies
          • NoClassDefFoundError: LogFactory
        • Transport layer
          • REST 5 Client
            • Getting started
              • Initialization
              • Performing requests
              • Reading responses
              • Logging
            • Common configuration
              • Timeouts
              • Number of threads
              • Basic authentication
              • Other authentication methods
              • Encrypted communication
              • More config options
              • Node selector
            • Sniffer
          • Legacy REST Client
            • Getting started
              • Javadoc
              • Maven repository
              • Dependencies
              • Shading
              • Initialization
              • Performing requests
              • Reading responses
              • Logging
            • Common configuration
              • Timeouts
              • Number of threads
              • Basic authentication
              • Other authentication methods
              • Encrypted communication
              • More config options
              • Node selector
            • Sniffer
              • Javadoc
              • Maven Repository
              • Usage
        • Javadoc and source code
        • External resources
        • Breaking changes policy
        • Release highlights
        • License
      • JavaScript
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Basic configuration
          • Advanced configuration
          • Creating a child client
          • Testing
        • Integrations
          • Observability
          • Transport
          • TypeScript support
        • API Reference
        • Examples
          • asStream
          • Bulk
          • Exists
          • Get
          • Ignore
          • MSearch
          • Scroll
          • Search
          • Suggest
          • transport.request
          • SQL
          • Update
          • Update By Query
          • Reindex
        • Client helpers
        • Timeout best practices
      • Elasticsearch DSL for JavaScript/TypeScript
        • ES|QL query builder
      • .NET
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Options on ElasticsearchClientSettings
        • Client concepts
          • Serialization
            • Source serialization
            • Serialization of Elasticsearch types
            • Plugin-defined variant types
        • Using the .NET Client
          • Aggregation examples
          • Using ES|QL
            • LINQ to ES|QL
          • CRUD usage examples
          • Custom mapping examples
          • Query examples
          • Usage recommendations
          • Low level Transport example
        • Troubleshoot
          • Logging
            • Logging with OnRequestCompleted
            • Logging with Fiddler
          • Debugging
            • Audit trail
            • Debug information
            • Debug mode
        • Breaking changes policy
      • PHP
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Dealing with JSON arrays and objects in PHP
          • Host Configuration
          • Set retries
          • HTTP Meta Data
          • Enabling the Logger
          • Configure the HTTP client
          • Namespaces
          • Node Pool
        • Operations
          • Index management operations
          • Search operations
          • Indexing documents
          • Getting documents
          • Updating documents
          • Deleting documents
        • Client helpers
          • Iterators
          • ES|QL
          • Bulk ingest
      • Python
        • Getting started
        • Installation
        • Connecting
        • Configuration
        • Querying
        • ES|QL query builder
        • Using with asyncio
        • Integrations
          • Using OpenTelemetry
          • ES|QL and Pandas
        • Examples
        • Elasticsearch Python DSL
          • Configuration
          • Tutorials
          • How-To Guides
          • Examples
          • Migrating from the elasticsearch-dsl package
        • Client helpers
      • Ruby
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Basic configuration
          • Advanced configuration
        • Integrations
          • Transport
          • Elasticsearch API
          • Using OpenTelemetry
          • Elastic Common Schema (ECS)
          • ActiveModel / ActiveRecord
          • Ruby On Rails
          • Persistence
          • Elasticsearch DSL
        • Examples
        • Client helpers
          • Bulk and Scroll helpers
          • ES|QL
        • Troubleshoot
      • Rust
        • Installation
      • Community-contributed clients
    • Elasticsearch plugins
      • Plugin management
        • Installing plugins
        • Custom URL or file system
        • Installing multiple plugins
        • Mandatory plugins
        • Listing, removing and updating installed plugins
        • Other command line parameters
        • Plugins directory
        • Manage plugins using a configuration file
        • Upload custom plugins and bundles
        • Manage plugins and extensions through the API
      • API extension plugins
      • Analysis plugins
        • ICU analysis plugin
          • ICU analyzer
          • ICU normalization character filter
          • ICU tokenizer
          • ICU normalization token filter
          • ICU folding token filter
          • ICU collation token filter
          • ICU collation keyword field
          • ICU transform token filter
        • Japanese (kuromoji) analysis plugin
          • kuromoji analyzer
          • kuromoji_iteration_mark character filter
          • kuromoji_tokenizer
          • kuromoji_baseform token filter
          • kuromoji_part_of_speech token filter
          • kuromoji_readingform token filter
          • kuromoji_stemmer token filter
          • ja_stop token filter
          • kuromoji_number token filter
          • hiragana_uppercase token filter
          • katakana_uppercase token filter
          • kuromoji_completion token filter
        • Korean (nori) analysis plugin
          • nori analyzer
          • nori_tokenizer
          • nori_part_of_speech token filter
          • nori_readingform token filter
          • nori_number token filter
        • Phonetic analysis plugin
          • phonetic token filter
        • Smart Chinese analysis plugin
          • Reimplementing and extending the smartcn analyzer
          • smartcn_stop token filter
        • Stempel Polish analysis plugin
          • Reimplementing and extending the polish analyzer
          • polish_stop token filter
        • Ukrainian analysis plugin
      • Discovery plugins
        • EC2 discovery plugin
          • Using the EC2 discovery plugin
          • Best practices in AWS
        • Azure classic discovery plugin
          • Azure virtual machine discovery
          • Setup process for Azure discovery
          • Scaling out
        • GCE Discovery plugin
          • GCE virtual machine discovery
          • GCE network host
          • Setting up GCE discovery
          • Cloning your existing machine
          • Using GCE zones
          • Filtering by tags
          • Changing default transport port
          • GCE tips
          • Testing GCE
      • Mapper plugins
        • Mapper size plugin
          • Using the _size field
        • Mapper murmur3 plugin
          • Using the murmur3 field
        • Mapper annotated text plugin
          • Using the annotated-text field
          • Data modelling tips
          • Using the annotated highlighter
          • Limitations
      • Snapshot/restore repository plugins
        • Hadoop HDFS repository plugin
          • Getting started with HDFS
          • Configuration properties
          • Hadoop security
      • Store plugins
        • Store SMB plugin
          • Working around a bug in Windows SMB and Java on windows
      • Authentication plugins
        • Microsoft Graph Authz
          • Configure Azure
          • Configuration properties
      • Integrations
    • Scripting languages
      • Painless
        • A brief Painless walkthrough
          • Accessing Doc Values from Painless
          • Missing keys or values
          • Updating Fields with Painless
          • Dates
          • Regular expressions
        • Use Painless scripts in runtime fields
        • Using datetime in Painless
          • Datetime representation
          • Datetime parsing and formatting
          • Datetime conversion
          • Datetime Pieces
          • Datetime Modification
          • Datetime difference
          • Datetime comparison
          • Datetime zone
          • Datetime Input
          • Datetime now
          • Datetime examples in contexts
        • Understanding method dispatching in Painless
        • Painless debugging
        • Painless execute API
        • Using ingest processors in Painless
        • Painless language specification
          • Comments
          • Keywords
          • Literals
          • Identifiers
          • Variables
          • Types
          • Casting
          • Operators
          • Operators: General
          • Operators: Numeric
          • Operators: Boolean
          • Operators: Reference
          • Operators: Array
          • Statements
          • Scripts
          • Functions
          • Lambdas
          • Regexes
        • Painless contexts
          • Context example data (eCommerce)
          • Runtime fields context
          • Ingest processor context
          • Update context
          • Update by query context
          • Reindex context
          • Sort context
          • Similarity context
          • Weight context
          • Score context
          • Field context
          • Filter context
          • Minimum should match context
          • Metric aggregation initialization context
          • Metric aggregation map context
          • Metric aggregation combine context
          • Metric aggregation reduce context
          • Bucket script aggregation context
          • Bucket selector aggregation context
          • Analysis Predicate Context
          • Watcher condition context
          • Watcher transform context
  • Kibana
    • Accessibility
    • Configuration
      • Elastic Cloud Kibana settings
      • Alerting and action settings
      • APM settings in Kibana
      • Background search settings
      • Banners settings
      • Cases settings
      • Fleet settings
      • General settings
      • Internationalization settings
      • Knowledge base artifact settings for AI Assistants
      • Logging settings
      • Logs settings
      • Map settings
      • Metrics settings
      • Monitoring settings
      • Product intercept settings
      • Reporting settings
      • Automatic Import settings
      • Universal Profiling settings
      • Security settings
      • Security Solution settings
      • Sharing settings
      • Spaces settings
      • Task Manager settings
      • Telemetry settings
      • URL drilldown settings
    • Advanced settings
    • Kibana audit events
    • User activity
    • Connectors
      • GenAI
        • AI Connector
        • Amazon Bedrock
        • Elastic Managed LLMs
        • Google Gemini
        • MCP
        • OpenAI
      • Elastic Stack
        • Cases
        • Index
        • Observability AI Assistant
        • Server log
      • Alerting and cases
        • CrowdStrike
        • D3 Security
        • Email
        • IBM Resilient
        • Jira
        • Jira Service Management
        • Microsoft Defender for Endpoint
        • Microsoft Teams
        • Opsgenie
        • PagerDuty
        • SentinelOne
        • ServiceNow ITSM
        • ServiceNow ITOM
        • ServiceNow SecOps
        • Slack
        • Swimlane
        • TheHive
        • Tines
        • Torq
        • Webhook
        • Webhook - Case Management
        • xMatters
        • XSOAR
      • Data and context sources
        • AbuseIPDB
        • AlienVault OTX
        • Amazon S3
        • Ansible Control Server
        • Argo CD
        • AWS CloudWatch
        • AWS X-Ray
        • Azure Blob Storage
        • Azure Monitor
        • BigQuery
        • Box
        • Brave Search
        • Buildkite
        • Censys
        • Confluence Cloud
        • Databricks
        • Datadog
        • Dropbox
        • Dynatrace
        • Figma
        • Firecrawl
        • Google Cloud IAM
        • Google Cloud Secret Manager
        • GitHub
        • Gmail
        • Google Calendar
        • Google Cloud Monitoring
        • Google Cloud Storage
        • Google Docs
        • Google Drive
        • Google threat intelligence
        • Grafana
        • GraphQL
        • GreyNoise
        • HubSpot
        • Jenkins
        • Jina Reader
        • Jira Cloud
        • Kubernetes
        • Microsoft Teams
        • Monday.com
        • MISP
        • New Relic
        • Notion
        • Okta
        • OneDrive
        • 1Password
        • OpenSearch (AWS OpenSearch Service)
        • Outlook
        • PagerDuty
        • PostHog
        • Prometheus
        • Rootly
        • Salesforce
        • Sentry
        • ServiceNow
        • SharePoint Online
        • SharePoint Server
        • Shodan
        • Slack (v2)
        • Snowflake
        • Sublime Security
        • Tavily
        • Trello
        • UniFi
        • URLScan.io
        • URLVoid
        • VirusTotal
        • Workday
        • Zabbix
        • Zendesk
        • Zoom
      • Preconfigured connectors
    • Kibana plugins
    • Command line tools
      • kibana-encryption-keys
      • kibana-setup
      • kibana-verification-code
    • Case analytics indices schema
  • Cloud
    • Elastic Cloud Enterprise
      • RESTful API
        • API calls
        • How to access the API
          • Access the API using Elastic Cloud Control
          • Access the API from the command line
          • Access the API using a REST application
          • Access the API using the Elastic Cloud Terraform provider
          • Create an API client
        • API examples
          • Setting up your environment
          • A first API call: What deployments are there?
          • Create your first deployment: Elasticsearch and Kibana
          • Applying a new plan: Resize and add high availability
          • Updating a deployment: Checking on progress
          • Applying a new deployment configuration: Upgrade
          • Enable more stack features: Add Enterprise Search to a deployment
          • Dipping a toe into platform automation: Generate a roles token
          • Customize your deployment
          • Remove unwanted deployment templates and instance configurations
          • Secure your settings
        • Changes to index allocation and API
      • Scripts
        • elastic-cloud-enterprise.sh install
        • elastic-cloud-enterprise.sh upgrade
        • elastic-cloud-enterprise.sh reset-adminconsole-password
        • elastic-cloud-enterprise.sh add-stack-version
      • Third party dependencies
        • ECE 4.0
        • ECE 4.1
        • ECE 4.2
    • Elastic Cloud Hosted
      • Hardware
        • GCP
          • VM configurations
          • Choosing a hardware profile
          • Default hardware specifications
            • Regional availability
        • AWS
          • VM configurations
          • FedRAMP VM configurations
          • Choosing a hardware profile
          • Default hardware specifications
            • Regional availability
        • Azure
          • VM configurations
          • Choosing a hardware profile
          • Default hardware specifications
            • Regional availability
      • Regions
        • Available regions, deployment templates, and instance configurations
      • RESTful API
        • Principles
        • Rate limiting
        • Work with Elastic APIs
          • Access the Elasticsearch API console
        • How to access the API
          • Access the API using Elastic Cloud Control
          • Access the API from the command line
          • Access the API using a REST application
          • Access the API using the Elastic Cloud Terraform provider
        • API examples
          • Deployment CRUD operations
          • Other deployment operations
          • Organization operations
        • Changes to index allocation and API
    • Elastic Cloud on Kubernetes
      • API reference
        • 3.5.0
        • 3.4.1
        • 3.4.0
        • 3.3.2
        • 3.3.1
        • 3.3.0
        • 3.2.0
        • 3.1.0
        • 3.0.0
      • Third-party dependencies
        • 3.5.0
        • 3.4.1
        • 3.4.0
        • 3.3.2
        • 3.3.1
        • 3.3.0
        • 3.2.0
        • 3.1.0
        • 3.0.0
      • ECK configuration flags
      • Elasticsearch upgrade predicates
    • Elastic cloud control (ECCTL)
      • Installing
      • Configuring
        • Authentication
        • Example: A shared configuration file
        • Environment variables
        • Multiple configuration files
        • Output format
        • Custom formatting
      • Usage examples
        • List deployments
        • Create a deployment
        • Update a deployment
        • Delete a deployment
      • Command reference
        • ecctl
        • ecctl auth
        • ecctl auth key
        • ecctl auth key create
        • ecctl auth key delete
        • ecctl auth key list
        • ecctl auth key show
        • ecctl comment
        • ecctl comment create
        • ecctl comment delete
        • ecctl comment list
        • ecctl comment show
        • ecctl comment update
        • ecctl deployment
        • ecctl deployment create
        • ecctl deployment delete
        • ecctl deployment elasticsearch
        • ecctl deployment elasticsearch keystore
        • ecctl deployment elasticsearch keystore show
        • ecctl deployment elasticsearch keystore update
        • ecctl deployment extension
        • ecctl deployment extension create
        • ecctl deployment extension delete
        • ecctl deployment extension list
        • ecctl deployment extension show
        • ecctl deployment extension update
        • ecctl deployment list
        • ecctl deployment plan
        • ecctl deployment plan cancel
        • ecctl deployment resource
        • ecctl deployment resource delete
        • ecctl deployment resource restore
        • ecctl deployment resource shutdown
        • ecctl deployment resource start-maintenance
        • ecctl deployment resource start
        • ecctl deployment resource stop-maintenance
        • ecctl deployment resource stop
        • ecctl deployment resource upgrade
        • ecctl deployment restore
        • ecctl deployment resync
        • ecctl deployment search
        • ecctl deployment show
        • ecctl deployment shutdown
        • ecctl deployment template
        • ecctl deployment template create
        • ecctl deployment template delete
        • ecctl deployment template list
        • ecctl deployment template show
        • ecctl deployment template update
        • ecctl deployment traffic-filter
        • ecctl deployment traffic-filter association
        • ecctl deployment traffic-filter association create
        • ecctl deployment traffic-filter association delete
        • ecctl deployment traffic-filter create
        • ecctl deployment traffic-filter delete
        • ecctl deployment traffic-filter list
        • ecctl deployment traffic-filter show
        • ecctl deployment traffic-filter update
        • ecctl deployment update
        • ecctl generate
        • ecctl generate completions
        • ecctl generate docs
        • ecctl init
        • ecctl platform
        • ecctl platform allocator
        • ecctl platform allocator list
        • ecctl platform allocator maintenance
        • ecctl platform allocator metadata
        • ecctl platform allocator metadata delete
        • ecctl platform allocator metadata set
        • ecctl platform allocator metadata show
        • ecctl platform allocator search
        • ecctl platform allocator show
        • ecctl platform allocator vacate
        • ecctl platform constructor
        • ecctl platform constructor list
        • ecctl platform constructor maintenance
        • ecctl platform constructor resync
        • ecctl platform constructor show
        • ecctl platform enrollment-token
        • ecctl platform enrollment-token create
        • ecctl platform enrollment-token delete
        • ecctl platform enrollment-token list
        • ecctl platform info
        • ecctl platform instance-configuration
        • ecctl platform instance-configuration create
        • ecctl platform instance-configuration delete
        • ecctl platform instance-configuration list
        • ecctl platform instance-configuration pull
        • ecctl platform instance-configuration show
        • ecctl platform instance-configuration update
        • ecctl platform proxy
        • ecctl platform proxy filtered-group
        • ecctl platform proxy filtered-group create
        • ecctl platform proxy filtered-group delete
        • ecctl platform proxy filtered-group list
        • ecctl platform proxy filtered-group show
        • ecctl platform proxy filtered-group update
        • ecctl platform proxy list
        • ecctl platform proxy settings
        • ecctl platform proxy settings show
        • ecctl platform proxy settings update
        • ecctl platform proxy show
        • ecctl platform repository
        • ecctl platform repository create
        • ecctl platform repository delete
        • ecctl platform repository list
        • ecctl platform repository show
        • ecctl platform role
        • ecctl platform role create
        • ecctl platform role delete
        • ecctl platform role list
        • ecctl platform role show
        • ecctl platform role update
        • ecctl platform runner
        • ecctl platform runner list
        • ecctl platform runner resync
        • ecctl platform runner search
        • ecctl platform runner show
        • ecctl project
        • ecctl project create
        • ecctl project delete
        • ecctl project list
        • ecctl project show
        • ecctl stack
        • ecctl stack delete
        • ecctl stack list
        • ecctl stack show
        • ecctl stack upload
        • ecctl user
        • ecctl user create
        • ecctl user delete
        • ecctl user disable
        • ecctl user enable
        • ecctl user key
        • ecctl user key delete
        • ecctl user key list
        • ecctl user key show
        • ecctl user list
        • ecctl user show
        • ecctl user update
        • ecctl version
  • Security
    • Fields and object schemas
      • Elastic Security ECS field reference
      • Timeline schema
      • Alert schema
    • Endpoint command reference
    • Elastic Defend advanced settings
    • Prebuilt detection rules reference
      • Prebuilt detection rules reference
      • Deprecated prebuilt detection rules
      • Windows Audit Policies
        • Audit Authorization Policy Change
        • Audit Certification Services
        • Audit Computer Account Management
        • Audit Detailed File Share
        • Audit Directory Service Access
        • Audit Directory Service Changes
        • Audit Filtering Platform Connection
        • Audit Filtering Platform Packet Drop
        • Audit Handle Manipulation
        • Audit Kerberos Authentication Service
        • Audit Kerberos Service Ticket Operations
        • Audit Logon
        • Audit Other Object Access Events
        • Audit Policy Change
        • Audit Process Creation And Command Line
        • Audit Security Group Management
        • Audit Security System Extension
        • Audit Sensitive Privilege Use
        • Audit Special Logon
        • Audit Token Right Adjusted Events
        • Audit User Account Management
        • Audit Powershell Scriptblock
        • Sysmon Event ID 1: Process Creation
        • Sysmon Event ID 2: File Creation Time Changed
        • Sysmon Event ID 3: Network Connection
        • Sysmon Event ID 7: Image Loaded
        • Sysmon Event ID 8: Create Remote Thread
        • Sysmon Event ID 10: Process Access
        • Sysmon Event ID 11: File Create
        • Sysmon Event ID 12, 13, 14: Registry Events
        • Sysmon Event ID 17, 18: Pipe Events
        • Sysmon Event ID 19, 20, 21: WMI Events
        • Sysmon Event ID 22: DNS Query
        • Sysmon Event ID 23: File Delete
  • Observability
    • Fields and object schemas
    • Infrastructure metrics reference
      • Host metrics
      • Container metrics
      • Kubernetes pod metrics
      • AWS metrics
  • Ingestion tools
    • APM
      • APM settings
      • APM settings for Elastic Cloud
      • APM settings for Elastic Cloud Enterprise
      • APM Attacher for Kubernetes
        • Instrument and configure pods
          • Add the helm repository to Helm
          • Configure the webhook with a Helm values file
          • Install the webhook with Helm
          • Add a pod template annotation to each pod you want to auto-instrument
          • Watch data flow into the Elastic Stack
      • APM Architecture for AWS Lambda
        • Performance impact and overhead
        • Configuration options
        • Using AWS Secrets Manager to manage APM authentication keys
      • APM agents
        • APM .NET Agent
          • Supported technologies
          • Set up the APM .NET Agent
            • Profiler auto-instrumentation
            • ASP.NET Core
            • .NET 8+
            • ASP.NET
            • Azure Functions
            • Other .NET applications
          • NuGet packages
            • Entity Framework Core
            • Entity Framework 6
            • Elasticsearch
            • gRPC
            • SqlClient
            • StackExchange.Redis
            • Azure Cosmos DB
            • Azure Service Bus
            • Azure Storage
            • MongoDB
            • Confluent Kafka
          • Configuration
            • Configuration on ASP.NET Core
            • Configuration for Windows services
            • Configuration on ASP.NET
            • Core configuration options
            • Reporter configuration options
            • HTTP configuration options
            • Messaging configuration options
            • Stacktrace configuration options
            • Supportability configuration options
            • All options summary
          • Public API
          • OpenTelemetry bridge
          • Metrics
          • Logs
            • Serilog
            • NLog
            • Manual log correlation
          • Performance tuning
          • MongoDB
          • Troubleshooting
        • APM Go agent
          • Set up the APM Go Agent
            • Built-in instrumentation modules
            • Custom instrumentation
            • Context propagation
          • Supported technologies
          • Configuration
          • API documentation
          • Metrics
          • Logs
          • Log correlation
          • OpenTelemetry API
          • OpenTracing API
          • Contributing
          • Upgrading
          • Troubleshooting
        • APM Java agent
          • Set up the APM Java Agent
            • Manual setup with -javaagent flag
            • Automatic setup with apm-agent-attach-cli.jar
            • Programmatic API setup to self-attach
            • SSL/TLS communication with APM Server
            • Monitoring AWS Lambda Java Functions
          • Supported technologies
          • Configuration
            • Circuit-Breaker
            • Core
            • Datastore
            • HTTP
            • Huge Traces
            • JAX-RS
            • JMX
            • Logging
            • Messaging
            • Metrics
            • Profiling
            • Reporter
            • Serverless
            • Stacktrace
            • Property file reference
          • Tracing APIs
            • Public API
            • OpenTelemetry bridge
            • OpenTracing bridge
          • Plugin API
          • Metrics
          • Logs
          • How to find slow methods
            • Sampling-based profiler
            • API/Code
            • Annotations
            • Configuration-based
          • Overhead and performance tuning
          • Frequently asked questions
          • Community plugins
          • Upgrading
          • Troubleshooting
        • APM Node.js agent
          • Set up the Agent
            • Monitoring AWS Lambda Node.js Functions
            • Monitoring Node.js Azure Functions
            • Get started with Express
            • Get started with Fastify
            • Get started with hapi
            • Get started with Koa
            • Get started with TypeScript
            • Get started with a custom Node.js stack
            • Starting the agent
          • Supported technologies
          • Configuration
            • Configuring the agent
            • Configuration options
            • Custom transactions
            • Custom spans
          • API Reference
            • Agent API
            • Transaction API
            • Span API
          • Metrics
          • Logs
          • OpenTelemetry bridge
          • OpenTracing bridge
          • Source map support
          • ECMAScript module support
          • Distributed tracing
          • Message queues
          • Performance Tuning
          • Upgrading
            • Upgrade to v4.x
            • Upgrade to v3.x
            • Upgrade to v2.x
            • Upgrade to v1.x
          • Troubleshooting
        • APM PHP agent
          • Set up the APM PHP Agent
          • Supported technologies
          • Configuration
            • Configuration reference
          • Public API
          • Troubleshooting
        • APM Python agent
          • Set up the APM Python Agent
            • Django support
            • Flask support
            • Aiohttp Server support
            • Tornado Support
            • Starlette/FastAPI Support
            • Sanic Support
            • Monitoring AWS Lambda Python Functions
            • Monitoring Azure Functions
            • Wrapper Support
            • ASGI Middleware
          • Supported technologies
          • Configuration
          • Advanced topics
            • Instrumenting custom code
            • Sanitizing data
            • How the Agent works
            • Run Tests Locally
          • API reference
          • Metrics
          • OpenTelemetry API Bridge
          • Logs
          • Performance tuning
          • Upgrading
            • Upgrading to version 6 of the agent
            • Upgrading to version 5 of the agent
            • Upgrading to version 4 of the agent
          • Troubleshooting
        • APM Ruby agent
          • Set up the APM Ruby agent
            • Getting started with Rails
            • Getting started with Rack
          • Supported technologies
          • Configuration
          • Advanced topics
            • Adding additional context
            • Custom instrumentation
          • API reference
          • Metrics
          • Logs
          • OpenTracing API
          • GraphQL
          • Performance tuning
          • Upgrading
          • Troubleshooting
        • APM RUM JavaScript agent
          • Set up the APM Real User Monitoring JavaScript Agent
            • Install the Agent
            • Configure CORS
          • Supported technologies
          • Configuration
          • API reference
            • Agent API
            • Transaction API
            • Span API
          • Source maps
          • Framework-specific integrations
            • React integration
            • Angular integration
            • Vue integration
          • Distributed tracing
          • Breakdown metrics
          • OpenTracing
          • Advanced topics
            • How to interpret long task spans in the UI
            • Using with TypeScript
            • Custom page load transaction names
            • Custom Transactions
          • Performance tuning
          • Upgrading
          • Troubleshooting
    • Beats
      • Beats for Elasticsearch Serverless
      • Config file format
        • Namespacing
        • Config file data types
        • Environment variables
        • Reference variables
        • Config file ownership and permissions
        • Command line arguments
        • YAML tips and gotchas
      • Auditbeat
        • Quick start
          • Installation script
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Auditbeat on Docker
          • Running Auditbeat on Kubernetes
          • Auditbeat and systemd
          • Start Auditbeat
          • Stop Auditbeat
        • Upgrade Auditbeat
        • Configure
          • Modules
          • General settings
          • Project paths
          • Config file reloading
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_session_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • now
            • rate_limit
            • registered_domain
            • rename
            • replace
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • auditbeat.reference.yml
        • How to guides
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Enrich events with geoIP information
          • Parse data using an ingest pipeline
          • Use environment variables in the configuration
          • Avoid YAML formatting problems
        • Modules
          • Auditd Module
          • File Integrity Module
          • System Module
            • System host dataset
            • System login dataset
            • System package dataset
            • System process dataset
            • System socket dataset
            • System user dataset
        • Exported fields
          • Auditd fields
          • Beat fields
          • Cloud provider metadata fields
          • Common fields
          • Docker fields
          • ECS fields
          • File Integrity fields
          • Host fields
          • Jolokia Discovery autodiscover provider fields
          • Kubernetes fields
          • Process fields
          • System fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get Help
          • Debug
          • Understand logged metrics
          • Common problems
            • Auditbeat fails to watch folders because too many files are open
            • Auditbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
        • Contribute
      • Filebeat
        • Quick start
          • Installation script
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Filebeat on Docker
          • Run Filebeat on Kubernetes
          • Run Filebeat on Cloud Foundry
          • Filebeat and systemd
          • Start Filebeat
          • Stop Filebeat
        • Upgrade
        • How Filebeat works
        • Configure
          • Inputs
            • Multiline messages
            • AWS CloudWatch
            • AWS S3
            • Azure Event Hub
            • Azure Blob Storage
            • Benchmark
            • CEL
            • Cloud Foundry
            • CometD
            • Container
            • Entity Analytics
            • ETW
            • filestream
            • GCP Pub/Sub
            • Google Cloud Storage
            • HTTP Endpoint
            • HTTP JSON
            • journald
            • Kafka
            • Log
            • MQTT
            • NetFlow
            • Office 365 Management Activity API
            • Redis
            • Salesforce
            • Stdin
            • Streaming
            • Syslog
            • TCP
            • UDP
            • Unified Logs
            • Unix
            • winlog
          • Modules
            • Override input settings
          • General settings
          • Project paths
          • Config file loading
            • Live reloading
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • cache
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_cef
            • decode_csv_fields
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • now
            • parse_aws_vpc_flow_log
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • timestamp
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Autodiscover
            • Hints based autodiscover
            • Advanced usage
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • filebeat.reference.yml
        • How to guides
          • Override configuration settings
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Load ingest pipelines
          • Enrich events with geoIP information
          • Deduplicate data
          • Parse data using an ingest pipeline
          • Use environment variables in the configuration
          • Avoid YAML formatting problems
          • Migrate log or container input configurations to filestream
          • How to choose file identity for filestream
          • Migrating from a Deprecated Filebeat Module
          • Removing files after ingestion
        • Modules
          • Modules
          • ActiveMQ module
          • Apache module
          • Auditd module
          • AWS module
          • AWS Fargate module
          • Azure module
          • CEF module
          • Check Point module
          • Cisco module
          • CoreDNS module
          • CrowdStrike module
          • Cyberark PAS module
          • Elasticsearch module
          • Envoyproxy module
          • Fortinet module
          • Google Cloud Platform (GCP) module
          • Google Workspace module
          • HAProxy module
          • IBM MQ module
          • Icinga module
          • IIS module
          • Iptables module
          • Juniper JUNOS module
          • Kafka module
          • Kibana module
          • Logstash module
          • Microsoft module
          • MISP module
          • MongoDB module
          • MSSQL module
          • MySQL module
          • MySQL Enterprise module
          • NATS module
          • NetFlow module
          • Nginx module
          • Office 365 module
          • Okta module
          • Oracle module
          • Osquery module
          • Palo Alto Networks module
          • Pensando module
          • PostgreSQL module
          • RabbitMQ module
          • Redis module
          • Salesforce module
            • Set up the OAuth App in the Salesforce
          • Google Santa module
          • Snyk module
          • Sophos module
          • Suricata module
          • System module
          • Threat Intel module
          • Traefik module
          • Zeek (Bro) module
          • ZooKeeper module
          • Zoom module
        • Exported fields
          • ActiveMQ fields
          • Apache fields
          • Auditd fields
          • AWS fields
          • AWS CloudWatch fields
          • AWS Fargate fields
          • Azure fields
          • Beat fields
          • Decode CEF processor fields fields
          • CEF fields
          • Check Point fields
          • Cisco fields
          • Cloud provider metadata fields
          • CoreDNS fields
          • CrowdStrike fields
          • Cyberark PAS fields
          • Docker fields
          • ECS fields
          • Elasticsearch fields
          • Elasticsearch query log fields
          • Envoyproxy fields
          • Fortinet fields
          • Google Cloud Platform (GCP) fields
          • Google Workspace fields
          • HAProxy fields
          • Host fields
          • IBM MQ fields
          • Icinga fields
          • IIS fields
          • Iptables fields
          • Jolokia Discovery autodiscover provider fields
          • Juniper JUNOS fields
          • Kafka fields
          • Kibana fields
          • Kubernetes fields
          • Log file content fields
          • Logstash fields
          • Lumberjack fields
          • Microsoft fields
          • MISP fields
          • MongoDB fields
          • MSSQL fields
          • MySQL fields
          • MySQL Enterprise fields
          • NATS fields
          • NetFlow fields
          • Nginx fields
          • Office 365 fields
          • Okta fields
          • Oracle fields
          • Osquery fields
          • Palo Alto Networks fields
          • Pensando fields
          • PostgreSQL fields
          • Process fields
          • RabbitMQ fields
          • Redis fields
          • s3 fields
          • Salesforce fields
          • Google Santa fields
          • Snyk fields
          • Sophos fields
          • Suricata fields
          • System fields
          • Threat Intel fields
          • Traefik fields
          • Windows ETW fields
          • Zeek (Bro) fields
          • ZooKeeper fields
          • Zoom fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Common problems
            • Error extracting container id while using Kubernetes metadata
            • Can't read log files from network volumes
            • Filebeat isn't collecting lines from a file
            • Too many open file handlers
            • Registry file is too large
            • Inode reuse causes Filebeat to skip lines
            • Log rotation results in lost or duplicate events
            • Open file handlers cause issues with Windows file rotation
            • Filebeat is using too much CPU
            • Dashboard in Kibana is breaking up data fields incorrectly
            • Fields are not indexed or usable in Kibana visualizations
            • Filebeat isn't shipping the last line of a file
            • Filebeat keeps open file handlers of deleted files for a long time
            • Filebeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
            • Files are not fully ingested when using autodiscover
        • Contribute
      • Heartbeat
        • Quick start
          • Installation script
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Heartbeat on Docker
          • Running Heartbeat on Kubernetes
          • Heartbeat and systemd
          • Stop Heartbeat
        • Configure
          • Monitors
            • Common monitor options
            • ICMP options
            • TCP options
            • HTTP options
          • Task scheduler
          • General settings
          • Project paths
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • now
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Autodiscover
            • Hints based autodiscover
            • Advanced usage
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • heartbeat.reference.yml
        • How to guides
          • Add observer and geo metadata
          • Load the Elasticsearch index template
          • Change the index name
          • Enrich events with geoIP information
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems
        • Exported fields
          • Beat fields
          • Synthetics browser metrics fields
          • Cloud provider metadata fields
          • Common heartbeat monitor fields
          • Docker fields
          • ECS fields
          • Host fields
          • HTTP monitor fields
          • ICMP fields
          • Jolokia Discovery autodiscover provider fields
          • Kubernetes fields
          • Process fields
          • Host lookup fields
          • APM Service fields
          • SOCKS5 proxy fields
          • Monitor state fields
          • Monitor summary fields
          • Synthetics types fields
          • TCP layer fields
          • TLS encryption layer fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Common problems
            • Heartbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • High RSS memory usage due to MADV settings
        • Contribute
      • Metricbeat
        • Quick start
          • Installation script
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Metricbeat on Docker
          • Run Metricbeat on Kubernetes
          • Run Metricbeat on Cloud Foundry
          • Metricbeat and systemd
          • Start Metricbeat
          • Stop Metricbeat
        • Upgrade Metricbeat
        • How Metricbeat works
          • Event structure
          • Error event structure
          • Key metricbeat features
        • Configure
          • Modules
          • General settings
          • Project paths
          • Config file loading
            • Live reloading
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • now
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Autodiscover
            • Hints based autodiscover
            • Advanced usage
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • metricbeat.reference.yml
        • How to guides
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Enrich events with geoIP information
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems
        • Modules
          • ActiveMQ module
            • ActiveMQ broker metricset
            • ActiveMQ queue metricset
            • ActiveMQ topic metricset
          • Aerospike module
            • Aerospike namespace metricset
          • Airflow module
            • Airflow statsd metricset
          • Apache module
            • Apache status metricset
          • AWS module
            • AWS awshealth metricset
            • AWS billing metricset
            • AWS cloudwatch metricset
            • AWS dynamodb metricset
            • AWS ebs metricset
            • AWS ec2 metricset
            • AWS elb metricset
            • AWS kinesis metricset
            • AWS lambda metricset
            • AWS natgateway metricset
            • AWS rds metricset
            • AWS s3_daily_storage metricset
            • AWS s3_request metricset
            • AWS sns metricset
            • AWS sqs metricset
            • AWS transitgateway metricset
            • AWS usage metricset
            • AWS vpn metricset
          • AWS Fargate module
            • AWS Fargate task_stats metricset
          • Azure module
            • Azure app_insights metricset
            • Azure app_state metricset
            • Azure billing metricset
            • Azure compute_vm metricset
            • Azure compute_vm_scaleset metricset
            • Azure container_instance metricset
            • Azure container_registry metricset
            • Azure container_service metricset
            • Azure database_account metricset
            • Azure monitor metricset
            • Azure storage metricset
          • Beat module
            • Beat state metricset
            • Beat stats metricset
          • Benchmark module
            • Benchmark info metricset
          • Ceph module
            • Ceph cluster_disk metricset
            • Ceph cluster_health metricset
            • Ceph cluster_status metricset
            • Ceph mgr_cluster_disk metricset
            • Ceph mgr_cluster_health metricset
            • Ceph mgr_osd_perf metricset
            • Ceph mgr_osd_pool_stats metricset
            • Ceph mgr_osd_tree metricset
            • Ceph mgr_pool_disk metricset
            • Ceph monitor_health metricset
            • Ceph osd_df metricset
            • Ceph osd_tree metricset
            • Ceph pool_disk metricset
          • Cloudfoundry module
            • Cloudfoundry container metricset
            • Cloudfoundry counter metricset
            • Cloudfoundry value metricset
          • CockroachDB module
            • CockroachDB status metricset
          • Consul module
            • Consul agent metricset
          • Containerd module
            • Containerd blkio metricset
            • Containerd cpu metricset
            • Containerd memory metricset
          • Coredns module
            • Coredns stats metricset
          • Couchbase module
            • Couchbase bucket metricset
            • Couchbase cluster metricset
            • Couchbase node metricset
          • CouchDB module
            • CouchDB server metricset
          • Docker module
            • Docker container metricset
            • Docker cpu metricset
            • Docker diskio metricset
            • Docker event metricset
            • Docker healthcheck metricset
            • Docker image metricset
            • Docker info metricset
            • Docker memory metricset
            • Docker network metricset
            • Docker network_summary metricset
          • Dropwizard module
            • Dropwizard collector metricset
          • Elasticsearch module
            • Elasticsearch ccr metricset
            • Elasticsearch cluster_stats metricset
            • Elasticsearch enrich metricset
            • Elasticsearch index metricset
            • Elasticsearch index_recovery metricset
            • Elasticsearch index_summary metricset
            • Elasticsearch ingest_pipeline metricset
            • Elasticsearch ml_job metricset
            • Elasticsearch node metricset
            • Elasticsearch node_stats metricset
            • Elasticsearch pending_tasks metricset
            • Elasticsearch security_stats metricset
            • Elasticsearch shard metricset
          • Envoyproxy module
            • Envoyproxy server metricset
          • Etcd module
            • Etcd leader metricset
            • Etcd metrics metricset
            • Etcd self metricset
            • Etcd store metricset
          • Google Cloud Platform module
            • Google Cloud Platform billing metricset
            • Google Cloud Platform carbon metricset
            • Google Cloud Platform compute metricset
            • Google Cloud Platform dataproc metricset
            • Google Cloud Platform firestore metricset
            • Google Cloud Platform gke metricset
            • Google Cloud Platform loadbalancing metricset
            • Google Cloud Platform metrics metricset
            • Google Cloud Platform pubsub metricset
            • Google Cloud Platform storage metricset
            • Google Cloud Platform vertexai_logs metricset
          • Golang module
            • Golang expvar metricset
            • Golang heap metricset
          • Graphite module
            • Graphite server metricset
          • HAProxy module
            • HAProxy info metricset
            • HAProxy stat metricset
          • HTTP module
            • HTTP json metricset
            • HTTP server metricset
          • IBM MQ module
            • IBM MQ qmgr metricset
          • IIS module
            • IIS application_pool metricset
            • IIS webserver metricset
            • IIS website metricset
          • Istio module
            • Istio citadel metricset
            • Istio galley metricset
            • Istio istiod metricset
            • Istio mesh metricset
            • Istio mixer metricset
            • Istio pilot metricset
            • Istio proxy metricset
          • Jolokia module
            • Jolokia jmx metricset
          • Kafka module
            • Kafka broker metricset
            • Kafka consumer metricset
            • Kafka consumergroup metricset
            • Kafka partition metricset
            • Kafka producer metricset
          • Kibana module
            • Kibana cluster_actions metricset
            • Kibana cluster_rules metricset
            • Kibana node_actions metricset
            • Kibana node_rules metricset
            • Kibana stats metricset
            • Kibana status metricset
          • Kubernetes module
            • Kubernetes apiserver metricset
            • Kubernetes container metricset
            • Kubernetes controllermanager metricset
            • Kubernetes event metricset
            • Kubernetes node metricset
            • Kubernetes pod metricset
            • Kubernetes proxy metricset
            • Kubernetes scheduler metricset
            • Kubernetes state_container metricset
            • Kubernetes state_cronjob metricset
            • Kubernetes state_daemonset metricset
            • Kubernetes state_deployment metricset
            • Kubernetes state_horizontalpodautoscaler metricset
            • Kubernetes state_job metricset
            • Kubernetes state_node metricset
            • Kubernetes state_persistentvolumeclaim metricset
            • Kubernetes state_pod metricset
            • Kubernetes state_replicaset metricset
            • Kubernetes state_resourcequota metricset
            • Kubernetes state_service metricset
            • Kubernetes state_statefulset metricset
            • Kubernetes state_storageclass metricset
            • Kubernetes system metricset
            • Kubernetes volume metricset
          • KVM module
            • KVM dommemstat metricset
            • KVM status metricset
          • Linux module
            • Linux conntrack metricset
            • Linux iostat metricset
            • Linux ksm metricset
            • Linux memory metricset
            • Linux pageinfo metricset
            • Linux pressure metricset
            • Linux rapl metricset
          • Logstash module
            • Logstash node metricset
            • Logstash node_stats metricset
          • Memcached module
            • Memcached stats metricset
          • Cisco Meraki module
            • Cisco Meraki device_health metricset
            • Cisco Meraki network_health metricset
          • MongoDB module
            • MongoDB collstats metricset
            • MongoDB dbstats metricset
            • MongoDB metrics metricset
            • MongoDB replstatus metricset
            • MongoDB status metricset
          • MSSQL module
            • MSSQL performance metricset
            • MSSQL transaction_log metricset
          • Munin module
            • Munin node metricset
          • MySQL module
            • MySQL galera_status metricset
            • galera status MetricSet
            • MySQL performance metricset
            • MySQL query metricset
            • MySQL status metricset
          • NATS module
            • NATS connection metricset
            • NATS connections metricset
            • NATS jetstream metricset
            • NATS route metricset
            • NATS routes metricset
            • NATS stats metricset
            • NATS subscriptions metricset
          • Nginx module
            • Nginx stubstatus metricset
          • Openmetrics module
            • Openmetrics collector metricset
          • Oracle module
            • Oracle performance metricset
            • Oracle sysmetric metricset
            • Oracle tablespace metricset
          • Panw module
            • Panw interfaces metricset
            • Panw routing metricset
            • Panw system metricset
            • Panw vpn metricset
          • PHP_FPM module
            • PHP_FPM pool metricset
            • PHP_FPM process metricset
          • PostgreSQL module
            • PostgreSQL activity metricset
            • PostgreSQL bgwriter metricset
            • PostgreSQL database metricset
            • PostgreSQL statement metricset
          • Prometheus module
            • Prometheus collector metricset
            • Prometheus query metricset
            • Prometheus remote_write metricset
          • RabbitMQ module
            • RabbitMQ connection metricset
            • RabbitMQ exchange metricset
            • RabbitMQ node metricset
            • RabbitMQ queue metricset
            • RabbitMQ shovel metricset
          • Redis module
            • Redis info metricset
            • Redis key metricset
            • Redis keyspace metricset
          • Redis Enterprise module
            • Redis Enterprise node metricset
            • Redis Enterprise proxy metricset
          • SQL module
            • Host Setup
            • SQL query metricset
          • Stan module
            • Stan channels metricset
            • Stan stats metricset
            • Stan subscriptions metricset
          • Statsd module
            • Metricsets
            • Statsd server metricset
          • SyncGateway module
            • SyncGateway db metricset
            • SyncGateway memory metricset
            • SyncGateway replication metricset
            • SyncGateway resources metricset
          • System module
            • System core metricset
            • System cpu metricset
            • System diskio metricset
            • System entropy metricset
            • System filesystem metricset
            • System fsstat metricset
            • System load metricset
            • System memory metricset
            • System network metricset
            • System network_summary metricset
            • System process metricset
            • System process_summary metricset
            • System raid metricset
            • System service metricset
            • System socket metricset
            • System socket_summary metricset
            • System uptime metricset
            • System users metricset
            • System ntp metricset
          • Tomcat module
            • Tomcat cache metricset
            • Tomcat memory metricset
            • Tomcat requests metricset
            • Tomcat threading metricset
          • Traefik module
            • Traefik health metricset
          • uWSGI module
            • uWSGI status metricset
          • vSphere module
            • vSphere cluster metricset
            • vSphere datastore metricset
            • vSphere datastorecluster metricset
            • vSphere host metricset
            • vSphere network metricset
            • vSphere resourcepool metricset
            • vSphere virtualmachine metricset
          • Windows module
            • Windows perfmon metricset
            • Windows service metricset
            • Windows wmi metricset
          • ZooKeeper module
            • ZooKeeper connection metricset
            • ZooKeeper mntr metricset
            • ZooKeeper server metricset
        • Exported fields
          • ActiveMQ fields
          • Aerospike fields
          • Airflow fields
          • Apache fields
          • AutoOps ES fields
          • AWS fields
          • AWS Fargate fields
          • Azure fields
          • Beat fields
          • Beat fields
          • Benchmark fields
          • Ceph fields
          • Cloud provider metadata fields
          • Cloudfoundry fields
          • CockroachDB fields
          • Common fields
          • Consul fields
          • Containerd fields
          • Coredns fields
          • Couchbase fields
          • CouchDB fields
          • Docker fields
          • Docker fields
          • Dropwizard fields
          • ECS fields
          • Elasticsearch fields
          • Envoyproxy fields
          • Etcd fields
          • Google Cloud Platform fields
          • Golang fields
          • Graphite fields
          • HAProxy fields
          • Host fields
          • HTTP fields
          • IBM MQ fields
          • IIS fields
          • Istio fields
          • Jolokia fields
          • Jolokia Discovery autodiscover provider fields
          • Kafka fields
          • Kibana fields
          • Kubernetes fields
          • Kubernetes fields
          • KVM fields
          • Linux fields
          • Logstash fields
          • Memcached fields
          • Cisco Meraki fields
          • MongoDB fields
          • MSSQL fields
          • Munin fields
          • MySQL fields
          • NATS fields
          • Nginx fields
          • Openmetrics fields
          • Oracle fields
          • Panw fields
          • PHP_FPM fields
          • PostgreSQL fields
          • Process fields
          • Prometheus fields
          • Prometheus typed metrics fields
          • RabbitMQ fields
          • Redis fields
          • Redis Enterprise fields
          • SQL fields
          • Stan fields
          • Statsd fields
          • SyncGateway fields
          • System fields
          • Tomcat fields
          • Traefik fields
          • uWSGI fields
          • vSphere fields
          • Windows fields
          • ZooKeeper fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Common problems
            • open /compat/linux/proc: no such file or directory error on FreeBSD
            • Metricbeat collects system metrics for interfaces you didn't configure
            • Metricbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
        • Contribute
      • Packetbeat
        • Quick start
          • Installation script
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Packetbeat on Docker
          • Packetbeat and systemd
          • Start Packetbeat
          • Stop Packetbeat
        • Upgrade Packetbeat
        • Configure
          • Traffic sniffing
          • Network flows
          • Protocols
            • Common protocol options
            • ICMP
            • DNS
            • HTTP
            • AMQP
            • Cassandra
            • Memcache
            • MySQL
            • PgSQL
            • Thrift
            • MongoDB
            • TLS
            • Redis
          • Processes
          • General settings
          • Project paths
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • now
            • rate_limit
            • registered_domain
            • rename
            • replace
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Internal queue
          • Logging
          • HTTP endpoint
            • Protocol-Specific Metrics
          • Instrumentation
          • Feature flags
          • packetbeat.reference.yml
        • How to guides
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Enrich events with geoIP information
          • Load ingest pipelines
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems
        • Exported fields
          • AMQP fields
          • Beat fields
          • Cassandra fields
          • Cloud provider metadata fields
          • Common fields
          • DHCPv4 fields
          • DNS fields
          • Docker fields
          • ECS fields
          • Flow Event fields
          • Host fields
          • HTTP fields
          • ICMP fields
          • Jolokia Discovery autodiscover provider fields
          • Kubernetes fields
          • Memcache fields
          • MongoDb fields
          • MySQL fields
          • NFS fields
          • PostgreSQL fields
          • Process fields
          • Raw fields
          • Redis fields
          • SIP fields
          • Thrift-RPC fields
          • Detailed TLS fields
          • Transaction Event fields
          • Measurements (Transactions) fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Visualize Packetbeat data in Kibana
          • Customize the Discover page
          • Kibana queries and filters
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Record a trace
          • Common problems
            • Dashboard in Kibana is breaking up data fields incorrectly
            • Packetbeat doesn't see any packets when using mirror ports
            • Packetbeat Can't capture traffic from Windows loopback interface
            • Packetbeat is missing long running transactions
            • Packetbeat isn't capturing MySQL performance data
            • Packetbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
            • Fields show up as nested JSON in Kibana
        • Contribute
      • Winlogbeat
        • Quick start
          • Installation script
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Start Winlogbeat
          • Stop Winlogbeat
        • Upgrade
        • Configure
          • Winlogbeat
          • General settings
          • Project paths
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • now
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • timestamp
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Internal queue
          • Logging
          • HTTP endpoint
            • Event Processing Metrics
          • Instrumentation
          • winlogbeat.reference.yml
        • How to guides
          • Enrich events with geoIP information
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Load ingest pipelines
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems
        • Modules
          • PowerShell Module
          • Security Module
          • Sysmon Module
        • Exported fields
          • Beat fields
          • Cloud provider metadata fields
          • Docker fields
          • ECS fields
          • Legacy Winlogbeat alias fields
          • Host fields
          • Jolokia Discovery autodiscover provider fields
          • Kubernetes fields
          • PowerShell module fields
          • Process fields
          • Security module fields
          • Sysmon module fields
          • Winlogbeat fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
        • Troubleshoot
          • Get Help
          • Debug
          • Understand logged metrics
          • Common problems
            • Dashboard in Kibana is breaking up data fields incorrectly
            • Bogus computer_name fields are reported in some events
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
            • Not sure how to read from .evtx files
        • Contribute
      • Upgrade
      • Community Beats
      • Contribute
      • Elastic logging plugin for Docker
        • Install and configure
        • Configuration options
        • Usage examples
        • Known problems and limitations
    • Content connectors
      • Connectors references
        • Azure Blob Storage
        • Box
        • Confluence
        • Dropbox
        • GitHub
        • GitLab
        • Gmail
        • Google Cloud Storage
        • Google Drive
        • GraphQL
        • Jira
        • Microsoft SQL
        • MongoDB
        • MySQL
        • Network drive
        • Notion
        • OneDrive
        • OpenText Documentum
        • Oracle
        • Outlook
        • PostgreSQL
        • Redis
        • S3
        • Salesforce
        • Sandfly Security
        • ServiceNow
        • SharePoint Online
        • SharePoint Server
        • Slack
        • Teams
        • Zoom
      • Self-managed connectors
        • Running from a Docker container
        • Running from the source code
        • Docker Compose quickstart
        • Tutorial
      • Build and customize connectors
      • Connectors UI
      • Connector APIs
        • API tutorial
      • Content syncs
      • Extract and transform
        • Content extraction
        • Sync rules
      • Document level security for content connectors
        • How DLS works
        • DLS in Search Applications
      • Management topics
        • Scalability
        • Security
        • Troubleshooting
        • Logs
      • Use cases
        • Internal knowledge search
      • Known issues
      • Release notes
    • Elastic OpenTelemetry
      • Quickstarts
      • Reference Architecture
        • Kubernetes environments
        • Hosts / VMs environments
        • Kafka ingest pipelines
      • Use cases
      • Compatibility and support
        • Features
        • Collector distributions
        • SDK Distributions
        • Elastic OpenTelemetry compared to upstream
        • Limitations
        • Nomenclature
        • Data streams comparison
      • Data streams
      • Central configuration
      • EDOT SDKs
      • Elastic Cloud Forwarder
        • Elastic Cloud Forwarder for AWS
          • Configuration settings
          • Deployment methods
          • Troubleshooting
          • Release notes
        • Elastic Cloud Forwarder for Azure
          • Deployment methods
          • Logs
          • Metrics
          • Configuration settings
          • Upgrade
          • Troubleshooting
            • Sizing and performance tuning
            • Resubmit failed events
        • Elastic Cloud Forwarder for GCP
      • OpenTelemetry
        • Download
        • Deployment modes
        • Configuration
          • Default config (Standalone)
          • Default config (Kubernetes)
          • Logs collection
          • Metrics collection
          • Tracing collection
          • Authentication methods
          • Profiles collection
          • Monitor internal metrics
          • Custom data stream routing
          • Migrate components
          • Proxy settings
        • Components
          • APM Config extension
          • Attributes processor
          • Elastic APM connector
          • Elastic APM intake receiver
          • Elastic APM processor
          • Elasticsearch exporter
          • File log receiver
          • Host metrics receiver
          • Kubernetes cluster receiver
          • Kubernetes objects receiver
          • Kubelet stats receiver
          • Prometheus remote Write receiver
        • Customization
          • Custom Collector
        • Use the contrib Collector
        • Troubleshooting
      • EDOT Android
        • Get started
        • Configuration
        • Crash reporting
        • Manual instrumentation
        • Automatic instrumentation
        • Troubleshooting
        • Release notes
      • EDOT .NET
        • Setup
          • ASP.NET
          • Console applications
          • .NET worker services
          • Zero-code instrumentation
          • Opinionated defaults
        • Configuration
        • Supported technologies
        • Migration
        • Troubleshooting
        • Release notes
      • EDOT iOS
        • Get started
        • Configuration
        • Automatic instrumentation
        • Manual instrumentation
        • Troubleshooting
        • Release notes
      • EDOT Java
        • Setup
          • Kubernetes Setup
          • Runtime attach Setup
        • Configuration
        • Features
        • Supported Technologies
        • Migration
        • Performance overhead
        • Troubleshooting
        • Release notes
      • EDOT Node.js
        • Setup
          • Kubernetes
        • Configuration
        • Supported Technologies
        • Metrics
        • Migration
        • Troubleshooting
        • Release notes
      • EDOT PHP
        • Setup
          • Limitations
        • Configuration
        • Attribute-based instrumentation
        • Supported Technologies
        • Migration
        • Long-running PHP servers
        • Performance overhead
        • Troubleshooting
        • Release notes
      • EDOT Python
        • Setup
          • Kubernetes
          • Manual instrumentation
        • Configuration
        • Supported Technologies
        • Migration
        • Performance overhead
        • Troubleshooting
        • Release notes
      • EDOT Browser
        • Setup
          • Install the agent
          • Proxy and CORS
        • Configuration
        • Metrics, traces, and logs
        • Supported technologies
        • Troubleshooting
    • Managed inputs
      • Authentication, delivery, and failure handling
      • Rate limiting
      • Managed OTLP Endpoint
        • Troubleshooting
      • Managed Prometheus Remote Write endpoint
      • Managed Elasticsearch _bulk endpoint
    • Elastic integrations
      • Integrations quick reference
      • Managed integrations quick reference
      • 1Password
      • Abnormal Security
      • ActiveMQ
      • Active Directory Entity Analytics
      • Admin By Request EPM integration
      • Airflow
      • Airlock Digital
      • Akamai
      • Android OpenTelemetry Assets
      • Anduril Lattice Integration for Elastic
      • Anthropic
      • Anthropic Metrics
      • Apache
        • Apache HTTP Server
        • Apache HTTP Server OpenTelemetry Input Package
        • Apache metrics from OpenTelemetry Collector
        • Apache Spark
        • Apache Tomcat
        • Tomcat NetWitness Logs
      • Apache ActiveMQ OpenTelemetry Assets
      • Apache Airflow OpenTelemetry Assets
      • Apache CouchDB OpenTelemetry Assets
      • Apache Tomcat OpenTelemetry Assets
      • Apache ZooKeeper OpenTelemetry Assets
      • API (custom)
      • Arista NG Firewall
      • Armis
      • Atlassian
        • Atlassian Bitbucket
        • Atlassian Cloud Integration for Elastic
        • Atlassian Confluence
        • Atlassian Jira
      • Auditd
        • Auditd Logs
        • Auditd Manager
      • Auth0
      • authentik
      • AWS
        • Amazon CloudFront
        • AWS CloudTrail Logs OpenTelemetry Assets
        • AWS CUR 2.0 Billing
        • Amazon DynamoDB
        • Amazon EBS
        • Amazon EC2
        • Amazon ECS
        • Amazon EMR
        • AWS API Gateway
        • AWS Config
        • Amazon GuardDuty
        • AWS Health
        • Amazon Kinesis Data Firehose
        • Amazon Kinesis Data Stream
        • Amazon MQ
        • Amazon Managed Streaming for Apache Kafka (MSK)
        • Amazon NAT Gateway
        • Amazon RDS
        • Amazon Redshift
        • Amazon S3
        • Amazon S3 Storage Lens
        • AWS Security Hub Integration for Elastic
        • Amazon Security Lake
        • Amazon SNS
        • Amazon SQS
        • Amazon VPC
        • Amazon VPN
        • AWS Bedrock
        • AWS Bedrock AgentCore
        • AWS Billing
        • AWS CloudTrail
        • AWS CloudWatch
        • AWS CloudWatch (OpenTelemetry)
        • AWS EC2 Metrics OpenTelemetry Assets
        • AWS ECS Metrics OpenTelemetry Assets
        • AWS ELB
        • AWS ELB Access Logs OpenTelemetry Assets
        • AWS ELB Metrics OpenTelemetry Assets
        • AWS Fargate
        • AWS Inspector
        • AWS Lambda
        • AWS Lambda Metrics OpenTelemetry Assets
        • AWS Logs (custom)
        • AWS Network Firewall
        • AWS RDS Metrics OpenTelemetry Assets
        • AWS Route 53
        • AWS Security Hub CSPM
        • AWS SQS Metrics OpenTelemetry Assets
        • AWS Transit Gateway
        • AWS Usage
        • AWS VPC Flow Logs OpenTelemetry Assets
        • AWS WAF
        • AWS Web Application Firewall (WAF) Logs OpenTelemetry Assets
      • Axonius Integration for Elastic
      • Azure
        • Activity logs
        • App Service
        • Application Gateway
        • Application Insights metrics
        • Application Insights metrics overview
        • Application State Insights metrics
        • Azure Activity Logs OpenTelemetry Assets
        • Azure AD Graph Activity Logs
        • Azure AI Foundry Integration
        • Azure Application Gateway OpenTelemetry Assets
        • Azure logs (v2 preview)
        • Azure OpenAI
        • Billing metrics
        • Container instance metrics
        • Container registry metrics
        • Container service metrics
        • Custom Azure Logs
        • Custom Blob Storage Input
        • Database Account metrics
        • Event Hub input
        • Firewall logs
        • Frontdoor
        • Functions
        • Microsoft Entra ID
        • Monitor metrics
        • Network Watcher VNet
        • Network Watcher NSG
        • Platform logs
        • Resource metrics
        • Spring Cloud logs
        • Storage Account metrics
        • Virtual machines metrics
        • Virtual machines scaleset metrics
      • Backstage Integration for Elastic
      • Barracuda
        • Barracuda WAF
        • CloudGen Firewall logs
      • Beelzebub Integration
      • BeyondInsight and Password Safe Integration
      • BeyondTrust EPM Integration for Elastic
      • BeyondTrust Identity Security Insights for Elastic
      • BeyondTrust PRA
      • BitDefender
      • Bitsight Integration
      • Bitwarden
      • blacklens.io
      • BBOT (Bighuge BLS OSINT Tool)
      • Box Events
      • Bravura Monitor
      • Broadcom ProxySG
      • Canva
      • Cassandra
      • Cassandra OpenTelemetry Assets
      • Cato Networks Integration for Elastic
      • CEL Custom API
      • Ceph
      • Check Point
        • Check Point Email
        • Check Point Harmony Endpoint
      • Cilium Tetragon
      • CISA Known Exploited Vulnerabilities
      • Cisco
        • Aironet
        • ASA
        • Duo
        • FTD
        • IOS
        • ISE
        • Meraki
        • Nexus
        • Secure Email Gateway
        • Secure Endpoint
        • Umbrella
      • Cisco Meraki Metrics
      • Citrix
        • ADC
        • Web App Firewall
      • Claroty CTD
      • Claroty xDome
      • Claude Code
      • Claude Cowork
      • Cloudflare
        • Cloudflare
        • Cloudflare Logpush
      • Cloud Asset Inventory
      • CockroachDB Metrics
      • CockroachDB OpenTelemetry Assets
      • Common Event Format (CEF)
      • Containerd
      • Contrast Security
      • CoreDNS
      • Corelight
      • Couchbase
      • CouchDB
      • Cribl
      • CrowdStrike
        • CrowdStrike
        • CrowdStrike Falcon Intelligence
      • Cursor
      • Cyberark
        • CyberArk EPM
        • Privileged Access Security
        • Privileged Threat Analytics
      • Cybereason
      • Cyera
      • CylanceProtect Logs
      • Cyware Intel Exchange
      • Custom Unix Logs Integration for Elastic
      • Custom Websocket logs
      • Darktrace
      • Data Exfiltration Detection
      • Dataminr Pulse Integration User Guide
      • DGA
      • Digital Guardian
      • Docker
      • Docker OpenTelemetry Assets
      • Docker OpenTelemetry Input Package
      • Doppel Integration for Elastic
      • Doppler Integration for Elastic
      • DomainTools Real Time Unified Feeds
      • Elastic APM
      • Elastic APM Intake OpenTelemetry Input Package
      • Elastic Cloud Enterprise Integration
      • Elastic Fleet Server
      • Elastic Security
        • Elastic Defend
        • Elastic Security
        • Defend for Containers
        • Prebuilt Security Detection Rules
        • Security Posture Management
        • Cloud Native Vulnerability Management (CNVM)
        • Cloud Security Posture Management (CSPM)
        • Kubernetes Security Posture Management (KSPM)
        • Threat intelligence utilities
      • Elastic Stack monitoring
        • Beats
        • Elasticsearch
        • Elastic Agent
        • Elastic Package Registry
        • Kibana
        • Logstash
      • Elasticsearch Service Billing
      • Endace
      • Entro
      • Envoy Proxy
      • Envoy Proxy OpenTelemetry Assets
      • ESET PROTECT
      • ESET Threat Intelligence
      • etcd
      • etcd OpenTelemetry Assets
      • ExtraHop
      • Falco
      • F5
        • BIG-IP
      • File Integrity Monitoring
      • File Log OpenTelemetry input
      • Filestream (custom)
      • FireEye Network Security
      • First EPSS
      • Forcepoint Web Security
      • ForgeRock
      • Forescout Integration for Elastic
      • Fortinet
        • FortiEDR Logs
        • FortiGate Firewall Logs
        • FortiMail
        • FortiManager Logs
        • Fortinet FortiProxy
      • Gigamon
      • Global Disaster Alert and Coordination System (GDACS) Integration for Elastic
      • GitHub
      • GitLab
      • Golang
      • Google
        • Google Santa
        • Google SecOps
        • Google Threat Intelligence
        • Google Workspace
      • Google Cloud
        • Custom GCS Input
        • GCP
        • GCP Audit logs
        • GCP Audit logs OpenTelemetry Assets
        • GCP Billing metrics
        • GCP Cloud Run metrics
        • GCP CloudSQL metrics
        • GCP Compute metrics
        • GCP Dataproc metrics
        • GCP DNS logs
        • GCP Firestore metrics
        • GCP Firewall logs
        • GCP GKE metrics
        • GCP Load Balancing metrics
        • GCP Metrics Input
        • GCP PubSub logs (custom)
        • GCP PubSub metrics
        • GCP Redis metrics
        • GCP Security Command Center
        • GCP Storage metrics
        • GCP VPC Flow logs
        • GCP VPC Flow logs OpenTelemetry Assets
        • GCP Vertex AI
      • GoFlow2 logs
      • Grafana Integration
      • Greenhouse Integration
      • GreyNoise
      • HackerOne Integration for Elastic
      • Hadoop
      • HAProxy
      • HAProxy OpenTelemetry Assets
      • Hashicorp Vault
      • Host Metrics OpenTelemetry Input Package
      • Host Traffic Anomalies
      • HPE Aruba CX
      • HTTP Check Integration for Elastic
      • HTTP Endpoint logs (custom)
      • IBM
        • IBM MQ
        • IBM MQ OpenTelemetry Assets
        • IBM QRadar
      • IIS
      • IIS OpenTelemetry Input Package
      • IIS metrics for OpenTelemetry Collector
      • Imperva
        • Imperva Cloud WAF
        • Imperva SecureSphere Logs
      • InfluxDb
      • InfluxDB OpenTelemetry Assets
      • Infoblox
        • BloxOne DDI
        • NIOS
        • Threat Defense
      • Iptables
      • IRONSCALES Integration for Elastic
      • Island Browser Integration for Elastic
      • Istio
      • Jaeger OpenTelemetry Input Package
      • Jamf Compliance Reporter
      • Jamf Pro
      • Jamf Protect
      • Jolokia Input
      • Journald logs (custom)
      • JumpCloud
      • JupiterOne
      • Kafka
        • Kafka
        • Kafka Connect Integration
        • Kafka Logs (custom)
        • Kafka OpenTelemetry Assets
        • Kafka OpenTelemetry Input Package
      • Keeper Security Integration
      • Keycloak
      • Kolide Integration for Elastic
      • Kubernetes
        • Kubernetes
        • API Server metrics
        • Audit logs
        • Container logs
        • Controller Manager metrics
        • Event metrics
        • Kube-state metrics
        • Kubelet metrics
        • OpenTelemetry Assets
        • Proxy metrics
        • Scheduler metrics
      • LastPass
      • Lateral Movement Detection
      • LiteLLM Integration
      • Linux Metrics
      • Living off the Land Attack Detection
      • Logs (custom)
      • Lumos
      • Lyve Cloud
      • macOS
      • macOS Unified Logs (custom)
      • Mattermost
      • Memcached
      • Memcached OpenTelemetry Assets
      • Menlo Security
      • Microsoft
        • Microsoft 365
        • Microsoft Defender for Cloud
        • Microsoft Defender for Endpoint
        • Microsoft DHCP
        • Microsoft DNS Server
        • Microsoft Entra ID Entity Analytics
        • Microsoft Exchange Online Message Trace
        • Microsoft Exchange Server
        • Microsoft Graph Activity Logs
        • Microsoft Intune Integration for Elastic
        • Microsoft Defender XDR
        • Microsoft Office 365 Metrics Integration
        • Microsoft Sentinel
        • Microsoft SQL Server
        • Microsoft SQL Server OpenTelemetry Assets
      • Mimecast
      • Miniflux integration
      • ModSecurity Audit
      • MongoDB
      • MongoDB Atlas
      • MongoDB OpenTelemetry Assets
      • MySQL
        • MySQL
        • MySQL Enterprise
        • MySQL metrics for OpenTelemetry Collector
      • MySQL OpenTelemetry Input Package
      • Nagios XI
      • NATS
      • Neon Cyber
      • NetBox Integration
      • NetFlow Records
      • Netskope
      • Network Beaconing Identification
      • Network Packet Capture
      • Nextron Thor APT Scanner
      • Nginx
        • Nginx
        • Nginx Ingress Controller Logs
        • Nginx Ingress Controller OpenTelemetry Logs
        • Nginx metrics from OpenTelemetry Collector
        • Nginx OpenTelemetry Input Package
      • Nozomi Networks
      • Nvidia GPU Monitoring
      • NVIDIA GPU OpenTelemetry Assets
      • Okta
        • Okta
        • Okta Entity Analytics
      • Oracle
        • Oracle
        • Oracle Database OTel Content Pack
        • Oracle WebLogic
      • OpenAI
      • OpenAI ChatGPT Enterprise Integration for Elastic
      • OpenCanary
      • OpenTelemetry internal telemetry Assets
      • OpenTelemetry Profiling Integration for Elastic
      • Osquery
        • Osquery Logs
        • Osquery Manager
      • OTLP Receiver OpenTelemetry Input Package
      • Palo Alto
        • Cortex XDR
        • Networks Metrics
        • Next-Gen Firewall
        • Prisma Cloud
        • Prisma Access
      • Permission Verifier Integration
      • pfSense
      • PHP-FPM
      • PingOne
      • PingFederate
      • Pleasant Password Server
      • PostgreSQL
      • PostgreSQL OpenTelemetry Assets
      • Privileged Access Detection
      • Profilingmetrics OpenTelemetry Assets
      • Prometheus
        • Prometheus
        • Promethues Input
        • Prometheus OTel Scrape (Guided)
        • Prometheus OTel Scrape (Bring Your Own Config)
      • Proofpoint
        • Proofpoint Essentials Integration for Elastic
        • Proofpoint TAP
        • Proofpoint On Demand
        • Proofpoint Insider Threat Management (ITM)
        • Proofpoint 365 Total Protection Integration for Elastic
      • Pulse Connect Secure
      • Qualys Global AssetView (GAV)
      • Qualys VMDR
      • Qualys Web Application Scanning (WAS)
      • QNAP NAS
      • RabbitMQ Logs
      • RabbitMQ OpenTelemetry Assets
      • Rapid7
        • Rapid7 InsightVM
        • Rapid7 Threat Command
      • Redis
        • Redis
        • Redis Enterprise
        • Redis Enterprise OpenTelemetry Assets
        • Redis OpenTelemetry Assets
        • Redis OpenTelemetry Input Package
      • Rubrik RSC Metrics Integration
      • RUM OpenTelemetry Assets
      • Sailpoint Identity Security Cloud
      • Salesforce
      • Security AI Prompts
      • SentinelOne
        • SentinelOne
        • SentinelOne Cloud Funnel
      • ServiceNow
      • Slack Logs
      • Snort
      • Snyk
      • SonicWall Firewall
      • Sophos
        • Sophos
        • Sophos Central
      • Spring Boot
      • Splunk
      • SpyCloud Enterprise Protection
      • SQL Input
      • SQL Server OpenTelemetry Input Package
      • Squid Logs
      • SRX
      • STAN
      • Statsd Input
      • StatsD OpenTelemetry Input Package
      • StormShield SNS
      • Sublime Security
      • Supabase OpenTelemetry Assets
      • Supabase OpenTelemetry Integration
      • Suricata
      • Swimlane Turbine
      • Symantec
        • Endpoint Protection
      • Symantec Endpoint Security
      • Sysmon for Linux
      • Sysdig
      • Syslog Router Integration
      • System
      • System Audit
      • System OpenTelemetry Assets
      • Tanium
      • TCP Logs (custom)
      • Teleport
      • Temporal (OpenTelemetry)
      • Temporal Cloud OpenTelemetry Assets
      • Tenable
        • Tenable.io
        • Tenable.sc
        • Tenable OT Security
      • Tencent Cloud 集成
      • Threat intelligence
        • abuse.ch
        • AlienVault OTX
        • Anomali
        • ANY.RUN Threat Intelligence Feeds
        • Collective Intelligence Framework
        • Custom Threat Intelligence
        • Cybersixgill
        • EclecticIQ
        • Flashpoint Integration for Elastic
        • Maltiverse
        • Mandiant Advantage
        • MISP
        • OpenCTI
        • Recorded Future
        • SOCRadar Threat Feeds
        • SOCRadar Threat Intelligence (TAXII)
        • Strider Shield Integration
        • ThreatQuotient
        • Ticura Threat Intelligence Integration
      • ThreatConnect
      • Threat Map
      • Thycotic Secret Server
      • Tines
      • Traefik
      • Traefik OpenTelemetry Assets
      • Trellix
        • Trellix EDR Cloud
        • Trellix ePO Cloud
      • Trend Micro
        • Trend Micro
        • Vision One
      • TYCHON Agentless
      • UDP Logs (custom)
      • Universal Profiling
        • Universal Profiling Agent
        • Universal Profiling Collector
        • Universal Profiling Symbolizer
      • Varonis integration
      • Vectra Detect
      • Vectra RUX
      • Vercel OpenTelemetry Assets
      • Vercel OpenTelemetry Integration
      • VMware
        • Carbon Black Cloud
        • Carbon Black EDR
        • vSphere
        • vSphere OpenTelemetry Assets
      • WatchGuard Firebox
      • WebSphere Application Server
      • Windows
        • Windows
        • Custom Windows ETW logs
        • Custom WMI Input Package
        • Windows Event Logs (custom)
      • WithSecure Elements Integration
      • Wiz
      • Workday
      • XM Cyber Integration
      • Zeek
      • ZeroFox
      • Zero Networks
      • Zipkin OpenTelemetry Input Package
      • ZooKeeper Metrics
      • Zoom
      • Zscaler
        • Zscaler Internet Access
        • Zscaler Private Access
    • Elastic Serverless Forwarder for AWS
      • Deploy serverless forwarder
      • Configuration options
    • Elasticsearch for Apache Hadoop
      • Setup and requirements
        • Key features
        • Requirements
        • Installation
      • Reference
        • Architecture
        • Configuration
        • Runtime options
        • Security
        • Logging
        • Map/Reduce integration
        • Apache Hive integration
        • Apache Spark support
        • Mapping and types
        • Error handlers
        • Kerberos
        • Hadoop metrics
        • Performance considerations
        • Cloud or restricted environments
      • Resources
      • License
    • Fleet and Elastic Agent
      • Restrictions for Elastic Cloud Serverless
      • Beats and Elastic Agent capabilities
      • Elastic Agent as an OTel Collector
      • Migrate from Beats to Elastic Agent
        • Migrate from Auditbeat to Elastic Agent
      • Deployment models
        • What is Fleet Server?
        • Deploy on Elastic Cloud
        • Deploy on-premises and self-managed
        • Deploy Fleet Server on-premises and Elasticsearch on Elastic Cloud
        • Deploy on Kubernetes
        • Fleet Server scalability
        • Fleet Server secrets
          • Secret files guide
        • Monitor a self-managed Fleet Server
      • Install Elastic Agents
        • Elastic Agent release process
        • Install Fleet-managed Elastic Agents
        • Install standalone Elastic Agents
          • Upgrade standalone Elastic Agents
        • Install Elastic Agents in a containerized environment
          • Run Elastic Agent in a container
          • Run Elastic Agent on Kubernetes managed by Fleet
          • Install Elastic Agent on Kubernetes using Helm
            • Example: Install standalone Elastic Agent on Kubernetes using Helm
            • Example: Install Fleet-managed Elastic Agent on Kubernetes using Helm
          • Advanced Elastic Agent configuration managed by Fleet
          • Configuring Kubernetes metadata enrichment on Elastic Agent
          • Run Elastic Agent on GKE managed by Fleet
          • Configure Elastic Agent Add-On on Amazon EKS
          • Run Elastic Agent on Azure AKS managed by Fleet
          • Run Elastic Agent Standalone on Kubernetes
          • Scaling Elastic Agent on Kubernetes
          • Using a custom ingest pipeline with the Kubernetes Integration
          • Environment variables
        • Run Elastic Agent as an OTel Collector
        • Transform an installed Elastic Agent to run as an OTel Collector
        • Run Elastic Agent without administrative privileges
        • Install Elastic Agent from an MSI package
        • Installation layout
        • Air-gapped environments
        • Using a proxy server with Elastic Agent and Fleet
          • When to configure proxy settings
          • Proxy server connectivity using default host variables
          • Fleet-managed Elastic Agent connectivity using a proxy server
          • Standalone Elastic Agent connectivity using a proxy server
          • Set the proxy URL of the Elastic Package Registry
        • Uninstall Elastic Agents from edge hosts
        • Start and stop Elastic Agents on edge hosts
        • Elastic Agent configuration encryption
      • Secure connections
        • Configure SSL/TLS for self-managed Fleet Servers
        • Certificate fingerprints
        • Rotate SSL/TLS CA certificates
        • Elastic Agent deployment models with mutual TLS
        • One-way and mutual TLS certifications flow
        • Configure SSL/TLS for the Logstash output
      • Manage Elastic Agents in Fleet
        • Fleet settings
          • Elasticsearch output settings
          • Logstash output settings
          • Kafka output settings
          • Remote Elasticsearch output
            • Automatic integrations synchronization
          • Considerations when changing outputs
        • Elastic Agents
          • Unenroll Elastic Agents
          • Set inactivity timeout
          • Upgrade Elastic Agents
          • Migrate Elastic Agents
          • Monitor Elastic Agents
          • Elastic Agent built-in alerts
          • Elastic Agent health status
          • Add tags to filter the Agents list
          • Enrollment handling for containerized agents
          • Remove agent elevated privileges
        • Policies
          • Create an agent policy without using the UI
          • Enable custom settings in an agent policy
          • Set environment variables in an Elastic Agent policy
          • Version-specific agent policies
        • Roles and privileges
        • Fleet enrollment tokens
        • Kibana Fleet APIs
      • Monitor OTel Collectors
        • Add an OTel Collector
        • View OTel Collectors
        • Remove an OTel Collector
        • Add internal telemetry
      • Configure standalone Elastic Agents
        • Create a standalone Elastic Agent policy
        • Structure of a config file
        • Inputs
          • Simplified log ingestion
          • Elastic Agent inputs
          • Variables and conditions in input configurations
        • Outputs
          • Elasticsearch
          • Kafka
          • Logstash
        • SSL/TLS
        • Logging
        • Feature flags
        • Agent download
        • Config file examples
          • Apache HTTP Server
          • Nginx HTTP Server
        • Grant standalone Elastic Agents access to Elasticsearch
        • Example: Use standalone Elastic Agent with Elastic Cloud Serverless to monitor nginx
        • Example: Use standalone Elastic Agent with Elastic Cloud Hosted to monitor nginx
        • Debug standalone Elastic Agents
        • Kubernetes autodiscovery with Elastic Agent
          • Conditions based autodiscover
          • Hints annotations based autodiscover
        • Monitoring
        • Reference YAML
      • Manage integrations
        • Package signatures
        • Add an integration to an Elastic Agent policy
        • View integration policies
        • Edit or delete an integration policy
        • Install and uninstall integration assets
        • View integration assets
        • Set integration-level outputs
        • Upgrade an integration
        • Roll back an integration
        • Managed content
        • Best practices for integration assets
        • OpenTelemetry integration packages
        • Deprecated integrations
        • Data streams
          • Customize data retention policies
            • All data streams, all namespaces
            • Specific data streams, all namespaces
            • One data stream, one namespace
            • Custom integrations
          • Transform data with custom ingest pipelines
          • Customize data streams with namespace index templates
          • Apply an ILM policy to a namespace
          • Resolve overlapping index templates
          • Advanced data stream features
        • Alerting rule templates
      • Command reference
      • Agent providers
        • Local provider
        • Agent provider
        • Host provider
        • Env provider
        • Filesource provider
        • Kubernetes Secrets provider
        • Kubernetes LeaderElection Provider
        • Local dynamic provider
        • Docker provider
        • Kubernetes provider
      • Agent processors
        • Processor syntax
        • add_cloud_metadata
        • add_cloudfoundry_metadata
        • add_docker_metadata
        • add_fields
        • add_host_metadata
        • add_id
        • add_kubernetes_metadata
        • add_labels
        • add_locale
        • add_network_direction
        • add_nomad_metadata
        • add_observer_metadata
        • add_process_metadata
        • add_tags
        • community_id
        • convert
        • copy_fields
        • decode_base64_field
        • decode_cef
        • decode_csv_fields
        • decode_duration
        • decode_json_fields
        • decode_xml
        • decode_xml_wineventlog
        • decompress_gzip_field
        • detect_mime_type
        • dissect
        • dns
        • drop_event
        • drop_fields
        • extract_array
        • fingerprint
        • include_fields
        • move_fields
        • parse_aws_vpc_flow_log
        • rate_limit
        • registered_domain
        • rename
        • replace
        • script
        • syslog
        • timestamp
        • translate_sid
        • truncate_fields
        • urldecode
    • Logstash
      • Getting started with Logstash
        • Installing Logstash
        • Stashing Your First Event
        • Parsing Logs with Logstash
        • Stitching Together Multiple Input and Output Plugins
      • How Logstash Works
        • Execution Model
        • ECS in Logstash
        • Processing Details
      • Setting up and running Logstash
        • Logstash Directory Layout
        • Logstash Configuration Files
        • logstash.yml
        • Secrets keystore for secure settings
        • Running Logstash from the Command Line
        • Running Logstash as a Service on Debian or RPM
        • Running Logstash on Docker
        • Configuring Logstash for Docker
        • Running Logstash on Kubernetes
        • Running Logstash on Windows
        • Logging
        • Shutting Down Logstash
      • Upgrading Logstash
        • Upgrading using package managers
        • Upgrading using a direct download
        • Upgrading between minor versions
      • Creating a Logstash Pipeline
        • Structure of a pipeline
        • Accessing event data and fields
        • Using environment variables
        • Sending data to Elastic Cloud Hosted
        • Sending data to Elasticsearch Serverless
        • Logstash configuration examples
      • Secure your connection
      • Advanced Logstash configurations
        • Multiple Pipelines
        • Pipeline-to-pipeline communication
        • Reloading the Config File
        • Managing Multiline Events
        • Glob Pattern Support
      • Logstash-to-Logstash communications
        • Logstash-to-Logstash: Lumberjack output to Beats input
        • Logstash-to-Logstash: HTTP output to HTTP input
        • Logstash-to-Logstash: Output to Input
      • Managing Logstash
        • Centralized Pipeline Management
        • Configure Centralized Pipeline Management
      • Using Logstash with Elastic integrations
        • Tutorial to extend Elastic Integrations
      • Working with Filebeat modules
        • Use ingest pipelines for parsing
        • Example: Set up Filebeat modules to work with Kafka and Logstash
      • Working with Winlogbeat modules
      • Queues and data resiliency
        • Memory queue
        • Persistent queues (PQ)
        • Dead letter queues (DLQ)
      • Transforming data
        • Performing Core Operations
        • Deserializing Data
        • Extracting Fields and Wrangling Data
        • Enriching Data with Lookups
      • Deploying and scaling Logstash
      • Managing GeoIP databases
        • GeoIP Database Management
        • Configure GeoIP Database Management
      • Performance tuning
        • Performance troubleshooting
        • Tuning and profiling logstash pipeline performance
      • Monitoring Logstash with Elastic Agent
        • Collect monitoring data for dashboards
        • Collect monitoring data for dashboards (Serverless )
        • Collect monitoring data for stack monitoring
      • Monitoring Logstash (Legacy)
        • Metricbeat collection
        • Legacy collection (deprecated)
        • Monitoring UI
        • Pipeline Viewer UI
        • Troubleshooting
      • Monitoring Logstash with APIs
      • Monitoring Logstash with OpenTelemetry
      • Working with plugins
        • Cross-plugin concepts and features
        • Generating plugins
        • Offline Plugin Management
        • Private Gem Repositories
        • Event API
      • Tips and best practices
        • JVM settings
        • File descriptors
    • Logstash Plugins
      • Integration plugins
        • aws
        • elastic_enterprise_search
        • jdbc
        • kafka
        • logstash
        • rabbitmq
        • snmp
      • Input plugins
        • azure_event_hubs
        • beats
        • cloudwatch
        • couchdb_changes
        • dead_letter_queue
        • elastic_agent
        • elastic_serverless_forwarder
        • elasticsearch
        • exec
        • file
        • ganglia
        • gelf
        • generator
        • github
        • google_cloud_storage
        • google_pubsub
        • graphite
        • heartbeat
        • http
        • http_poller
        • imap
        • irc
        • java_generator
        • java_stdin
        • jdbc
        • jms
        • jmx
        • kafka
        • kinesis
        • logstash
        • log4j
        • lumberjack
        • meetup
        • pipe
        • puppet_facter
        • rabbitmq
        • redis
        • relp
        • rss
        • s3
        • s3-sns-sqs
        • salesforce
        • snmp
        • snmptrap
        • sqlite
        • sqs
        • stdin
        • stomp
        • syslog
        • tcp
        • twitter
        • udp
        • unix
        • varnishlog
        • websocket
        • wmi
        • xmpp
      • Output plugins
        • boundary
        • circonus
        • cloudwatch
        • csv
        • datadog
        • datadog_metrics
        • dynatrace
        • elastic_app_search
        • elastic_workplace_search
        • elasticsearch
        • email
        • exec
        • file
        • ganglia
        • gelf
        • google_bigquery
        • google_cloud_storage
        • google_pubsub
        • graphite
        • graphtastic
        • http
        • influxdb
        • irc
        • java_stdout
        • juggernaut
        • kafka
        • librato
        • logstash
        • loggly
        • lumberjack
        • metriccatcher
        • mongodb
        • nagios
        • nagios_nsca
        • opentsdb
        • pagerduty
        • pipe
        • rabbitmq
        • redis
        • redmine
        • riak
        • riemann
        • s3
        • sink
        • sns
        • solr_http
        • sqs
        • statsd
        • stdout
        • stomp
        • syslog
        • tcp
        • timber
        • udp
        • webhdfs
        • websocket
        • xmpp
        • zabbix
      • Filter plugins
        • age
        • aggregate
        • alter
        • bytes
        • cidr
        • cipher
        • clone
        • csv
        • date
        • de_dot
        • dissect
        • dns
        • drop
        • elapsed
        • elastic_integration
        • elasticsearch
        • environment
        • extractnumbers
        • fingerprint
        • geoip
        • grok
        • http
        • i18n
        • java_uuid
        • jdbc_static
        • jdbc_streaming
        • json
        • json_encode
        • kv
        • memcached
        • metricize
        • metrics
        • mutate
        • prune
        • range
        • ruby
        • sleep
        • split
        • syslog_pri
        • threats_classifier
        • throttle
        • tld
        • translate
        • truncate
        • urldecode
        • useragent
        • uuid
        • wurfl_device_detection
        • xml
      • Codec plugins
        • avro
        • cef
        • cloudfront
        • cloudtrail
        • collectd
        • csv
        • dots
        • edn
        • edn_lines
        • es_bulk
        • fluent
        • graphite
        • gzip_lines
        • jdots
        • java_line
        • java_plain
        • json
        • json_lines
        • line
        • msgpack
        • multiline
        • netflow
        • nmap
        • plain
        • protobuf
        • rubydebug
      • Plugin value types
    • Logstash Versioned Plugin Reference
      • Integration plugins
        • aws
        • elastic_enterprise_search
        • jdbc
        • kafka
        • logstash
        • rabbitmq
        • snmp
      • Input plugins
        • azure_event_hubs
        • beats
        • cloudwatch
        • couchdb_changes
        • dead_letter_queue
        • drupal_dblog
        • elastic_serverless_forwarder
        • elasticsearch
        • eventlog
        • exec
        • file
        • ganglia
        • gelf
        • gemfire
        • generator
        • github
        • google_cloud_storage
        • google_pubsub
        • graphite
        • heartbeat
        • heroku
        • http
        • http_poller
        • imap
        • irc
        • jdbc
        • jms
        • jmx
        • journald
        • kafka
        • kinesis
        • log4j
        • logstash
        • lumberjack
        • meetup
        • neo4j
        • pipe
        • puppet_facter
        • rabbitmq
        • rackspace
        • redis
        • relp
        • rss
        • s3
        • salesforce
        • snmp
        • snmptrap
        • sqlite
        • sqs
        • stdin
        • stomp
        • syslog
        • tcp
        • twitter
        • udp
        • unix
        • varnishlog
        • websocket
        • wmi
        • xmpp
        • zenoss
        • zeromq
      • Output plugins
        • appsearch
        • boundary
        • circonus
        • cloudwatch
        • csv
        • datadog
        • datadog_metrics
        • elastic_app_search
        • elastic_workplace_search
        • elasticsearch
        • elasticsearch_java
        • email
        • exec
        • file
        • ganglia
        • gelf
        • gemfire
        • google_bigquery
        • google_cloud_storage
        • google_pubsub
        • graphite
        • graphtastic
        • hipchat
        • http
        • influxdb
        • irc
        • jira
        • jms
        • juggernaut
        • kafka
        • librato
        • loggly
        • logstash
        • lumberjack
        • metriccatcher
        • monasca_log_api
        • mongodb
        • nagios
        • nagios_nsca
        • neo4j
        • null
        • opentsdb
        • pagerduty
        • pipe
        • rabbitmq
        • rackspace
        • redis
        • redmine
        • riak
        • riemann
        • s3
        • slack
        • sns
        • solr_http
        • sqs
        • statsd
        • stdout
        • stomp
        • syslog
        • tcp
        • timber
        • udp
        • webhdfs
        • websocket
        • xmpp
        • zabbix
        • zeromq
      • Filter plugins
        • age
        • aggregate
        • alter
        • anonymize
        • bytes
        • checksum
        • cidr
        • cipher
        • clone
        • collate
        • csv
        • date
        • de_dot
        • dissect
        • dns
        • drop
        • elapsed
        • elastic_integration
        • elasticsearch
        • emoji
        • environment
        • extractnumbers
        • fingerprint
        • geoip
        • grok
        • hashid
        • http
        • i18n
        • jdbc_static
        • jdbc_streaming
        • json
        • json_encode
        • kv
        • math
        • memcached
        • metaevent
        • metricize
        • metrics
        • multiline
        • mutate
        • oui
        • prune
        • punct
        • range
        • ruby
        • sleep
        • split
        • syslog_pri
        • throttle
        • tld
        • translate
        • truncate
        • unique
        • urldecode
        • useragent
        • uuid
        • xml
        • yaml
        • zeromq
      • Codec plugins
        • avro
        • cef
        • cloudfront
        • cloudtrail
        • collectd
        • compress_spooler
        • csv
        • dots
        • edn
        • edn_lines
        • es_bulk
        • fluent
        • graphite
        • gzip_lines
        • json
        • json_lines
        • line
        • msgpack
        • multiline
        • netflow
        • nmap
        • oldlogstashjson
        • plain
        • protobuf
        • rubydebug
        • s3plain
  • Elastic Common Schema (ECS)
    • Using ECS
      • Getting started
      • Guidelines and best practices
        • Conventions
        • Implementation patterns
        • Mapping network events
      • Design principles
      • Custom fields
    • ECS field reference
      • Base fields
      • Agent fields
      • Autonomous System fields
      • Client fields
      • Cloud fields
        • Cloud fields usage and examples
      • Code Signature fields
      • Container fields
      • Data Stream fields
      • Destination fields
      • Device fields
      • DLL fields
      • DNS fields
      • ECS fields
      • ELF Header fields
      • Email fields
      • Entity fields
        • entity.type
      • Entity Reference fields
      • Error fields
      • Event fields
      • FaaS fields
      • File fields
      • Gen AI fields
      • Geo fields
      • Group fields
      • Hash fields
      • Host fields
      • HTTP fields
      • Interface fields
      • Log fields
      • Mach-O Header fields
      • Network fields
      • Observer fields
      • Orchestrator fields
      • Organization fields
      • Operating System fields
      • Package fields
      • PE Header fields
      • Process fields
      • Registry fields
      • Related fields
      • Risk information fields
      • Rule fields
      • Server fields
      • Service fields
        • Service fields usage and examples
      • Source fields
      • Threat fields
        • Threat fields usage and examples
      • TLS fields
      • Tracing fields
      • URL fields
      • User fields
        • User fields usage and examples
      • User agent fields
      • VLAN fields
      • Volume fields
      • Vulnerability fields
        • vulnerability.status
      • x509 Certificate fields
    • ECS categorization fields
      • event.kind
      • event.category
      • event.type
      • event.outcome
      • Using the categorization fields
    • Migrating to ECS
      • Products and solutions that support ECS
      • Map custom data to ECS
    • ECS & OpenTelemetry
      • OTel Alignment Overview
      • Field & Attributes Alignment
    • Additional information
      • Questions and answers
      • Contributing to ECS
      • Generated artifacts
    • ECS logging libraries
      • ECS Logging .NET
        • Get started
        • .NET model of ECS
          • Usage
          • A note on the Metadata property
          • Extending EcsDocument
        • Formatters
          • Serilog formatter
          • NLog layout
          • log4net
        • Data shippers
          • Elasticsearch security
          • ECS ingest channels
          • Elastic.Serilog.Sinks
          • Elastic.Extensions.Logging
          • BenchmarkDotnet exporter
        • Enrichers
          • APM serilog enricher
          • APM NLog layout
      • ECS Logging Go (Logrus)
        • Get started
      • ECS Logging Go (Zap)
        • Get started
      • ECS Logging Go (Zerolog)
        • Get started
      • ECS Logging Java
        • Get started
        • Structured logging with log4j2
      • ECS Logging Node.js
        • ECS Logging with Pino
        • ECS Logging with Winston
        • ECS Logging with Morgan
      • ECS Logging PHP
        • Get started
      • ECS Logging Python
        • Installation
      • ECS Logging Ruby
        • Get started
  • Elastic CLI
    • Get started with the Elastic CLI
    • Install the Elastic CLI
    • Configure the Elastic CLI
      • Configuration file reference
    • Connect to Elastic Cloud with the Elastic CLI
    • Command reference
      • version cmd
      • stack ns
        • es ns
          • bulk cmd
          • create cmd
          • delete cmd
          • delete-by-query cmd
          • exists cmd
          • exists-source cmd
          • get cmd
          • get-source cmd
          • index cmd
          • mget cmd
          • reindex cmd
          • update cmd
          • update-by-query cmd
          • clear-scroll cmd
          • close-point-in-time cmd
          • msearch cmd
          • msearch-template cmd
          • open-point-in-time cmd
          • render-search-template cmd
          • scroll cmd
          • search cmd
          • search-mvt cmd
          • search-shards cmd
          • search-template cmd
          • count cmd
          • explain cmd
          • field-caps cmd
          • mtermvectors cmd
          • rank-eval cmd
          • terms-enum cmd
          • termvectors cmd
          • delete-script cmd
          • get-script cmd
          • get-script-context cmd
          • get-script-languages cmd
          • put-script cmd
          • scripts-painless-execute cmd
          • health-report cmd
          • info cmd
          • ping cmd
          • delete-by-query-rethrottle cmd
          • reindex-rethrottle cmd
          • update-by-query-rethrottle cmd
          • cancel-reindex cmd
          • get-reindex cmd
          • list-reindex cmd
          • helpers cmd
          • async-search ns
            • delete cmd
            • get cmd
            • status cmd
            • submit cmd
          • cat ns
            • aliases cmd
            • allocation cmd
            • circuit-breaker cmd
            • component-templates cmd
            • count cmd
            • fielddata cmd
            • health cmd
            • help cmd
            • indices cmd
            • master cmd
            • ml-data-frame-analytics cmd
            • ml-datafeeds cmd
            • ml-jobs cmd
            • ml-trained-models cmd
            • nodeattrs cmd
            • nodes cmd
            • pending-tasks cmd
            • plugins cmd
            • recovery cmd
            • repositories cmd
            • segments cmd
            • shards cmd
            • snapshots cmd
            • tasks cmd
            • templates cmd
            • thread-pool cmd
            • transforms cmd
          • ccr ns
            • delete-auto-follow-pattern cmd
            • follow cmd
            • follow-info cmd
            • follow-stats cmd
            • forget-follower cmd
            • get-auto-follow-pattern cmd
            • pause-auto-follow-pattern cmd
            • pause-follow cmd
            • put-auto-follow-pattern cmd
            • resume-auto-follow-pattern cmd
            • resume-follow cmd
            • stats cmd
            • unfollow cmd
          • cluster ns
            • allocation-explain cmd
            • delete-component-template cmd
            • delete-voting-config-exclusions cmd
            • exists-component-template cmd
            • get-component-template cmd
            • get-settings cmd
            • health cmd
            • info cmd
            • pending-tasks cmd
            • post-voting-config-exclusions cmd
            • put-component-template cmd
            • put-settings cmd
            • remote-info cmd
            • reroute cmd
            • state cmd
            • stats cmd
          • connector ns
            • check-in cmd
            • delete cmd
            • get cmd
            • list cmd
            • post cmd
            • put cmd
            • sync-job-cancel cmd
            • sync-job-check-in cmd
            • sync-job-claim cmd
            • sync-job-delete cmd
            • sync-job-error cmd
            • sync-job-get cmd
            • sync-job-list cmd
            • sync-job-post cmd
            • sync-job-update-stats cmd
            • update-active-filtering cmd
            • update-api-key-id cmd
            • update-configuration cmd
            • update-error cmd
            • update-features cmd
            • update-filtering cmd
            • update-filtering-validation cmd
            • update-index-name cmd
            • update-name cmd
            • update-native cmd
            • update-pipeline cmd
            • update-scheduling cmd
            • update-service-type cmd
            • update-status cmd
          • dangling-indices ns
            • delete-dangling-index cmd
            • import-dangling-index cmd
            • list-dangling-indices cmd
          • encryption ns
            • reset cmd
          • enrich ns
            • delete-policy cmd
            • execute-policy cmd
            • get-policy cmd
            • put-policy cmd
            • stats cmd
          • eql ns
            • delete cmd
            • get cmd
            • get-status cmd
            • search cmd
          • esql ns
            • async-query cmd
            • async-query-delete cmd
            • async-query-get cmd
            • async-query-stop cmd
            • delete-data-source cmd
            • delete-dataset cmd
            • delete-view cmd
            • get-data-source cmd
            • get-dataset cmd
            • get-query cmd
            • get-view cmd
            • list-queries cmd
            • put-data-source cmd
            • put-dataset cmd
            • put-view cmd
            • query cmd
          • features ns
            • get-features cmd
            • reset-features cmd
          • fleet ns
            • global-checkpoints cmd
            • msearch cmd
            • search cmd
          • graph ns
            • explore cmd
          • ilm ns
            • delete-lifecycle cmd
            • explain-lifecycle cmd
            • get-lifecycle cmd
            • get-status cmd
            • migrate-to-data-tiers cmd
            • move-to-step cmd
            • put-lifecycle cmd
            • remove-policy cmd
            • retry cmd
            • start cmd
            • stop cmd
          • indices ns
            • add-block cmd
            • analyze cmd
            • cancel-migrate-reindex cmd
            • clear-cache cmd
            • clone cmd
            • close cmd
            • create cmd
            • create-data-stream cmd
            • create-from cmd
            • data-streams-stats cmd
            • delete cmd
            • delete-alias cmd
            • delete-data-lifecycle cmd
            • delete-data-stream cmd
            • delete-data-stream-options cmd
            • delete-index-template cmd
            • delete-template cmd
            • disk-usage cmd
            • downsample cmd
            • exists cmd
            • exists-alias cmd
            • exists-index-template cmd
            • exists-template cmd
            • explain-data-lifecycle cmd
            • field-usage-stats cmd
            • flush cmd
            • forcemerge cmd
            • get cmd
            • get-alias cmd
            • get-data-lifecycle cmd
            • get-data-lifecycle-stats cmd
            • get-data-stream cmd
            • get-data-stream-mappings cmd
            • get-data-stream-options cmd
            • get-data-stream-settings cmd
            • get-field-mapping cmd
            • get-index-template cmd
            • get-mapping cmd
            • get-migrate-reindex-status cmd
            • get-settings cmd
            • get-template cmd
            • migrate-reindex cmd
            • migrate-to-data-stream cmd
            • modify-data-stream cmd
            • open cmd
            • promote-data-stream cmd
            • put-alias cmd
            • put-data-lifecycle cmd
            • put-data-stream-mappings cmd
            • put-data-stream-options cmd
            • put-data-stream-settings cmd
            • put-index-template cmd
            • put-mapping cmd
            • put-settings cmd
            • put-template cmd
            • recovery cmd
            • refresh cmd
            • reload-search-analyzers cmd
            • remove-block cmd
            • resolve-cluster cmd
            • resolve-index cmd
            • rollover cmd
            • segments cmd
            • shard-stores cmd
            • shrink cmd
            • simulate-index-template cmd
            • simulate-template cmd
            • split cmd
            • stats cmd
            • update-aliases cmd
            • validate-query cmd
          • inference ns
            • chat-completion-unified cmd
            • completion cmd
            • delete cmd
            • delete-region-policy cmd
            • embedding cmd
            • get cmd
            • get-region-policy cmd
            • inference cmd
            • put cmd
            • put-ai21 cmd
            • put-alibabacloud cmd
            • put-amazonbedrock cmd
            • put-amazonsagemaker cmd
            • put-anthropic cmd
            • put-azureaistudio cmd
            • put-azureopenai cmd
            • put-cohere cmd
            • put-contextualai cmd
            • put-custom cmd
            • put-deepseek cmd
            • put-elasticsearch cmd
            • put-elser cmd
            • put-fireworksai cmd
            • put-googleaistudio cmd
            • put-googlevertexai cmd
            • put-groq cmd
            • put-hugging-face cmd
            • put-jinaai cmd
            • put-llama cmd
            • put-mistral cmd
            • put-nvidia cmd
            • put-openai cmd
            • put-openshift-ai cmd
            • put-region-policy cmd
            • put-voyageai cmd
            • put-watsonx cmd
            • rerank cmd
            • sparse-embedding cmd
            • stream-completion cmd
            • text-embedding cmd
            • update cmd
          • ingest ns
            • delete-geoip-database cmd
            • delete-ip-location-database cmd
            • delete-pipeline cmd
            • geo-ip-stats cmd
            • get-geoip-database cmd
            • get-ip-location-database cmd
            • get-pipeline cmd
            • processor-grok cmd
            • put-geoip-database cmd
            • put-ip-location-database cmd
            • put-pipeline cmd
            • simulate cmd
          • license ns
            • delete cmd
            • get cmd
            • get-basic-status cmd
            • get-trial-status cmd
            • post cmd
            • post-start-basic cmd
            • post-start-trial cmd
          • logstash ns
            • delete-pipeline cmd
            • get-pipeline cmd
            • put-pipeline cmd
          • migration ns
            • deprecations cmd
            • get-feature-upgrade-status cmd
            • post-feature-upgrade cmd
          • ml ns
            • clear-trained-model-deployment-cache cmd
            • close-job cmd
            • delete-calendar cmd
            • delete-calendar-event cmd
            • delete-calendar-job cmd
            • delete-data-frame-analytics cmd
            • delete-datafeed cmd
            • delete-expired-data cmd
            • delete-filter cmd
            • delete-forecast cmd
            • delete-job cmd
            • delete-model-snapshot cmd
            • delete-trained-model cmd
            • delete-trained-model-alias cmd
            • estimate-model-memory cmd
            • evaluate-data-frame cmd
            • explain-data-frame-analytics cmd
            • flush-job cmd
            • forecast cmd
            • get-buckets cmd
            • get-calendar-events cmd
            • get-calendars cmd
            • get-categories cmd
            • get-data-frame-analytics cmd
            • get-data-frame-analytics-stats cmd
            • get-datafeed-stats cmd
            • get-datafeeds cmd
            • get-filters cmd
            • get-influencers cmd
            • get-job-stats cmd
            • get-jobs cmd
            • get-memory-stats cmd
            • get-model-snapshot-upgrade-stats cmd
            • get-model-snapshots cmd
            • get-overall-buckets cmd
            • get-records cmd
            • get-trained-models cmd
            • get-trained-models-stats cmd
            • infer-trained-model cmd
            • info cmd
            • open-job cmd
            • post-calendar-events cmd
            • post-data cmd
            • preview-data-frame-analytics cmd
            • preview-datafeed cmd
            • put-calendar cmd
            • put-calendar-job cmd
            • put-data-frame-analytics cmd
            • put-datafeed cmd
            • put-filter cmd
            • put-job cmd
            • put-trained-model cmd
            • put-trained-model-alias cmd
            • put-trained-model-definition-part cmd
            • put-trained-model-vocabulary cmd
            • reset-job cmd
            • revert-model-snapshot cmd
            • set-upgrade-mode cmd
            • start-data-frame-analytics cmd
            • start-datafeed cmd
            • start-trained-model-deployment cmd
            • stop-data-frame-analytics cmd
            • stop-datafeed cmd
            • stop-trained-model-deployment cmd
            • update-data-frame-analytics cmd
            • update-datafeed cmd
            • update-filter cmd
            • update-job cmd
            • update-model-snapshot cmd
            • update-trained-model-deployment cmd
            • upgrade-job-snapshot cmd
          • nodes ns
            • clear-repositories-metering-archive cmd
            • get-repositories-metering-info cmd
            • hot-threads cmd
            • info cmd
            • reload-secure-settings cmd
            • stats cmd
            • usage cmd
          • project ns
            • create-many-routing cmd
            • create-routing cmd
            • delete-routing cmd
            • get-many-routing cmd
            • get-routing cmd
            • tags cmd
          • query-rules ns
            • delete-rule cmd
            • delete-ruleset cmd
            • get-rule cmd
            • get-ruleset cmd
            • list-rulesets cmd
            • put-rule cmd
            • put-ruleset cmd
            • test cmd
          • rollup ns
            • delete-job cmd
            • get-jobs cmd
            • get-rollup-caps cmd
            • get-rollup-index-caps cmd
            • put-job cmd
            • rollup-search cmd
            • start-job cmd
            • stop-job cmd
          • search-application ns
            • delete cmd
            • delete-behavioral-analytics cmd
            • get cmd
            • get-behavioral-analytics cmd
            • list cmd
            • post-behavioral-analytics-event cmd
            • put cmd
            • put-behavioral-analytics cmd
            • render-query cmd
            • search cmd
          • searchable-snapshots ns
            • cache-stats cmd
            • clear-cache cmd
            • mount cmd
            • stats cmd
          • security ns
            • activate-user-profile cmd
            • authenticate cmd
            • bulk-delete-role cmd
            • bulk-put-role cmd
            • bulk-update-api-keys cmd
            • change-password cmd
            • clear-api-key-cache cmd
            • clear-cached-privileges cmd
            • clear-cached-realms cmd
            • clear-cached-roles cmd
            • clear-cached-service-tokens cmd
            • clone-api-key cmd
            • create-api-key cmd
            • create-cross-cluster-api-key cmd
            • create-service-token cmd
            • delegate-pki cmd
            • delete-privileges cmd
            • delete-role cmd
            • delete-role-mapping cmd
            • delete-service-token cmd
            • delete-user cmd
            • disable-user cmd
            • disable-user-profile cmd
            • enable-user cmd
            • enable-user-profile cmd
            • enroll-kibana cmd
            • enroll-node cmd
            • get-api-key cmd
            • get-builtin-privileges cmd
            • get-privileges cmd
            • get-role cmd
            • get-role-mapping cmd
            • get-service-accounts cmd
            • get-service-credentials cmd
            • get-settings cmd
            • get-stats cmd
            • get-token cmd
            • get-user cmd
            • get-user-privileges cmd
            • get-user-profile cmd
            • grant-api-key cmd
            • has-privileges cmd
            • has-privileges-user-profile cmd
            • invalidate-api-key cmd
            • invalidate-token cmd
            • oidc-authenticate cmd
            • oidc-logout cmd
            • oidc-prepare-authentication cmd
            • put-privileges cmd
            • put-role cmd
            • put-role-mapping cmd
            • put-user cmd
            • query-api-keys cmd
            • query-role cmd
            • query-user cmd
            • saml-authenticate cmd
            • saml-complete-logout cmd
            • saml-invalidate cmd
            • saml-logout cmd
            • saml-prepare-authentication cmd
            • saml-service-provider-metadata cmd
            • suggest-user-profiles cmd
            • update-api-key cmd
            • update-cross-cluster-api-key cmd
            • update-settings cmd
            • update-user-profile-data cmd
          • simulate ns
            • ingest cmd
          • slm ns
            • delete-lifecycle cmd
            • execute-lifecycle cmd
            • execute-retention cmd
            • get-lifecycle cmd
            • get-stats cmd
            • get-status cmd
            • put-lifecycle cmd
            • start cmd
            • stop cmd
          • snapshot ns
            • cleanup-repository cmd
            • clone cmd
            • create cmd
            • create-repository cmd
            • delete cmd
            • delete-repository cmd
            • get cmd
            • get-repository cmd
            • repository-analyze cmd
            • repository-verify-integrity cmd
            • restore cmd
            • status cmd
            • verify-repository cmd
          • sql ns
            • clear-cursor cmd
            • delete-async cmd
            • get-async cmd
            • get-async-status cmd
            • query cmd
            • translate cmd
          • ssl ns
            • certificates cmd
          • streams ns
            • logs-disable cmd
            • logs-enable cmd
            • status cmd
          • synonyms ns
            • delete-synonym cmd
            • delete-synonym-rule cmd
            • get-synonym cmd
            • get-synonym-rule cmd
            • get-synonyms-sets cmd
            • put-synonym cmd
            • put-synonym-rule cmd
          • tasks ns
            • cancel cmd
            • get cmd
            • list cmd
          • text-structure ns
            • find-field-structure cmd
            • find-message-structure cmd
            • find-structure cmd
            • test-grok-pattern cmd
          • transform ns
            • delete-transform cmd
            • get-node-stats cmd
            • get-transform cmd
            • get-transform-stats cmd
            • preview-transform cmd
            • put-transform cmd
            • reset-transform cmd
            • schedule-now-transform cmd
            • set-upgrade-mode cmd
            • start-transform cmd
            • stop-transform cmd
            • update-transform cmd
            • upgrade-transforms cmd
          • watcher ns
            • ack-watch cmd
            • activate-watch cmd
            • deactivate-watch cmd
            • delete-watch cmd
            • execute-watch cmd
            • get-settings cmd
            • get-watch cmd
            • put-watch cmd
            • query-watches cmd
            • start cmd
            • stats cmd
            • stop cmd
            • update-settings cmd
          • xpack ns
            • info cmd
            • usage cmd
        • kb ns
          • agent-builder ns
            • post-agent-builder-a2a-agentid cmd
            • get-agent-builder-a2a-agentid-json cmd
            • get-agent-builder-agents cmd
            • post-agent-builder-agents cmd
            • post-agent-builder-agents-agent-id-consumption cmd
            • delete-agent-builder-agents-id cmd
            • get-agent-builder-agents-id cmd
            • put-agent-builder-agents-id cmd
            • get-agent-builder-agents-id-access-control cmd
            • put-agent-builder-agents-id-access-control cmd
            • get-agent-builder-conversations cmd
            • post-agent-builder-conversations cmd
            • delete-agent-builder-conversations-conversation-id cmd
            • get-agent-builder-conversations-conversation-id cmd
            • put-agent-builder-conversations-conversation-id-access-control cmd
            • get-agent-builder-conversations-conversation-id-attachments cmd
            • post-agent-builder-conversations-conversation-id-attachments cmd
            • delete-agent-builder-conversations-conversation-id-attachments-attachment-id cmd
            • patch-agent-builder-conversations-conversation-id-attachments-attachment-id cmd
            • put-agent-builder-conversations-conversation-id-attachments-attachment-id cmd
            • post-agent-builder-conversations-conversation-id-attachments-attachment-id-restore cmd
            • put-agent-builder-conversations-conversation-id-attachments-attachment-id-origin cmd
            • get-agent-builder-conversations-conversation-id-attachments-stale cmd
            • post-agent-builder-converse cmd
            • post-agent-builder-converse-async cmd
            • post-agent-builder-mcp cmd
            • get-agent-builder-plugins cmd
            • delete-agent-builder-plugins-pluginid cmd
            • get-agent-builder-plugins-pluginid cmd
            • post-agent-builder-plugins-install cmd
            • get-agent-builder-skills cmd
            • post-agent-builder-skills cmd
            • delete-agent-builder-skills-skillid cmd
            • get-agent-builder-skills-skillid cmd
            • put-agent-builder-skills-skillid cmd
            • get-agent-builder-tools cmd
            • post-agent-builder-tools cmd
            • post-agent-builder-tools-execute cmd
            • delete-agent-builder-tools-toolid cmd
            • get-agent-builder-tools-toolid cmd
            • put-agent-builder-tools-toolid cmd
          • alerting ns
            • delete-alerting-rule-id cmd
            • get-alerting-rule-id cmd
            • post-alerting-rule-id cmd
            • put-alerting-rule-id cmd
            • post-alerting-rule-id-disable cmd
            • post-alerting-rule-id-enable cmd
            • post-alerting-rule-id-mute-all cmd
            • post-alerting-rule-id-unmute-all cmd
            • post-alerting-rule-id-update-api-key cmd
            • get-alerting-rule-id-query-inspector cmd
            • post-alerting-rule-id-snooze-schedule cmd
            • post-alerting-rule-rule-id-alert-alert-id-mute cmd
            • post-alerting-rule-rule-id-alert-alert-id-snooze cmd
            • post-alerting-rule-rule-id-alert-alert-id-unmute cmd
            • post-alerting-rule-rule-id-alert-alert-id-unsnooze cmd
            • delete-alerting-rule-ruleid-snooze-schedule-scheduleid cmd
            • get-alerting-rules-find cmd
            • post-alerting-rules-backfill-find cmd
            • post-alerting-rules-backfill-schedule cmd
            • delete-alerting-rules-backfill-id cmd
            • get-alerting-rules-backfill-id cmd
          • alerting-v2 ns
            • get-alerting-v2-action-policies cmd
            • post-alerting-v2-action-policies cmd
            • post-alerting-v2-action-policies-bulk-delete cmd
            • post-alerting-v2-action-policies-bulk-disable cmd
            • post-alerting-v2-action-policies-bulk-enable cmd
            • post-alerting-v2-action-policies-bulk-snooze cmd
            • post-alerting-v2-action-policies-bulk-unsnooze cmd
            • post-alerting-v2-action-policies-bulk-update-api-key cmd
            • post-alerting-v2-action-policies-match-for-rule cmd
            • delete-alerting-v2-action-policies-id cmd
            • get-alerting-v2-action-policies-id cmd
            • patch-alerting-v2-action-policies-id cmd
            • put-alerting-v2-action-policies-id cmd
            • post-alerting-v2-action-policies-id-disable cmd
            • post-alerting-v2-action-policies-id-enable cmd
            • post-alerting-v2-action-policies-id-snooze cmd
            • post-alerting-v2-action-policies-id-unsnooze cmd
            • post-alerting-v2-action-policies-id-update-api-key cmd
            • get-alerting-v2-action-policies-tags cmd
            • post-alerting-v2-alerts-bulk-action cmd
            • post-alerting-v2-alerts-group-hash-ack cmd
            • post-alerting-v2-alerts-group-hash-activate cmd
            • post-alerting-v2-alerts-group-hash-assign cmd
            • post-alerting-v2-alerts-group-hash-deactivate cmd
            • post-alerting-v2-alerts-group-hash-snooze cmd
            • post-alerting-v2-alerts-group-hash-tag cmd
            • post-alerting-v2-alerts-group-hash-unack cmd
            • post-alerting-v2-alerts-group-hash-unsnooze cmd
            • get-alerting-v2-execution-history-action-policies cmd
            • get-alerting-v2-execution-history-rules cmd
            • get-alerting-v2-rules cmd
            • post-alerting-v2-rules cmd
            • post-alerting-v2-rules-bulk-delete cmd
            • post-alerting-v2-rules-bulk-disable cmd
            • post-alerting-v2-rules-bulk-enable cmd
            • post-alerting-v2-rules-bulk-get cmd
            • post-alerting-v2-rules-bulk-update-api-key cmd
            • post-alerting-v2-rules-delete-by-query cmd
            • post-alerting-v2-rules-disable-by-query cmd
            • post-alerting-v2-rules-enable-by-query cmd
            • post-alerting-v2-rules-update-api-key-by-query cmd
            • delete-alerting-v2-rules-id cmd
            • get-alerting-v2-rules-id cmd
            • patch-alerting-v2-rules-id cmd
            • put-alerting-v2-rules-id cmd
            • post-alerting-v2-rules-id-disable cmd
            • post-alerting-v2-rules-id-enable cmd
            • post-alerting-v2-rules-id-run cmd
            • get-alerting-v2-rules-id-history cmd
            • get-alerting-v2-rules-id-history-eventid cmd
            • get-alerting-v2-rules-tags cmd
            • get-alerting-v2-suggestions-rule-event-fields cmd
          • apm-agent-configuration ns
            • delete-agent-configuration cmd
            • get-agent-configurations cmd
            • create-update-agent-configuration cmd
            • get-agent-name-for-service cmd
            • get-environments-for-service cmd
            • search-single-configuration cmd
            • get-single-agent-configuration cmd
          • apm-agent-keys ns
            • create-agent-key cmd
          • apm-annotations ns
            • create-annotation cmd
            • get-annotation cmd
          • apm-server-schema ns
            • save-apm-server-schema cmd
          • cases ns
            • delete-case cmd
            • update-case cmd
            • create-case cmd
            • find-cases cmd
            • get-case cmd
            • get-case-alerts cmd
            • delete-case-comments cmd
            • update-case-comment cmd
            • add-case-comment cmd
            • find-case-comments cmd
            • delete-case-comment cmd
            • get-case-comment cmd
            • push-case cmd
            • get-case-applicable-fields cmd
            • add-case-file cmd
            • find-case-activity cmd
            • get-cases-by-alert cmd
            • get-case-configuration cmd
            • set-case-configuration cmd
            • update-case-configuration cmd
            • find-case-connectors cmd
            • get-applicable-fields cmd
            • get-case-reporters cmd
            • get-case-tags cmd
            • get-case-templates cmd
            • create-case-template cmd
            • delete-case-template cmd
            • get-case-template cmd
            • update-case-template cmd
          • connectors ns
            • get-actions-connector-types cmd
            • get-actions-connector-oauth-callback cmd
            • get-actions-connector-connectorid-oauth-start cmd
            • delete-actions-connector-id cmd
            • get-actions-connector-id cmd
            • post-actions-connector-id cmd
            • put-actions-connector-id cmd
            • post-actions-connector-id-execute cmd
            • get-actions-connectors cmd
          • dashboards ns
            • search-dashboards cmd
            • create-dashboard cmd
            • get-dashboard cmd
            • upsert-dashboard cmd
            • delete-dashboard cmd
          • data-streams ns
            • get-fleet-data-streams cmd
            • get-fleet-data-streams-data cmd
            • get-fleet-epm-data-streams cmd
          • data-views ns
            • get-all-data-views-default cmd
            • create-data-view-default cmd
            • delete-data-view-default cmd
            • get-data-view-default cmd
            • update-data-view-default cmd
            • update-fields-metadata-default cmd
            • create-runtime-field-default cmd
            • create-update-runtime-field-default cmd
            • delete-runtime-field-default cmd
            • get-runtime-field-default cmd
            • update-runtime-field-default cmd
            • get-default-data-view-default cmd
            • set-default-datail-view-default cmd
            • swap-data-views-default cmd
            • preview-swap-data-views-default cmd
          • elastic-agent-actions ns
            • post-fleet-agents-agentid-actions cmd
            • post-fleet-agents-agentid-reassign cmd
            • post-fleet-agents-agentid-remove-collector cmd
            • post-fleet-agents-agentid-request-diagnostics cmd
            • post-fleet-agents-agentid-rollback cmd
            • post-fleet-agents-agentid-unenroll cmd
            • post-fleet-agents-agentid-upgrade cmd
            • get-fleet-agents-action-status cmd
            • post-fleet-agents-actions-actionid-cancel cmd
            • post-fleet-agents-bulk-reassign cmd
            • post-fleet-agents-bulk-remove-collectors cmd
            • post-fleet-agents-bulk-request-diagnostics cmd
            • post-fleet-agents-bulk-rollback cmd
            • post-fleet-agents-bulk-unenroll cmd
            • post-fleet-agents-bulk-update-agent-tags cmd
            • post-fleet-agents-bulk-upgrade cmd
          • elastic-agent-binary-download-sources ns
            • get-fleet-agent-download-sources cmd
            • post-fleet-agent-download-sources cmd
            • delete-fleet-agent-download-sources-sourceid cmd
            • get-fleet-agent-download-sources-sourceid cmd
            • put-fleet-agent-download-sources-sourceid cmd
          • elastic-agent-policies ns
            • get-fleet-agent-policies cmd
            • post-fleet-agent-policies cmd
            • post-fleet-agent-policies-bulk-get cmd
            • get-fleet-agent-policies-agentpolicyid cmd
            • put-fleet-agent-policies-agentpolicyid cmd
            • get-fleet-agent-policies-agentpolicyid-auto-upgrade-agents-status cmd
            • post-fleet-agent-policies-agentpolicyid-copy cmd
            • get-fleet-agent-policies-agentpolicyid-download cmd
            • get-fleet-agent-policies-agentpolicyid-full cmd
            • get-fleet-agent-policies-agentpolicyid-outputs cmd
            • post-fleet-agent-policies-delete cmd
            • post-fleet-agent-policies-outputs cmd
            • get-fleet-kubernetes cmd
            • get-fleet-kubernetes-download cmd
          • elastic-agent-status ns
            • get-fleet-agent-status cmd
          • elastic-agents ns
            • get-fleet-agent-status-data cmd
            • get-fleet-agents cmd
            • post-fleet-agents cmd
            • delete-fleet-agents-agentid cmd
            • get-fleet-agents-agentid cmd
            • put-fleet-agents-agentid cmd
            • get-fleet-agents-agentid-effective-config cmd
            • post-fleet-agents-agentid-migrate cmd
            • post-fleet-agents-agentid-privilege-level-change cmd
            • get-fleet-agents-agentid-uploads cmd
            • get-fleet-agents-available-versions cmd
            • post-fleet-agents-bulk-migrate cmd
            • post-fleet-agents-bulk-privilege-level-change cmd
            • delete-fleet-agents-files-fileid cmd
            • get-fleet-agents-files-fileid-filename cmd
            • get-fleet-agents-setup cmd
            • post-fleet-agents-setup cmd
            • get-fleet-agents-tags cmd
          • elastic-package-manager-epm ns
            • post-fleet-epm-bulk-assets cmd
            • get-fleet-epm-categories cmd
            • post-fleet-epm-custom-integrations cmd
            • put-fleet-epm-custom-integrations-pkgname cmd
            • get-fleet-epm-packages cmd
            • post-fleet-epm-packages cmd
            • post-fleet-epm-packages-bulk cmd
            • post-fleet-epm-packages-bulk-namespace-customization cmd
            • post-fleet-epm-packages-bulk-rollback cmd
            • get-fleet-epm-packages-bulk-rollback-taskid cmd
            • post-fleet-epm-packages-bulk-uninstall cmd
            • get-fleet-epm-packages-bulk-uninstall-taskid cmd
            • post-fleet-epm-packages-bulk-upgrade cmd
            • get-fleet-epm-packages-bulk-upgrade-taskid cmd
            • delete-fleet-epm-packages-pkgname cmd
            • get-fleet-epm-packages-pkgname cmd
            • post-fleet-epm-packages-pkgname cmd
            • put-fleet-epm-packages-pkgname cmd
            • delete-fleet-epm-packages-pkgname-pkgversion cmd
            • get-fleet-epm-packages-pkgname-pkgversion cmd
            • post-fleet-epm-packages-pkgname-pkgversion cmd
            • put-fleet-epm-packages-pkgname-pkgversion cmd
            • get-fleet-epm-packages-pkgname-pkgversion-filepath cmd
            • delete-fleet-epm-packages-pkgname-pkgversion-datastream-assets cmd
            • get-fleet-epm-packages-pkgname-pkgversion-dependencies cmd
            • delete-fleet-epm-packages-pkgname-pkgversion-kibana-assets cmd
            • post-fleet-epm-packages-pkgname-pkgversion-kibana-assets cmd
            • post-fleet-epm-packages-pkgname-pkgversion-rule-assets cmd
            • post-fleet-epm-packages-pkgname-pkgversion-transforms-authorize cmd
            • post-fleet-epm-packages-pkgname-review-upgrade cmd
            • post-fleet-epm-packages-pkgname-rollback cmd
            • get-fleet-epm-packages-pkgname-stats cmd
            • get-fleet-epm-packages-installed cmd
            • get-fleet-epm-packages-limited cmd
            • get-fleet-epm-templates-pkgname-pkgversion-inputs cmd
            • get-fleet-epm-verification-key-id cmd
          • fleet-agentless-policies ns
            • get-fleet-agentless-policies cmd
            • post-fleet-agentless-policies cmd
            • post-fleet-agentless-policies-upgrade cmd
            • post-fleet-agentless-policies-upgrade-dryrun cmd
            • delete-fleet-agentless-policies-policyid cmd
            • get-fleet-agentless-policies-policyid cmd
            • put-fleet-agentless-policies-policyid cmd
          • fleet-cloud-connectors ns
            • get-fleet-cloud-connectors cmd
            • post-fleet-cloud-connectors cmd
            • delete-fleet-cloud-connectors-cloudconnectorid cmd
            • get-fleet-cloud-connectors-cloudconnectorid cmd
            • put-fleet-cloud-connectors-cloudconnectorid cmd
            • get-fleet-cloud-connectors-cloudconnectorid-usage cmd
          • fleet-enrollment-api-keys ns
            • get-fleet-enrollment-api-keys cmd
            • post-fleet-enrollment-api-keys cmd
            • post-fleet-enrollment-api-keys-bulk-delete cmd
            • delete-fleet-enrollment-api-keys-keyid cmd
            • get-fleet-enrollment-api-keys-keyid cmd
          • fleet-internals ns
            • get-fleet-check-permissions cmd
            • post-fleet-health-check cmd
            • get-fleet-settings cmd
            • put-fleet-settings cmd
            • post-fleet-setup cmd
            • get-fleet-space-settings cmd
            • put-fleet-space-settings cmd
          • fleet-managed-integrations ns
            • get-fleet-managed-integrations cmd
            • post-fleet-managed-integrations cmd
            • post-fleet-managed-integrations-upgrade cmd
            • post-fleet-managed-integrations-upgrade-dryrun cmd
            • delete-fleet-managed-integrations-policyid cmd
            • get-fleet-managed-integrations-policyid cmd
            • put-fleet-managed-integrations-policyid cmd
          • fleet-outputs ns
            • post-fleet-logstash-api-keys cmd
            • get-fleet-outputs cmd
            • post-fleet-outputs cmd
            • delete-fleet-outputs-outputid cmd
            • get-fleet-outputs-outputid cmd
            • put-fleet-outputs-outputid cmd
            • get-fleet-outputs-outputid-health cmd
          • fleet-package-policies ns
            • get-fleet-package-policies cmd
            • post-fleet-package-policies cmd
            • post-fleet-package-policies-bulk-get cmd
            • delete-fleet-package-policies-packagepolicyid cmd
            • get-fleet-package-policies-packagepolicyid cmd
            • put-fleet-package-policies-packagepolicyid cmd
            • post-fleet-package-policies-delete cmd
            • post-fleet-package-policies-upgrade cmd
            • post-fleet-package-policies-upgrade-dryrun cmd
          • fleet-proxies ns
            • get-fleet-proxies cmd
            • post-fleet-proxies cmd
            • delete-fleet-proxies-itemid cmd
            • get-fleet-proxies-itemid cmd
            • put-fleet-proxies-itemid cmd
          • fleet-server-hosts ns
            • get-fleet-fleet-server-hosts cmd
            • post-fleet-fleet-server-hosts cmd
            • delete-fleet-fleet-server-hosts-itemid cmd
            • get-fleet-fleet-server-hosts-itemid cmd
            • put-fleet-fleet-server-hosts-itemid cmd
          • fleet-service-tokens ns
            • post-fleet-service-tokens cmd
          • fleet-uninstall-tokens ns
            • get-fleet-uninstall-tokens cmd
            • post-fleet-uninstall-tokens-agentpolicyid-rotate cmd
            • get-fleet-uninstall-tokens-uninstalltokenid cmd
          • links ns
            • get-links cmd
            • post-links cmd
            • delete-links-id cmd
            • get-links-id cmd
            • put-links-id cmd
          • maintenance-window ns
            • post-maintenance-window cmd
            • get-maintenance-window-find cmd
            • delete-maintenance-window-id cmd
            • get-maintenance-window-id cmd
            • patch-maintenance-window-id cmd
            • post-maintenance-window-id-archive cmd
            • post-maintenance-window-id-unarchive cmd
          • markdowns ns
            • get-markdowns cmd
            • post-markdowns cmd
            • delete-markdowns-id cmd
            • get-markdowns-id cmd
            • put-markdowns-id cmd
          • message-signing-service ns
            • post-fleet-message-signing-service-rotate-key-pair cmd
          • misc ns
            • get-actions-connector-oauth-callback-script cmd
            • post-security-role-query cmd
          • ml ns
            • ml-sync cmd
            • ml-update-jobs-spaces cmd
            • ml-update-trained-models-spaces cmd
          • observabilityaiassistant ns
            • observability-ai-assistant-chat-complete cmd
          • roles ns
            • get-security-role cmd
            • delete-security-role-name cmd
            • get-security-role-name cmd
            • put-security-role-name cmd
            • post-security-roles cmd
          • saved-objects ns
            • post-saved-objects-export cmd
            • post-saved-objects-import cmd
            • post-saved-objects-resolve-import-errors cmd
          • security-ai-assistant-api ns
            • perform-anonymization-fields-bulk-action cmd
            • find-anonymization-fields cmd
            • chat-complete cmd
            • delete-all-conversations cmd
            • create-conversation cmd
            • find-conversations cmd
            • delete-conversation cmd
            • read-conversation cmd
            • update-conversation cmd
            • get-knowledge-base cmd
            • post-knowledge-base cmd
            • read-knowledge-base cmd
            • create-knowledge-base cmd
            • create-knowledge-base-entry cmd
            • perform-knowledge-base-entry-bulk-action cmd
            • find-knowledge-base-entries cmd
            • delete-knowledge-base-entry cmd
            • read-knowledge-base-entry cmd
            • update-knowledge-base-entry cmd
            • perform-prompts-bulk-action cmd
            • find-prompts cmd
          • security-attack-discovery-api ns
            • post-attack-discovery-bulk cmd
            • attack-discovery-find cmd
            • post-attack-discovery-generate cmd
            • get-attack-discovery-generations cmd
            • get-attack-discovery-generation cmd
            • post-attack-discovery-generations-dismiss cmd
            • create-attack-discovery-schedules cmd
            • bulk-delete-attack-discovery-schedules cmd
            • bulk-disable-attack-discovery-schedules cmd
            • bulk-enable-attack-discovery-schedules cmd
            • find-attack-discovery-schedules cmd
            • delete-attack-discovery-schedules cmd
            • get-attack-discovery-schedules cmd
            • update-attack-discovery-schedules cmd
            • disable-attack-discovery-schedules cmd
            • enable-attack-discovery-schedules cmd
          • security-detections-api ns
            • set-attacks-assignees cmd
            • search-attacks cmd
            • set-attacks-status cmd
            • set-attacks-tags cmd
            • read-privileges cmd
            • delete-rule cmd
            • read-rule cmd
            • patch-rule cmd
            • create-rule cmd
            • update-rule cmd
            • perform-rules-bulk-action cmd
            • export-rules cmd
            • find-rules cmd
            • import-rules cmd
            • rule-preview cmd
            • set-alert-assignees cmd
            • search-alerts cmd
            • set-alerts-status cmd
            • set-alert-tags cmd
            • read-tags cmd
          • security-endpoint-exceptions-api ns
            • create-endpoint-list cmd
            • delete-endpoint-list-item cmd
            • read-endpoint-list-item cmd
            • create-endpoint-list-item cmd
            • update-endpoint-list-item cmd
            • find-endpoint-list-items cmd
          • security-endpoint-management-api ns
            • endpoint-get-actions-list cmd
            • endpoint-get-actions-status cmd
            • endpoint-get-actions-details cmd
            • endpoint-file-info cmd
            • endpoint-file-download cmd
            • cancel-action cmd
            • endpoint-execute-action cmd
            • endpoint-get-file-action cmd
            • endpoint-isolate-action cmd
            • endpoint-kill-process-action cmd
            • endpoint-generate-memory-dump cmd
            • run-script-action cmd
            • endpoint-get-processes-action cmd
            • endpoint-scan-action cmd
            • endpoint-get-actions-state cmd
            • endpoint-suspend-process-action cmd
            • endpoint-unisolate-action cmd
            • endpoint-upload-action cmd
            • get-endpoint-metadata-list cmd
            • get-endpoint-metadata cmd
            • get-policy-response cmd
            • get-protection-updates-note cmd
            • create-update-protection-updates-note cmd
            • endpoint-script-library-list-scripts cmd
            • endpoint-script-library-create-script cmd
            • endpoint-script-library-delete-script cmd
            • endpoint-script-library-get-one-script cmd
            • endpoint-script-library-patch-update-script cmd
            • endpoint-script-library-download-script cmd
          • security-entity-analytics-api ns
            • delete-asset-criticality-record cmd
            • get-asset-criticality-record cmd
            • create-asset-criticality-record cmd
            • bulk-upsert-asset-criticality-records cmd
            • find-asset-criticality-records cmd
            • delete-monitoring-engine cmd
            • disable-monitoring-engine cmd
            • init-monitoring-engine cmd
            • schedule-monitoring-engine cmd
            • priv-mon-health cmd
            • priv-mon-privileges cmd
            • create-priv-mon-user cmd
            • privmon-bulk-upload-users-c-s-v cmd
            • delete-priv-mon-user cmd
            • update-priv-mon-user cmd
            • list-priv-mon-users cmd
            • install-privileged-access-detection-package cmd
            • get-privileged-access-detection-package-status cmd
            • create-watchlist cmd
            • get-watchlist cmd
            • update-watchlist cmd
            • upload-watchlist-csv cmd
            • assign-watchlist-entities cmd
            • unassign-watchlist-entities cmd
            • list-watchlists cmd
            • clean-up-risk-engine cmd
            • configure-risk-engine-saved-object cmd
            • schedule-risk-engine-now cmd
            • get-risk-score-history cmd
          • security-entity-store ns
            • put-security-entity-store cmd
            • get-security-entity-store-entities cmd
            • delete-security-entity-store-entities cmd
            • post-security-entity-store-entities-entitytype cmd
            • put-security-entity-store-entities-entitytype cmd
            • put-security-entity-store-entities-bulk cmd
            • post-security-entity-store-install cmd
            • get-security-entity-store-resolution-group cmd
            • post-security-entity-store-resolution-link cmd
            • get-security-entity-store-resolution-rules cmd
            • put-security-entity-store-resolution-rules-id-disable cmd
            • put-security-entity-store-resolution-rules-id-enable cmd
            • post-security-entity-store-resolution-unlink cmd
            • put-security-entity-store-start cmd
            • get-security-entity-store-status cmd
            • put-security-entity-store-stop cmd
            • post-security-entity-store-uninstall cmd
          • security-exceptions-api ns
            • create-rule-exception-list-items cmd
            • delete-exception-list cmd
            • read-exception-list cmd
            • create-exception-list cmd
            • update-exception-list cmd
            • duplicate-exception-list cmd
            • export-exception-list cmd
            • find-exception-lists cmd
            • import-exception-list cmd
            • delete-exception-list-item cmd
            • read-exception-list-item cmd
            • create-exception-list-item cmd
            • update-exception-list-item cmd
            • find-exception-list-items cmd
            • read-exception-list-summary cmd
            • create-shared-exception-list cmd
          • security-lists-api ns
            • delete-list cmd
            • read-list cmd
            • patch-list cmd
            • create-list cmd
            • update-list cmd
            • find-lists cmd
            • delete-list-index cmd
            • read-list-index cmd
            • create-list-index cmd
            • delete-list-item cmd
            • read-list-item cmd
            • patch-list-item cmd
            • create-list-item cmd
            • update-list-item cmd
            • export-list-items cmd
            • find-list-items cmd
            • import-list-items cmd
            • read-list-privileges cmd
          • security-osquery-api ns
            • osquery-get-unified-history cmd
            • osquery-find-live-queries cmd
            • osquery-create-live-query cmd
            • osquery-get-live-query-details cmd
            • osquery-get-live-query-results cmd
            • osquery-export-live-query-results cmd
            • osquery-find-packs cmd
            • osquery-create-packs cmd
            • osquery-delete-packs cmd
            • osquery-get-packs-details cmd
            • osquery-update-packs cmd
            • osquery-copy-packs cmd
            • osquery-find-saved-queries cmd
            • osquery-create-saved-query cmd
            • osquery-delete-saved-query cmd
            • osquery-get-saved-query-details cmd
            • osquery-update-saved-query cmd
            • osquery-copy-saved-query cmd
            • osquery-get-scheduled-action-results cmd
            • osquery-export-scheduled-query-results cmd
            • osquery-get-scheduled-query-results cmd
          • security-solution-initialization-api ns
            • initialize-security-solution cmd
          • security-timeline-api ns
            • delete-note cmd
            • get-notes cmd
            • persist-note-route cmd
            • persist-pinned-event-route cmd
            • delete-timelines cmd
            • get-timeline cmd
            • patch-timeline cmd
            • create-timelines cmd
            • copy-timeline cmd
            • get-draft-timelines cmd
            • clean-draft-timelines cmd
            • export-timelines cmd
            • persist-favorite-route cmd
            • import-timelines cmd
            • install-prepacked-timelines cmd
            • resolve-timeline cmd
            • get-timelines cmd
          • significantevents ns
            • get-streams-name-queries cmd
            • post-streams-name-queries-bulk cmd
            • delete-streams-name-queries-queryid cmd
            • put-streams-name-queries-queryid cmd
            • get-streams-name-significant-events cmd
          • slo ns
            • find-slos-op cmd
            • create-slo-op cmd
            • bulk-delete-op cmd
            • bulk-delete-status-op cmd
            • delete-rollup-data-op cmd
            • bulk-snapshot-op cmd
            • delete-slo-instances-op cmd
            • delete-slo-op cmd
            • get-slo-op cmd
            • update-slo-op cmd
            • reset-slo-op cmd
            • get-snapshot-op cmd
            • disable-slo-op cmd
            • enable-slo-op cmd
            • get-definitions-op cmd
          • spaces ns
            • get-spaces-space cmd
            • post-spaces-space cmd
            • delete-spaces-space-id cmd
            • get-spaces-space-id cmd
            • put-spaces-space-id cmd
          • streams ns
            • get-streams cmd
            • post-streams-disable cmd
            • post-streams-enable cmd
            • post-streams-resync cmd
            • delete-streams-name cmd
            • get-streams-name cmd
            • put-streams-name cmd
            • post-streams-name-fork cmd
            • get-streams-name-ingest cmd
            • put-streams-name-ingest cmd
            • get-streams-name-query cmd
            • put-streams-name-query cmd
            • post-streams-name-content-export cmd
            • post-streams-name-content-import cmd
            • get-streams-streamname-attachments cmd
            • post-streams-streamname-attachments-bulk cmd
            • delete-streams-streamname-attachments-attachmenttype-attachmentid cmd
            • put-streams-streamname-attachments-attachmenttype-attachmentid cmd
          • system ns
            • get-status cmd
          • tags ns
            • get-tags cmd
            • post-tags cmd
            • delete-tags-id cmd
            • get-tags-id cmd
            • put-tags-id cmd
          • task-manager ns
            • task-manager-health cmd
          • visualizations ns
            • search-visualizations cmd
            • create-visualization cmd
            • get-visualization cmd
            • upsert-visualization cmd
            • delete-visualization cmd
          • workflows ns
            • delete-workflows cmd
            • get-workflows cmd
            • post-workflows cmd
            • get-workflows-aggs cmd
            • get-workflows-connectors cmd
            • get-workflows-executions-executionid cmd
            • post-workflows-executions-executionid-cancel cmd
            • get-workflows-executions-executionid-children cmd
            • get-workflows-executions-executionid-logs cmd
            • post-workflows-executions-executionid-resume cmd
            • get-workflows-executions-executionid-step-stepexecutionid cmd
            • get-workflows-executions-executionid-steps-stepid-resume-external cmd
            • post-workflows-executions-executionid-steps-stepid-resume-external cmd
            • get-workflows-executions-executionid-steps-stepid-resume-external-form cmd
            • post-workflows-export cmd
            • put-workflows-managed-workflow-id cmd
            • post-workflows-mget cmd
            • get-workflows-schema cmd
            • get-workflows-stats cmd
            • post-workflows-step-test cmd
            • post-workflows-test cmd
            • post-workflows-workflow cmd
            • delete-workflows-workflow-id cmd
            • get-workflows-workflow-id cmd
            • put-workflows-workflow-id cmd
            • post-workflows-workflow-id-clone cmd
            • post-workflows-workflow-id-run cmd
            • get-workflows-workflow-workflowid-executions cmd
            • post-workflows-workflow-workflowid-executions-cancel cmd
            • get-workflows-workflow-workflowid-executions-steps cmd
            • get-workflows-workflow-executions cmd
      • cloud ns
        • trust ns
          • get-current-account cmd
          • update-current-account cmd
          • patch-current-account cmd
        • auth ns
          • get-api-keys cmd
          • create-api-key cmd
          • delete-api-keys cmd
          • get-api-key cmd
          • delete-api-key cmd
        • billing ns
          • get-costs-overview cmd
          • get-costs-charts cmd
          • get-costs-deployments cmd
          • get-costs-charts-by-deployment cmd
          • get-costs-items-by-deployment cmd
          • get-costs-items cmd
        • orgs ns
          • list-organizations cmd
          • get-organization-invitation cmd
          • get-organization cmd
          • update-organization cmd
          • domain-claim-get-domain-claims cmd
          • domain-claim-delete cmd
          • domain-claim-generate-verification-code cmd
          • domain-claim-verify-domain cmd
          • get-organization-idp cmd
          • setup-organization-idp cmd
          • teardown-organization-idp cmd
          • get-organization-idp-metadata cmd
          • list-organization-invitations cmd
          • create-organization-invitations cmd
          • delete-organization-invitations cmd
          • list-organization-members cmd
          • delete-organization-memberships cmd
          • get-role-mappings cmd
          • add-role-mappings-individually cmd
          • update-role-mappings cmd
          • delete-role-mappings cmd
          • delete-role-mappings-individually cmd
          • update-role-mapping cmd
        • users ns
          • add-role-assignments cmd
          • remove-role-assignments cmd
        • hosted ns
          • deployment-templates ns
            • get-deployment-templates-v2 cmd
            • get-deployment-template-v2 cmd
          • deployments ns
            • list-deployments cmd
            • create-deployment cmd
            • search-deployments cmd
            • search-eligible-remote-clusters cmd
            • get-deployment cmd
            • update-deployment cmd
            • restore-deployment cmd
            • shutdown-deployment cmd
            • get-deployment-apm-resource-info cmd
            • deployment-apm-reset-secret-token cmd
            • get-deployment-appsearch-resource-info cmd
            • get-appsearch-read-only-mode cmd
            • set-appsearch-read-only-mode cmd
            • get-deployment-certificate-authority cmd
            • get-deployment-es-resource-info cmd
            • enable-deployment-resource-ccr cmd
            • enable-deployment-resource-ilm cmd
            • enable-deployment-resource-slm cmd
            • reset-elasticsearch-user-password cmd
            • restart-deployment-es-resource cmd
            • shutdown-deployment-es-resource cmd
            • get-deployment-es-resource-eligible-remote-clusters cmd
            • get-deployment-es-resource-keystore cmd
            • set-deployment-es-resource-keystore cmd
            • get-deployment-es-resource-remote-clusters cmd
            • set-deployment-es-resource-remote-clusters cmd
            • get-deployment-es-resource-snapshot-repository cmd
            • create-deployment-es-resource-snapshot-repository cmd
            • delete-deployment-es-resource-snapshot-repository cmd
            • get-deployment-es-resource-tiers cmd
            • update-deployment-es-resource-tier cmd
            • get-deployment-enterprise-search-resource-info cmd
            • get-deployment-integrations-server-resource-info cmd
            • get-deployment-kib-resource-info cmd
            • migrate-deployment-template cmd
            • get-deployment-tags cmd
            • set-deployment-tags cmd
            • upgrade-deployment cmd
            • get-deployment-upgrade-assistant-status cmd
            • restore-deployment-resource cmd
            • start-deployment-resource-instances-all cmd
            • stop-deployment-resource-instances-all cmd
            • start-deployment-resource-instances-all-maintenance-mode cmd
            • stop-deployment-resource-instances-all-maintenance-mode cmd
            • start-deployment-resource-instances cmd
            • stop-deployment-resource-instances cmd
            • start-deployment-resource-maintenance-mode cmd
            • stop-deployment-resource-maintenance-mode cmd
            • cancel-deployment-resource-pending-plan cmd
            • get-deployment-resource-user-settings cmd
            • update-deployment-resource-user-settings cmd
            • restart-deployment-stateless-resource cmd
            • shutdown-deployment-stateless-resource cmd
          • traffic-filters ns
            • get-traffic-filter-deployment-ruleset-associations cmd
            • get-traffic-filter-claimed-link-ids cmd
            • claim-traffic-filter-link-id cmd
            • unclaim-traffic-filter-link-id cmd
            • get-traffic-filter-rulesets cmd
            • create-traffic-filter-ruleset cmd
            • get-traffic-filter-ruleset cmd
            • update-traffic-filter-ruleset cmd
            • delete-traffic-filter-ruleset cmd
            • get-traffic-filter-ruleset-deployment-associations cmd
            • create-traffic-filter-ruleset-association cmd
            • delete-traffic-filter-ruleset-association cmd
          • extensions ns
            • list-extensions cmd
            • create-extension cmd
            • get-extension cmd
            • update-extension cmd
            • upload-extension cmd
            • delete-extension cmd
          • stack ns
            • get-version-stacks cmd
          • trusted-environments ns
            • get-trusted-envs cmd
        • serverless ns
          • projects ns
            • search ns
              • list cmd
              • create cmd
              • get cmd
              • delete cmd
              • patch cmd
              • reset-credentials cmd
              • resume cmd
              • get-roles cmd
              • get-status cmd
            • observability ns
              • list cmd
              • create cmd
              • get cmd
              • delete cmd
              • patch cmd
              • reset-credentials cmd
              • resume cmd
              • get-roles cmd
              • get-status cmd
            • security ns
              • list cmd
              • create cmd
              • get cmd
              • delete cmd
              • patch cmd
              • reset-credentials cmd
              • resume cmd
              • get-roles cmd
              • get-status cmd
          • cross-project ns
            • get-elasticsearch-project-link-candidates cmd
            • get-observability-project-link-candidates cmd
            • get-security-project-link-candidates cmd
            • get-elasticsearch-project-can-delete cmd
            • get-observability-project-can-delete cmd
            • get-security-project-can-delete cmd
          • regions ns
            • list-regions cmd
            • get-region cmd
          • traffic-filters ns
            • list-traffic-filters cmd
            • create-traffic-filter cmd
            • get-traffic-filter-metadata cmd
            • get-traffic-filter cmd
            • delete-traffic-filter cmd
            • patch-traffic-filter cmd
      • docs ns
        • search cmd
        • ask cmd
        • read cmd
      • config ns
        • context ns
          • list cmd
          • add cmd
          • edit cmd
          • remove cmd
        • current-context ns
          • get cmd
          • set cmd
      • sanitize ns
        • index-name cmd
        • snapshot-name cmd
        • data-stream-type cmd
        • data-stream-dataset cmd
        • data-stream-namespace cmd
        • field-name cmd
        • pipeline-name cmd
        • repository-name cmd
  • Machine learning
    • Kibana anomaly detection job wizards
      • Apache anomaly detection configurations
      • APM anomaly detection configurations
      • Auditbeat anomaly detection configurations
      • Logs anomaly detection configurations
      • Metricbeat anomaly detection configurations
      • Metrics anomaly detection configurations
      • Nginx anomaly detection configurations
      • Security anomaly detection configurations
      • Uptime anomaly detection configurations
    • ML function reference
      • Count functions
      • Geographic functions
      • Information content functions
      • Metric functions
      • Rare functions
      • Sum functions
      • Time functions
  • Search UI
    • Ecommerce
      • Autocomplete
      • Product Carousels
      • Category Page
      • Product Detail Page
      • Search Page
    • Tutorials
      • Search UI with Elasticsearch
        • Setup Elasticsearch
        • Setup an Index
        • Install Connector
        • Configure and Run Search UI
        • Using in Production
        • Customise Request
      • Search UI with App Search
      • Search UI with Workplace Search
    • Basic usage
      • Using search-as-you-type
      • Adding search bar to header
      • Debugging
    • Advanced usage
      • Conditional Facets
      • Changing component behavior
      • Analyzing performance
      • Creating Components
      • Building a custom connector
      • NextJS Integration
    • API reference
      • Core API
        • Configuration
        • State
        • Actions
      • React API
        • WithSearch & withSearch
        • useSearch hook
      • React components
        • Results
        • Result
        • ResultsPerPage
        • Facet
        • Sorting
        • Paging
        • PagingInfo
        • ErrorBoundary
      • Connectors API
        • Elasticsearch Connector
        • Site Search Connector
        • Workplace Search Connector
      • Plugins
    • Troubleshooting
  • Glossary
Elastic logo
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© 2026 Elasticsearch B.V. All Rights Reserved.

This content is available in different formats for convenience only. All original licensing terms apply.

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries. Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.

Notice at Collection | Your Privacy Choices