Explorer

Browse indices, data streams, aliases and templates; see an index’s stats, mapping, settings and shards; delete or empty indices safely.

The Explorer is the home screen of a connection: a tree of everything in the cluster on the left, and a page for whatever you select on the right.

The tree

The header shows the cluster name, health and node count, for example Elasticsearch 9.5.3 · green · 1 node. Below it are up to five sections, each with a count:

  • Indices — with size, document count, or closed.
  • Data streams — with the number of backing indices.
  • Aliases — shown as alias → index or alias → 3 indices.
  • Index templates and Component templates — with their priority (p200).

Filtering and sorting

  • Filter indices, aliases, templates — type to filter every section at once. Filtering expands all sections and shows up to 100 matches per section.
  • Hide system (on by default) hides the clutter: dot-prefixed and hidden indices, data-stream backing indices, system data streams, dot-prefixed aliases and built-in managed templates (logs, metrics, apm, ilm-history, anything with @ in its name…). The cluster overview tells you how many objects are hidden.
  • Hide closed hides closed indices.
  • Sort cycles between name, size and docs.
  • Collapse all / Expand all — the two icons next to the cluster name.
  • ↻ refreshes the metadata. kabanos caches it for 30 seconds and refreshes it automatically after any successful write.

Long sections show 12 rows and a + N more button.

Index page

Selecting an index opens its page. The header has the health, its aliases, Open in workspace (a new POST _search block targeting the index) and Query this index (the Index view).

Tabs:

  • Overview — documents, store size, shards (1p · 1r), creation date; the mapping; its Aliases (write index, filters); the Matched index template with priority, patterns and components; and Key settings such as refresh_interval, replicas, max_result_window, lifecycle policy and codec.
  • Mapping — the field tree, editable. See Mappings.
  • Settings — every setting, filterable, or as raw JSON.
  • Documents — the first 20 documents.
  • Shards — each shard’s role, state, documents, size and node — or why it’s unassigned.
  • Saved queries — library queries that target this index or one of its aliases.

The ⋯ menu has Refresh, Clear cache, Close index / Open index, Export documents…, Empty index… and Delete index….

Delete and empty — with a typed confirmation

Both destructive actions ask you to type the index name before the button unlocks:

  • Delete index removes the index, its mapping, settings and every document. For a data stream it removes all backing indices.
  • Empty index (delete all documents) keeps the index, mapping, settings and aliases and deletes every document with _delete_by_query (match_all). A progress bar follows the task until it finishes.

On a production connection you are asked a second time by the native confirmation dialog.

Data streams

A data stream’s page shows its documents, size, backing indices (each one clickable) and the template that created it. Use Query this data stream to search it, and the ⋯ menu to export, empty or delete it.

Aliases

An alias page shows the merged mapping of all its indices, any alias filters, and a Targets card where you can add and remove indices and choose the write index. See Aliases & templates.

Templates

Index templates show their index patterns, the component templates they’re composed of, and which existing indices match. Component templates show which index templates use them. You can edit both — see Aliases & templates.