Docs
  • Release notes
  • Troubleshoot
  • Reference
  1. Docs /
  2. Reference /
  3. Elastic CLI /
  4. Command reference

docs cli namespace

elastic docs --help
		

Search, read, and ask questions about Elastic documentation

Commands

search

Search Elastic documentation

ask

Ask a question about Elastic documentation using AI (single answer)

read

Read an Elastic documentation page

Namespace Flags

--input-file string
path to a JSON file to use as command input
--dry-run

validate all inputs and exit without performing any action (preview changes without applying them)

Previous
patch-traffic-filter
Next
search
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
On this page
  • Commands
  • Namespace Flags
  • Elastic fundamentals
  • Solutions and use cases
  • Manage data
  • Explore and analyze
  • Deploy and manage
  • Manage your Cloud account
  • Troubleshoot
  • Release notes
  • Reference
  • Extend and contribute
  • Contribute to the docs
  • Elasticsearch
    • Configuration
      • Circuit breaker settings
      • Auditing settings
      • Enrich settings
      • Cluster-level shard allocation and routing settings
      • Miscellaneous cluster settings
      • Cross-cluster replication settings
      • Discovery and cluster formation settings
      • Field data cache settings
      • Health Diagnostic settings
      • Index lifecycle management settings
      • Data stream lifecycle settings
      • Index management settings
      • Index recovery settings
      • Indexing buffer settings
      • Indexing pressure
      • Ingest settings
      • License settings
      • Local gateway
      • Machine learning settings
      • Inference settings
      • Monitoring settings
      • Node settings
      • Path settings
      • Networking settings
      • Node query cache settings
      • Remote cluster settings
      • Search settings
      • Security settings
      • Cluster state encryption
      • Shard request cache
      • Snapshot and restore settings
        • S3 repository
        • Azure repository
        • GCS repository
        • Shared file system repository
        • Read-only URL repository
        • Source-only repository
      • Transforms settings
      • Thread pool settings
      • Watcher settings
    • JVM settings
    • Built-in roles
    • Elasticsearch privileges
    • Columnar
    • Index settings
      • Serverless index settings
      • General
      • Shard allocation
        • Data tier allocation
        • Index recovery prioritization
        • Total shards per node
      • History retention
      • Index blocks
      • Mapping limit
      • Merge
      • Similarity
      • Slow log
      • Sorting
        • Use index sorting to speed up conjunctions
      • Store
        • Preloading data into the file system cache
      • Time series
      • Source settings
      • Translog
    • Index lifecycle actions
      • Allocate
      • Delete
      • Force merge
      • Migrate
      • Read only
      • Rollover
      • Downsample
      • Searchable snapshot
      • Set priority
      • Shrink
      • Unfollow
      • Wait for snapshot
    • REST APIs
      • API conventions
      • Common options
      • Compatibility
      • Guides and examples
        • Collapse search results
        • Create index from source
        • Understand the lifecycle status
        • Filter search results
        • Rescore search results
        • Find text structure API examples
        • Highlighting
          • Highlighting settings
          • Highlighting examples
          • How highlighters work internally
        • Analyze index disk usage
        • Optimistic concurrency control
        • Paginate search results
        • Query API key information
        • Reciprocal rank fusion
        • The refresh parameter
        • Reindex data stream
        • Reindex indices
        • Retrieve inner hits
        • Retrieve selected fields
        • Retrieve stored fields
        • Retrievers
          • kNN retriever
          • Linear retriever
          • Pinned retriever
          • Rescorer retriever
          • RRF retriever
          • Query rules retriever
          • Standard retriever
          • Text similarity re-ranker retriever
          • Diversify retriever
          • Examples
        • Search multiple data streams and indices
        • Profile search requests
        • Ranking evaluation
        • Search shard routing
        • Suggesters
        • Sort search results
        • Searching with query rules
        • The shard request cache
        • Term vectors API examples
        • Update By Query API
        • Update a document
        • Update cross-cluster API examples
        • Vector tile search API
    • Mapping
      • Document metadata fields
        • _doc_count field
        • _field_names field
        • _ignored field
        • _id field
        • _index field
        • _meta field
        • _routing field
        • _source field
        • _tier field
      • Field data types
        • Aggregate metric
        • Alias
        • Arrays
        • Binary
        • Boolean
        • Completion
        • Date
        • Date nanoseconds
        • Dense vector
        • Flattened
        • Geopoint
        • Geoshape
        • Histogram
        • Exponential histogram
        • T-digest
        • IP
        • Join
        • Keyword
        • Nested
        • Numeric
        • Object
        • Pass-through object
        • Percolator
        • Point
        • Range
        • Rank feature
        • Rank features
        • Rank vectors
        • Search-as-you-type
        • Semantic
          • Reference
        • Semantic text
          • Reference
          • How-to guides
            • Set up and configure
            • Ingest data
            • Search and retrieve
        • Shape
        • Sparse vector
        • Text type family
          • Text
          • Pattern Text
          • Match Only Text
        • Token count
        • Unsigned long
        • Version
      • Mapping parameters
        • analyzer
        • coerce
        • copy_to
        • doc_values
        • dynamic
        • eager_global_ordinals
        • enabled
        • format
        • ignore_above
        • ignore_above index setting
        • ignore_malformed
        • index
        • index_options
        • index_phrases
        • index_prefixes
        • meta
        • fields
        • normalizer
        • norms
        • null_value
        • position_increment_gap
        • properties
        • search_analyzer
        • similarity
        • store
        • subobjects
        • term_vector
        • Better Binary Quantization (BBQ)
    • Elasticsearch audit events
    • Command-line tools
      • elasticsearch-certgen
      • elasticsearch-certutil
      • elasticsearch-create-enrollment-token
      • elasticsearch-croneval
      • elasticsearch-keystore
      • elasticsearch-node
      • elasticsearch-reconfigure-node
      • elasticsearch-reset-password
      • elasticsearch-saml-metadata
      • elasticsearch-service-tokens
      • elasticsearch-setup-passwords
      • elasticsearch-shard
      • elasticsearch-syskeygen
      • elasticsearch-users
    • Query languages
      • Query DSL
        • Get started
        • Query and filter context
        • Compound queries
          • Boolean
          • Boosting
          • Constant score
          • Disjunction max
          • Function score
        • Full text queries
          • Intervals
          • Match
          • Match boolean prefix
          • Match phrase
          • Match phrase prefix
          • Combined fields
          • Multi-match
          • Query string
          • Simple query string
          • KQL
        • Geo queries
          • Geo-bounding box
          • Geo-distance
          • Geo-grid
          • Geo-polygon
          • Geoshape
        • Shape queries
          • Shape
        • Joining queries
          • Nested
          • Has child
          • Has parent
          • Parent ID
        • Match all
        • Span queries
          • Span containing
          • Span field masking
          • Span first
          • Span multi-term
          • Span near
          • Span not
          • Span or
          • Span term
          • Span within
        • Vector queries
          • Knn
          • Dense vector
          • Sparse vector
          • Semantic
          • Text expansion
          • Weighted tokens
        • Specialized queries
          • Distance feature
          • more_like_this
          • Percolate
          • Rank feature
          • Script
          • Script score
          • Wrapper
          • Pinned query
          • Rule
        • Term-level queries
          • Bitmap terms
          • Exists
          • Fuzzy
          • IDs
          • Prefix
          • Range
          • Regexp
          • Term
          • Terms
          • Terms set
          • Wildcard
        • minimum_should_match parameter
        • rewrite parameter
        • Regular expression syntax
      • ES|QL
        • Get started
        • Use cases
          • ES|QL for search
          • ES|QL for cybersecurity
        • REST API
        • Syntax reference
          • Basic syntax
          • Query directives
            • SET
          • Commands
            • Source commands
              • FROM
              • PROMQL
              • ROW
              • SHOW
              • TS
            • Processing commands
              • CHANGE_POINT
              • COMPLETION
              • DEDUP
              • DISSECT
              • DROP
              • ENRICH
              • EVAL
              • FORK
              • FUSE
              • GROK
              • HIGHLIGHT
              • INLINE STATS
              • IP_LOCATION
              • KEEP
              • LIMIT
              • LOOKUP JOIN
              • METRICS_INFO
              • MMR
              • MV_EXPAND
              • REGISTERED_DOMAIN
              • RENAME
              • RERANK
              • SAMPLE
              • SORT
              • STATS
              • TS_INFO
              • TS_COLLAPSE
              • USER_AGENT
              • URI_PARTS
              • WHERE
          • Functions and operators
            • Aggregation functions
              • ABSENT
              • AVG
              • COUNT
              • COUNT_DISTINCT
              • EARLIEST
              • FIRST
              • LAST
              • LATEST
              • MAX
              • MEDIAN
              • MEDIAN_ABSOLUTE_DEVIATION
              • MIN
              • PERCENTILE
              • PRESENT
              • SAMPLE
              • SPARKLINE
              • ST_CENTROID_AGG
              • ST_EXTENT_AGG
              • STD_DEV
              • SUM
              • TOP
              • VALUES
              • VARIANCE
              • WEIGHTED_AVG
            • Time series aggregation functions
              • ABSENT_OVER_TIME
              • AVG_OVER_TIME
              • COUNT_OVER_TIME
              • COUNT_DISTINCT_OVER_TIME
              • DELTA
              • DERIV
              • FIRST_OVER_TIME
              • IDELTA
              • INCREASE
              • IRATE
              • LAST_OVER_TIME
              • MAX_OVER_TIME
              • MIN_OVER_TIME
              • PERCENTILE_OVER_TIME
              • PRESENT_OVER_TIME
              • RATE
              • STDDEV_OVER_TIME
              • VARIANCE_OVER_TIME
              • SUM_OVER_TIME
            • Grouping functions
              • BUCKET
              • TBUCKET
              • CATEGORIZE
              • WITHOUT
            • Conditional functions and expressions
              • CASE
              • COALESCE
              • GREATEST
              • LEAST
              • CLAMP
              • CLAMP_MIN
              • CLAMP_MAX
            • Date-time functions
              • DATE_DIFF
              • DATE_EXTRACT
              • DATE_FORMAT
              • DATE_PARSE
              • DATE_TRUNC
              • DAY_NAME
              • MONTH_NAME
              • NOW
              • RANGE_MAX
              • RANGE_MIN
              • RANGE_WITHIN
              • RANGE_CONTAINS
              • RANGE_INTERSECTS
              • TRANGE
            • IP functions
              • CIDR_MATCH
              • IP_PREFIX
            • Math functions
              • ABS
              • ACOS
              • ACOSH
              • ASIN
              • ASINH
              • ATAN
              • ATAN2
              • ATANH
              • CBRT
              • CEIL
              • COPY_SIGN
              • COS
              • COSH
              • E
              • EXP
              • FLOOR
              • HYPOT
              • LOG
              • LOG10
              • PI
              • POW
              • ROUND
              • ROUND_TO
              • SCALB
              • SIGNUM
              • SIN
              • SINH
              • SQRT
              • TAN
              • TANH
              • TAU
            • Search functions
              • DECAY
              • KQL
              • MATCH
              • MATCH_PHRASE
              • QSTR
              • SCORE
              • TOP_SNIPPETS
            • Spatial functions
              • ST_DISTANCE
              • ST_INTERSECTS
              • ST_DISJOINT
              • ST_CONTAINS
              • ST_WITHIN
              • ST_X
              • ST_Y
              • ST_NPOINTS
              • ST_BUFFER
              • ST_SIMPLIFY
              • ST_SIMPLIFYPRESERVETOPOLOGY
              • ST_GEOMETRYTYPE
              • ST_DIMENSION
              • ST_ISEMPTY
              • ST_UNION
              • ST_INTERSECTION
              • ST_DIFFERENCE
              • ST_SYMDIFFERENCE
              • ST_ENVELOPE
              • ST_XMAX
              • ST_XMIN
              • ST_YMAX
              • ST_YMIN
              • ST_GEOTILE
              • ST_GEOHEX
              • ST_GEOHASH
            • String functions
              • BIT_LENGTH
              • BYTE_LENGTH
              • CHUNK
              • CONCAT
              • CONTAINS
              • ENDS_WITH
              • FIELD_EXTRACT
              • FROM_BASE64
              • HASH
              • JSON_EXTRACT
              • JSON_STRING
              • LEFT
              • LENGTH
              • LOCATE
              • LTRIM
              • MD5
              • REPEAT
              • REPLACE
              • REVERSE
              • RIGHT
              • RTRIM
              • SHA1
              • SHA256
              • SPACE
              • SPLIT
              • STARTS_WITH
              • SUBSTRING
              • TO_BASE64
              • TO_LOWER
              • TO_UPPER
              • TRIM
              • URL_ENCODE
              • URL_ENCODE_COMPONENT
              • URL_DECODE
            • Dense vector functions
              • EMBEDDING
              • KNN
              • TEXT_EMBEDDING
              • V_COSINE
              • V_DOT_PRODUCT
              • V_HAMMING
              • V_L1_NORM
              • V_L2_NORM
            • Type conversion functions
              • TO_AGGREGATE_METRIC_DOUBLE
              • TO_BOOLEAN
              • TO_CARTESIANPOINT
              • TO_CARTESIANSHAPE
              • TO_COUNTER
              • TO_DATEPERIOD
              • TO_DATETIME
              • TO_DATE_NANOS
              • TO_DATE_RANGE
              • TO_DEGREES
              • TO_DENSE_VECTOR
              • TO_DOUBLE
              • TO_DOUBLE_RANGE
              • TO_EXPONENTIAL_HISTOGRAM
              • TO_GAUGE
              • TO_GEOHASH
              • TO_GEOHEX
              • TO_GEOPOINT
              • TO_GEOSHAPE
              • TO_GEOTILE
              • TO_INTEGER
              • TO_IP
              • TO_LONG
              • TO_RADIANS
              • TO_RANGE
              • TO_STRING
              • TO_TDIGEST
              • TO_TEXT
              • TO_TIMEDURATION
              • TO_UNSIGNED_LONG
              • TO_VERSION
            • Multivalue functions
              • MV_APPEND
              • MV_AVG
              • MV_CONCAT
              • MV_CONTAINS
              • MV_COUNT
              • MV_DEDUPE
              • MV_DIFFERENCE
              • MV_FIRST
              • MV_GREATER
              • MV_IN_RANGE
              • MV_INTERSECTION
              • MV_INTERSECTS
              • MV_LAST
              • MV_LESS
              • MV_LIKE
              • MV_MAX
              • MV_MEDIAN
              • MV_MEDIAN_ABSOLUTE_DEVIATION
              • MV_MIN
              • MV_PERCENTILE
              • MV_PSERIES_WEIGHTED_SUM
              • MV_RLIKE
              • MV_SLICE
              • MV_SORT
              • MV_SUM
              • MV_UNION
              • MV_ZIP
            • Operators
        • Optimize query performance
          • Approximate STATS queries
        • Query multiple sources
          • Query multiple indices
          • Query across clusters
          • Query across serverless projects
        • Combine and reuse queries
          • Subqueries
            • Subqueries with FROM
            • Subqueries with IN / NOT IN
          • Views
        • Data Federation
          • Quickstart
          • Connect data sources
            • AWS federated identity
            • AWS static credentials
          • Add datasets
            • Resource patterns
          • Query datasets
          • Manage access
          • Cluster settings
        • Advanced workflows
          • Extract data with DISSECT and GROK
          • Combine data with ENRICH
          • Join data with LOOKUP JOIN
        • Types and fields
          • Implicit casting
          • Time spans
          • Flattened fields
          • Metadata fields
          • NULL values
          • Multivalued fields
          • Histogram fields
          • Unmapped fields
        • Tutorials
          • ES|QL for search
          • ES|QL for threat hunting
        • Troubleshooting
          • Query log