Index view
Query one index, alias or data stream with any method, see hits as documents, a table or JSON, and edit, clone or delete documents.
The Index view is a focused tab for one target — an index, alias, data stream or pattern. Open it with Query this index (or alias, data stream) in the Explorer, or from ⌘K. Every target you open gets its own tab; ← Explorer takes you back.
The header shows the target, its kind, document count, size and health. Below it are six tabs: Query, Aggregations, Documents, Mapping, Aliases and Settings.
Query
The request bar
- Method —
GET(read),POST(search / create),PUT(create / replace),HEAD(exists check) orDELETE(asks to confirm on production). - Path — the
/<target>/prefix is locked; type the rest (_search?track_total_hits=true,_doc/abc123…). Press ↵ in the path box to run. - ▶ Run (⌘↵) — becomes Cancel while a request is running; cancelling also cancels the search task on the cluster.
- Save to library — name it, choose or create a folder, add
#tags.
Endpoint chips
One click fills in the method, path and a starter body:
| Chip | Request |
|---|---|
_search | POST _search?track_total_hits=true with size: 20 and match_all |
_count | POST _count |
_doc/{id} | GET _doc/ — add the id |
_mapping | GET _mapping |
_update_by_query | runs in the background (wait_for_completion=false) with a sample script |
_delete_by_query | conflicts=proceed with a sample query |
_settings | GET _settings?flat_settings=true |
The body
The JSON body has autocomplete for the query DSL and the real fields of the target (with their types), snippets for common queries and aggregations, and Format (⌘I). Drag the divider to resize the body and results.
Results
The results header shows the status, 1–20 of 4,213 hits, time and size. Switch between:
- Documents — one card per hit with Edit, Copy, Clone and Delete.
- Table — a virtualised table of the flattened
_source(first 40 columns). - JSON — the raw response.
‹ › pages through results by rewriting from in the body. Export… saves this page or every matching document — see Export. Copy copies the response.
Editing documents
- Edit re-reads the document first, opens it in an editor, and Review changes shows a diff before Save document. The save uses
if_seq_noandif_primary_term, so if someone changed the document in the meantime you get a clear version conflict instead of silently overwriting their change. - Clone opens a copy as a new document with a new id.
- Delete asks first, then deletes the document and refreshes.
On production connections every write is confirmed again; on read-only connections writes are blocked.
Documents
The Documents tab browses every document — not limited to the first 10,000 — using a point-in-time snapshot and search_after, 20 at a time. The header reads 1–20 of 1,204,553 documents · point-in-time snapshot. View as Documents or Table, page with ‹ ›, and Export… everything, optionally with the index definition. The snapshot is closed when you leave the tab.
Aggregations, Mapping, Aliases, Settings
- Aggregations — the stage-by-stage builder. See Aggregation pipelines.
- Mapping — editable for a concrete index (Mappings); for an alias, data stream or pattern it shows the merged, read-only field list.
- Aliases — which indices an alias points to, or which aliases point at an index.
- Settings — flat settings of the index (or of the first index behind an alias).