Query workspace

A Kibana-style console made of named request blocks — with autocomplete, formatting, imports, sequences and a response pane.

The Query workspace is where you write free-form requests. Instead of one long console, every request is a block with a name that you can fold, tag, save, search and run on its own.

Tabs

Work is organised in tabs (the first one is called Scratch). + adds a tab, double-click renames it. Tabs and their blocks are saved automatically and survive restarts. Closing a tab warns you about unsaved blocks; blocks saved to the library stay in the library.

Each tab can have:

  • a Default target — an index, alias or data stream that is put in front of index-scoped paths. With a default target of listings, POST _search runs as POST listings/_search. Blocks show (default target) when it’s applied.
  • an Env — the environment whose {{variables}} are filled in when you run.

The toolbar also shows which connection requests go to (with a prod pill for production).

Request blocks

A block is written like a Kibana console request — the first line is METHOD path, the rest is the JSON body:

POST listings/_search
{
  "query": { "match": { "title": "garden" } }
}
  • Methods: GET, POST, PUT, DELETE, HEAD, PATCH.
  • Click the block header to fold or unfold it; Collapse all / Expand all are in the toolbar.
  • Click or double-click the title to rename (Untitled request by default). Add #tags from the block menu.
  • An unsaved pill means the block isn’t in a library folder yet. Drag a block’s header onto a folder to save it there.
  • The header shows the line count, the last status and when it last ran.
  • The ⋯ menu: Save to folder… / Rename / move / tags…, Rename, Duplicate, Copy as cURL, Move up, Move down, Delete block / Close (stays in library).

Edits are saved as you type.

Running

  • ⌘↵ in a block runs that block. Outside an editor it runs the active block.
  • Tick the checkboxes of several blocks and click ▶ Run N in order to run them as a sequence. A sequence stops at the first failure.
  • ■ cancels a running request, including the search task on the cluster.
  • Add to routine turns the selected blocks into routine steps.

Autocomplete

  • Request line — methods, then endpoints from the Elasticsearch API specification, your index, alias and data stream names, and query parameters after ?.
  • Body — every key of the query DSL, plus the actual fields of the target index, with their types. Fields are ranked by context: keyword, numeric and date fields first in term, range, sort and aggregations; text fields first in match.
  • Snippets — choosing a query or aggregation inserts a ready skeleton you can tab through, the way Kibana does. For example term inserts "term": { "FIELD": { "value": "VALUE" } } and immediately suggests fields for FIELD. There are snippets for the common queries (bool, match, range, nested, function_score, geo_distance, …), aggregations (terms, date_histogram, composite, top_hits, …) and top-level keys (query, aggs, sort, highlight, collapse, search_after, …).
  • {{variable}} placeholders are highlighted.

⌘I formats the block: JSON is pretty-printed; NDJSON bodies (_bulk, _msearch) keep one object per line.

Importing from Kibana or cURL

Click Import… and paste:

  • an export of the Kibana Dev Tools console — every request becomes a block. A comment line directly above a request (#, ##, ### or //) becomes the block’s title, and Kibana’s """triple-quoted""" strings are converted to normal JSON; or
  • a single cURL command — any credentials in it are removed.

A preview shows what will be imported; click Import N requests.

Copy as cURL

Copy as cURL never includes your credentials. It uses placeholders instead — -u 'user:$ES_PASSWORD' or Authorization: ApiKey $ES_API_KEY — so you can paste it into a terminal and set the variable yourself.

The response pane

  • The status code with its meaning, the time, size and when it ran.
  • JSON or Table (for search results).
  • Previous — the last five responses of a saved block, to compare runs. (Responses up to 512 KB are kept.)
  • Export… — for search responses, export this page or every matching document. See Export.
  • Copy.

The library sidebar

The left side of the workspace is your query library: folders, pins, recent runs, history and search.