Query workspace
A Kibana-style console made of named request blocks — with autocomplete, formatting, imports, sequences and a response pane.
The Query workspace is where you write free-form requests. Instead of one long console, every request is a block with a name that you can fold, tag, save, search and run on its own.
Tabs
Work is organised in tabs (the first one is called Scratch). + adds a tab, double-click renames it. Tabs and their blocks are saved automatically and survive restarts. Closing a tab warns you about unsaved blocks; blocks saved to the library stay in the library.
Each tab can have:
- a Default target — an index, alias or data stream that is put in front of index-scoped paths. With a default target of
listings,POST _searchruns asPOST listings/_search. Blocks show (default target) when it’s applied. - an Env — the environment whose
{{variables}}are filled in when you run.
The toolbar also shows which connection requests go to (with a prod pill for production).
Request blocks
A block is written like a Kibana console request — the first line is METHOD path, the rest is the JSON body:
POST listings/_search
{
"query": { "match": { "title": "garden" } }
}
- Methods:
GET,POST,PUT,DELETE,HEAD,PATCH. - Click the block header to fold or unfold it; Collapse all / Expand all are in the toolbar.
- Click or double-click the title to rename (Untitled request by default). Add
#tagsfrom the block menu. - An
unsavedpill means the block isn’t in a library folder yet. Drag a block’s header onto a folder to save it there. - The header shows the line count, the last status and when it last ran.
- The ⋯ menu: Save to folder… / Rename / move / tags…, Rename, Duplicate, Copy as cURL, Move up, Move down, Delete block / Close (stays in library).
Edits are saved as you type.
Running
- ⌘↵ in a block runs that block. Outside an editor it runs the active block.
- Tick the checkboxes of several blocks and click ▶ Run N in order to run them as a sequence. A sequence stops at the first failure.
- ■ cancels a running request, including the search task on the cluster.
- Add to routine turns the selected blocks into routine steps.
Autocomplete
- Request line — methods, then endpoints from the Elasticsearch API specification, your index, alias and data stream names, and query parameters after
?. - Body — every key of the query DSL, plus the actual fields of the target index, with their types. Fields are ranked by context: keyword, numeric and date fields first in
term,range,sortand aggregations; text fields first inmatch. - Snippets — choosing a query or aggregation inserts a ready skeleton you can tab through, the way Kibana does. For example
terminserts"term": { "FIELD": { "value": "VALUE" } }and immediately suggests fields forFIELD. There are snippets for the common queries (bool,match,range,nested,function_score,geo_distance, …), aggregations (terms,date_histogram,composite,top_hits, …) and top-level keys (query,aggs,sort,highlight,collapse,search_after, …). {{variable}}placeholders are highlighted.
⌘I formats the block: JSON is pretty-printed; NDJSON bodies (_bulk, _msearch) keep one object per line.
Importing from Kibana or cURL
Click Import… and paste:
- an export of the Kibana Dev Tools console — every request becomes a block. A comment line directly above a request (
#,##,###or//) becomes the block’s title, and Kibana’s"""triple-quoted"""strings are converted to normal JSON; or - a single cURL command — any credentials in it are removed.
A preview shows what will be imported; click Import N requests.
Copy as cURL
Copy as cURL never includes your credentials. It uses placeholders instead — -u 'user:$ES_PASSWORD' or Authorization: ApiKey $ES_API_KEY — so you can paste it into a terminal and set the variable yourself.
The response pane
- The status code with its meaning, the time, size and when it ran.
- JSON or Table (for search results).
- Previous — the last five responses of a saved block, to compare runs. (Responses up to 512 KB are kept.)
- Export… — for search responses, export this page or every matching document. See Export.
- Copy.
The library sidebar
The left side of the workspace is your query library: folders, pins, recent runs, history and search.