Essential Operations and Configuration for Elasticsearch

License Management

To check the current license details, use:

curl -XGET 'http://localhost:9200/_xpack/license?pretty'

Obtain a new license at the official registrasion portal. To apply an updated license file:

curl -XPUT -u elastic 'http://localhost:9200/_xpack/license?acknowledge=true' -H "Content-Type: application/json" -d @new_license.json

Core Concepts

Elasticsearch requests follow a standard HTTP structure:

curl -X<METHOD> '<PROTOCOL>://<HOST>:<PORT>/<PATH>?<QUERY>' -d '<BODY>'
  • METHOD: GET, POST, PUT, DELETE, HEAD.
  • PROTOCOL: http or https.
  • HOST: Node hostname or localhost.
  • PORT: Default is 9200.
  • PATH: API endpoint (e.g., _cluster/health).
  • QUERY: Optional parameters like ?pretty.
  • BODY: JSON payload if required.

Data is stored as JSON documents within indices and types.

Search Operations

Full-text Search with match:

GET /user_index/user_type/_search
{
  "query": {
    "match": {
      "description": "software development"
    }
  }
}

Phrase Search using match_phrase:

GET /user_index/user_type/_search
{
  "query": {
    "match_phrase": {
      "description": "software development"
    }
  }
}

Highlighting matches in results:

GET /user_index/user_type/_search
{
  "query": {
    "match_phrase": {
      "description": "software development"
    }
  },
  "highlight": {
    "fields": {
      "description": {}
    }
  }
}

Aggregations for analytical queries:

GET /user_index/user_type/_search
{
  "aggs": {
    "top_skills": {
      "terms": { "field": "skills" }
    }
  }
}

If a fielddata error occurs for text fields, enable it:

PUT user_index/_mapping/user_type
{
  "properties": {
    "skills": {
      "type": "text",
      "fielddata": true
    }
  }
}

Cluster Health

GET /_cluster/health
{
  "cluster_name": "my_cluster",
  "status": "green",
  "timed_out": false,
  "number_of_nodes": 3,
  "number_of_data_nodes": 2,
  "active_primary_shards": 10,
  "active_shards": 20,
  "relocating_shards": 0,
  "initializing_shards": 0,
  "unassigned_shards": 0
}

Status colors indicate cluster state:

  • green: All primary and replica shards operational.
  • yellow: All primaries active, but some replicas missing.
  • red: At least one primary shard is down.

Index Configuration

Create an index with custom settings:

PUT /products
{
  "settings": {
    "number_of_shards": 5,
    "number_of_replicas": 1
  }
}

Update replica count dynamically:

PUT /products/_settings
{
  "number_of_replicas": 2
}

Document Operations

Index a Document with a custom ID:

PUT /products/item/101
{
  "name": "Laptop",
  "price": 1200
}

Auto-generate ID using POST:

POST /products/item/
{
  "name": "Monitor",
  "price": 300
}

Retrieve a Document:

GET /products/item/101

Update a Document (full replacement):

PUT /products/item/101
{
  "name": "Gaming Laptop",
  "price": 1500
}

Delete a Document:

DELETE /products/item/101

Bulk Operations

Perform multiple actions efficiently:

POST /_bulk
{ "index": { "_index": "products", "_type": "item", "_id": "200" } }
{ "name": "Keyboard", "price": 50 }
{ "delete": { "_index": "products", "_type": "item", "_id": "150" } }
{ "update": { "_index": "products", "_type": "item", "_id": "101", "_retry_on_conflict": 3 } }
{ "doc": { "price": 1400 } }

Search Queries with DSL

Combine conditions using bool:

GET /products/item/_search
{
  "query": {
    "bool": {
      "must": {
        "match": { "category": "electronics" }
      },
      "filter": {
        "range": {
          "price": { "gte": 100, "lte": 1000 }
        }
      }
    }
  }
}

Multi-field search:

{
  "multi_match": {
    "query": "wireless mouse",
    "fields": ["title", "description"]
  }
}

Exact match with term:

{ "term": { "status": "active" } }

Check field existence:

{ "exists": { "field": "tags" } }

Pagination Methods

Basic Pagination using from and size:

GET /products/item/_search
{
  "from": 10,
  "size": 5,
  "query": { "match_all": {} }
}

Encrease the maximum window if needed:

PUT products/_settings
{
  "index": {
    "max_result_window": 50000
  }
}

Search After for deep pagination with out skipping:

GET /products/item/_search
{
  "size": 10,
  "query": { "match_all": {} },
  "sort": [
    { "price": "desc" },
    { "_id": "asc" }
  ]
}

Use the sort values from the last result as search_after for the next page.

Scroll API for large result sets (non-real-time):

POST /products/_search?scroll=2m
{
  "size": 100,
  "query": { "match_all": {} }
}

Continue scrolling with the returned _scroll_id:

POST /_search/scroll
{
  "scroll": "2m",
  "scroll_id": "DXF1ZXJ5QW5kRmV0Y2gBAAAAAAAAACYWaFh0R3k5Y3ZTYU9JSEZqNGV6ek14UQ=="
}

Clean up scroll contexts:

DELETE /_search/scroll/_all

Text vs. Keyword Fields

In Elasticsearch 5.x and above, string fields are replaced by:

  • text: For full-text content. Values are analyzed (tokenized) for searching.
  • keyword: For exact values like IDs, codes, or tags. No analysis; used for filtering, sorting, and aggregations.

Example mapping:

PUT /my_index
{
  "mappings": {
    "my_type": {
      "properties": {
        "title": { "type": "text" },
        "sku": { "type": "keyword" }
      }
    }
  }
}

Analyzers and Tokenization

Test how text is processed:

POST /_analyze
{
  "analyzer": "standard",
  "text": "Elasticsearch tutorial"
}

For a custom pattern analyzer (splitting by comma):

PUT /my_index
{
  "settings": {
    "analysis": {
      "analyzer": {
        "comma_splitter": {
          "type": "pattern",
          "pattern": ","
        }
      }
    }
  }
}

Tags: elasticsearch Search Engine Data Indexing query DSL Data Aggregation

Posted on Fri, 09 Oct 2026 16:16:58 +0000 by cyberrate