Index view

Query one index, alias or data stream with any method, see hits as documents, a table or JSON, and edit, clone or delete documents.

The Index view is a focused tab for one target — an index, alias, data stream or pattern. Open it with Query this index (or alias, data stream) in the Explorer, or from ⌘K. Every target you open gets its own tab; ← Explorer takes you back.

The header shows the target, its kind, document count, size and health. Below it are six tabs: Query, Aggregations, Documents, Mapping, Aliases and Settings.

Query

The request bar

  • Method — GET (read), POST (search / create), PUT (create / replace), HEAD (exists check) or DELETE (asks to confirm on production).
  • Path — the /<target>/ prefix is locked; type the rest (_search?track_total_hits=true, _doc/abc123…). Press ↵ in the path box to run.
  • ▶ Run (⌘↵) — becomes Cancel while a request is running; cancelling also cancels the search task on the cluster.
  • Save to library — name it, choose or create a folder, add #tags.

Endpoint chips

One click fills in the method, path and a starter body:

ChipRequest
_searchPOST _search?track_total_hits=true with size: 20 and match_all
_countPOST _count
_doc/{id}GET _doc/ — add the id
_mappingGET _mapping
_update_by_queryruns in the background (wait_for_completion=false) with a sample script
_delete_by_queryconflicts=proceed with a sample query
_settingsGET _settings?flat_settings=true

The body

The JSON body has autocomplete for the query DSL and the real fields of the target (with their types), snippets for common queries and aggregations, and Format (⌘I). Drag the divider to resize the body and results.

Results

The results header shows the status, 1–20 of 4,213 hits, time and size. Switch between:

  • Documents — one card per hit with Edit, Copy, Clone and Delete.
  • Table — a virtualised table of the flattened _source (first 40 columns).
  • JSON — the raw response.

‹ › pages through results by rewriting from in the body. Export… saves this page or every matching document — see Export. Copy copies the response.

Editing documents

  • Edit re-reads the document first, opens it in an editor, and Review changes shows a diff before Save document. The save uses if_seq_no and if_primary_term, so if someone changed the document in the meantime you get a clear version conflict instead of silently overwriting their change.
  • Clone opens a copy as a new document with a new id.
  • Delete asks first, then deletes the document and refreshes.

On production connections every write is confirmed again; on read-only connections writes are blocked.

Documents

The Documents tab browses every document — not limited to the first 10,000 — using a point-in-time snapshot and search_after, 20 at a time. The header reads 1–20 of 1,204,553 documents · point-in-time snapshot. View as Documents or Table, page with ‹ ›, and Export… everything, optionally with the index definition. The snapshot is closed when you leave the tab.

Aggregations, Mapping, Aliases, Settings

  • Aggregations — the stage-by-stage builder. See Aggregation pipelines.
  • Mapping — editable for a concrete index (Mappings); for an alias, data stream or pattern it shows the merged, read-only field list.
  • Aliases — which indices an alias points to, or which aliases point at an index.
  • Settings — flat settings of the index (or of the first index behind an alias).