stack es fleet search cli command

Auth required Idempotent Scope: global
elastic stack es fleet search --index <index> [options]
		

Run a Fleet search.

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--index string required
A single target to search. If the target is an index alias, it must resolve to a single index.
--allow-no-indices
A setting that does two separate checks on the index expression. If false, the request returns an error (1) if any wildcard expression (including _all and *) resolves to zero matching indices or (2) if the complete set of resolved indices, aliases or data streams is empty after all expressions are evaluated. If true, index expressions that resolve to no indices are allowed and the request returns an empty result.
--analyzer string
--analyze-wildcard
--batched-reduce-size number
--ccs-minimize-roundtrips
--default-operator enum

Values: and, or

--df string
--docvalue-fields string[]

Array of wildcard (*) patterns. The request returns doc values for field names matching these patterns in the hits.fields property of the response.

Repeatable: pass --docvalue-fields multiple times to supply more than one value

--expand-wildcards enum

Values: all, open, closed, hidden, none

Repeatable: pass --expand-wildcards multiple times to supply more than one value

--explain
If true, returns detailed information about score computation as part of a hit.
--ignore-throttled
--ignore-unavailable
If false, the request returns an error if it targets a concrete (non-wildcarded) index, alias, or data stream that is missing, closed, or otherwise unavailable. If true, unavailable concrete targets are silently ignored.
--lenient
--max-concurrent-shard-requests number
--preference string
--pre-filter-shard-size number
--request-cache
--routing string

Repeatable: pass --routing multiple times to supply more than one value

--scroll string
--search-type enum

Values: query_then_fetch, dfs_query_then_fetch

--stats string[]

Stats groups to associate with the search. Each group maintains a statistics aggregation for its associated searches. You can retrieve these stats using the indices stats API.

Repeatable: pass --stats multiple times to supply more than one value

--stored-fields string

List of stored fields to return as part of a hit. If no fields are specified, no stored fields are included in the response. If this field is specified, the _source parameter defaults to false. You can pass _source: true to return both source fields and stored fields in the search response.

Repeatable: pass --stored-fields multiple times to supply more than one value

--suggest-field string
Specifies which field to use for suggestions.
--suggest-mode enum

Values: missing, popular, always

--suggest-size number
--suggest-text string
The source text for which the suggestions should be returned.
--terminate-after number
Maximum number of documents to collect for each shard. If a query reaches this limit, Elasticsearch terminates the query early. Elasticsearch collects documents before sorting. Defaults to 0, which does not terminate query execution early.
--timeout string
Specifies the period of time to wait for a response from each shard. If no response is received before the timeout expires, the request fails and returns an error. Defaults to no timeout.
--track-total-hits number
Number of hits matching the query to count accurately. If true, the exact number of hits is returned at the cost of some performance. If false, the response does not include the total number of hits matching the query. Defaults to 10,000 hits.
--track-scores
If true, calculate and return document scores, even if the scores are not used for sorting.
--typed-keys
--rest-total-hits-as-int
--version
If true, returns document version as part of a hit.
--source string
Indicates which source fields are returned for matching documents. These fields are returned in the hits._source property of the search response.
--source-excludes string

Repeatable: pass --source-excludes multiple times to supply more than one value

--source-includes string

Repeatable: pass --source-includes multiple times to supply more than one value

--seq-no-primary-term
If true, returns sequence number and primary term of the last modification of each hit. See Optimistic concurrency control.
--q string
--size number
The number of hits to return. By default, you cannot page through more than 10,000 hits using the from and size parameters. To page through more hits, use the search_after parameter.
--from number
Starting document offset. By default, you cannot page through more than 10,000 hits using the from and size parameters. To page through more hits, use the search_after parameter.
--sort string

Repeatable: pass --sort multiple times to supply more than one value

--wait-for-checkpoints string[]

A comma separated list of checkpoints. When configured, the search API will only be executed on a shard after the relevant checkpoint has become visible for search. Defaults to an empty list which will cause Elasticsearch to immediately execute the search.

Repeatable: pass --wait-for-checkpoints multiple times to supply more than one value

--allow-partial-search-results
If true, returns partial results if there are shard request timeouts or shard failures. If false, returns an error with no partial results. Defaults to the configured cluster setting search.default_allow_partial_results, which is true by default.
--aggregations string
--collapse string
--ext string
Configuration of search extensions defined by Elasticsearch plugins.
--highlight string
--indices-boost string[]

Boosts the _score of documents from specified indices.

Repeatable: pass --indices-boost multiple times to supply more than one value

--min-score number
Minimum _score for matching documents. Documents with a lower _score are not included in search results and results collected by aggregations.
--post-filter string
--profile
--query string
Defines the search definition using the Query DSL.
--rescore string

Repeatable: pass --rescore multiple times to supply more than one value

--script-fields string
Retrieve a script evaluation (based on different fields) for each hit.
--search-after string[]

Repeatable: pass --search-after multiple times to supply more than one value

--slice string
--fields string[]

Array of wildcard (*) patterns. The request returns values for field names matching these patterns in the hits.fields property of the response.

Repeatable: pass --fields multiple times to supply more than one value

--suggest string
--pit string
Limits the search to a point in time (PIT). If you provide a PIT, you cannot specify an <index> in the request path.
--runtime-mappings string
Defines one or more runtime fields in the search request. These fields take precedence over mapped fields with the same name.
--error-trace
When set to true Elasticsearch will include the full stack trace of errors when they occur.
--filter-path string

Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.

Repeatable: pass --filter-path multiple times to supply more than one value

--human
When set to true will return statistics in a format suitable for humans. For example "exists_time": "1h" for humans and "exists_time_in_millis": 3600000 for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines.
--pretty
If set to true the returned JSON will be "pretty-formatted". Only use this option for debugging only.
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--json

output as JSON