License Management
To check the current license details, use:
curl -XGET 'http://localhost:9200/_xpack/license?pretty'
Obtain a new license at the official registrasion portal. To apply an updated license file:
curl -XPUT -u elastic 'http://localhost:9200/_xpack/license?acknowledge=true' -H "Content-Type: application/json" -d @new_license.json
Core Concepts
Elasticsearch requests follow a standard HTTP structure:
curl -X<METHOD> '<PROTOCOL>://<HOST>:<PORT>/<PATH>?<QUERY>' -d '<BODY>'
- METHOD: GET, POST, PUT, DELETE, HEAD.
- PROTOCOL: http or https.
- HOST: Node hostname or localhost.
- PORT: Default is 9200.
- PATH: API endpoint (e.g.,
_cluster/health). - QUERY: Optional parameters like
?pretty. - BODY: JSON payload if required.
Data is stored as JSON documents within indices and types.
Search Operations
Full-text Search with match:
GET /user_index/user_type/_search
{
"query": {
"match": {
"description": "software development"
}
}
}
Phrase Search using match_phrase:
GET /user_index/user_type/_search
{
"query": {
"match_phrase": {
"description": "software development"
}
}
}
Highlighting matches in results:
GET /user_index/user_type/_search
{
"query": {
"match_phrase": {
"description": "software development"
}
},
"highlight": {
"fields": {
"description": {}
}
}
}
Aggregations for analytical queries:
GET /user_index/user_type/_search
{
"aggs": {
"top_skills": {
"terms": { "field": "skills" }
}
}
}
If a fielddata error occurs for text fields, enable it:
PUT user_index/_mapping/user_type
{
"properties": {
"skills": {
"type": "text",
"fielddata": true
}
}
}
Cluster Health
GET /_cluster/health
{
"cluster_name": "my_cluster",
"status": "green",
"timed_out": false,
"number_of_nodes": 3,
"number_of_data_nodes": 2,
"active_primary_shards": 10,
"active_shards": 20,
"relocating_shards": 0,
"initializing_shards": 0,
"unassigned_shards": 0
}
Status colors indicate cluster state:
- green: All primary and replica shards operational.
- yellow: All primaries active, but some replicas missing.
- red: At least one primary shard is down.
Index Configuration
Create an index with custom settings:
PUT /products
{
"settings": {
"number_of_shards": 5,
"number_of_replicas": 1
}
}
Update replica count dynamically:
PUT /products/_settings
{
"number_of_replicas": 2
}
Document Operations
Index a Document with a custom ID:
PUT /products/item/101
{
"name": "Laptop",
"price": 1200
}
Auto-generate ID using POST:
POST /products/item/
{
"name": "Monitor",
"price": 300
}
Retrieve a Document:
GET /products/item/101
Update a Document (full replacement):
PUT /products/item/101
{
"name": "Gaming Laptop",
"price": 1500
}
Delete a Document:
DELETE /products/item/101
Bulk Operations
Perform multiple actions efficiently:
POST /_bulk
{ "index": { "_index": "products", "_type": "item", "_id": "200" } }
{ "name": "Keyboard", "price": 50 }
{ "delete": { "_index": "products", "_type": "item", "_id": "150" } }
{ "update": { "_index": "products", "_type": "item", "_id": "101", "_retry_on_conflict": 3 } }
{ "doc": { "price": 1400 } }
Search Queries with DSL
Combine conditions using bool:
GET /products/item/_search
{
"query": {
"bool": {
"must": {
"match": { "category": "electronics" }
},
"filter": {
"range": {
"price": { "gte": 100, "lte": 1000 }
}
}
}
}
}
Multi-field search:
{
"multi_match": {
"query": "wireless mouse",
"fields": ["title", "description"]
}
}
Exact match with term:
{ "term": { "status": "active" } }
Check field existence:
{ "exists": { "field": "tags" } }
Pagination Methods
Basic Pagination using from and size:
GET /products/item/_search
{
"from": 10,
"size": 5,
"query": { "match_all": {} }
}
Encrease the maximum window if needed:
PUT products/_settings
{
"index": {
"max_result_window": 50000
}
}
Search After for deep pagination with out skipping:
GET /products/item/_search
{
"size": 10,
"query": { "match_all": {} },
"sort": [
{ "price": "desc" },
{ "_id": "asc" }
]
}
Use the sort values from the last result as search_after for the next page.
Scroll API for large result sets (non-real-time):
POST /products/_search?scroll=2m
{
"size": 100,
"query": { "match_all": {} }
}
Continue scrolling with the returned _scroll_id:
POST /_search/scroll
{
"scroll": "2m",
"scroll_id": "DXF1ZXJ5QW5kRmV0Y2gBAAAAAAAAACYWaFh0R3k5Y3ZTYU9JSEZqNGV6ek14UQ=="
}
Clean up scroll contexts:
DELETE /_search/scroll/_all
Text vs. Keyword Fields
In Elasticsearch 5.x and above, string fields are replaced by:
- text: For full-text content. Values are analyzed (tokenized) for searching.
- keyword: For exact values like IDs, codes, or tags. No analysis; used for filtering, sorting, and aggregations.
Example mapping:
PUT /my_index
{
"mappings": {
"my_type": {
"properties": {
"title": { "type": "text" },
"sku": { "type": "keyword" }
}
}
}
}
Analyzers and Tokenization
Test how text is processed:
POST /_analyze
{
"analyzer": "standard",
"text": "Elasticsearch tutorial"
}
For a custom pattern analyzer (splitting by comma):
PUT /my_index
{
"settings": {
"analysis": {
"analyzer": {
"comma_splitter": {
"type": "pattern",
"pattern": ","
}
}
}
}
}