Elastic Stack (ELK Stack) Enrich API
The enrich API from Elastic Stack (ELK Stack) — 4 operation(s) for enrich.
The enrich API from Elastic Stack (ELK Stack) — 4 operation(s) for enrich.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/elk-stack-enrich-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Elasticsearch Request & Response Specification Enrich API
license:
name: Apache 2.0
url: https://github.com/elastic/elasticsearch-specification/blob/main/LICENSE
version: ''
tags:
- name: enrich
paths:
/_enrich/policy/{name}:
get:
tags:
- enrich
summary: Get an enrich policy
description: Returns information about an enrich policy.
operationId: enrich-get-policy
parameters:
- $ref: '#/components/parameters/enrich.get_policy-name'
- $ref: '#/components/parameters/enrich.get_policy-master_timeout'
responses:
'200':
$ref: '#/components/responses/enrich.get_policy-200'
x-state: Generally available; Added in 7.5.0
x-metaTags:
- content: Elasticsearch
name: product_name
put:
tags:
- enrich
summary: Create an enrich policy
description: Creates an enrich policy.
operationId: enrich-put-policy
parameters:
- in: path
name: name
description: Name of the enrich policy to create or update.
required: true
deprecated: false
schema:
$ref: '#/components/schemas/_types.Name'
style: simple
- in: query
name: master_timeout
description: Period to wait for a connection to the master node.
deprecated: false
schema:
default: 30s
allOf:
- $ref: '#/components/schemas/_types.Duration'
style: form
requestBody:
content:
application/json:
schema:
type: object
properties:
geo_match:
description: Matches enrich data to incoming documents based on a `geo_shape` query.
allOf:
- $ref: '#/components/schemas/enrich._types.Policy'
match:
description: Matches enrich data to incoming documents based on a `term` query.
allOf:
- $ref: '#/components/schemas/enrich._types.Policy'
range:
description: Matches a number, date, or IP address in incoming documents to a range in the enrich index based on a `term` query.
allOf:
- $ref: '#/components/schemas/enrich._types.Policy'
examples:
EnrichPutPolicyExample1:
description: An example body for a `PUT /_enrich/policy/postal_policy` request.
value: "{\n \"geo_match\": {\n \"indices\": \"postal_codes\",\n \"match_field\": \"location\",\n \"enrich_fields\": [ \"location\", \"postal_code\" ]\n }\n}"
required: true
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/_types.AcknowledgedResponseBase'
x-state: Generally available; Added in 7.5.0
x-metaTags:
- content: Elasticsearch
name: product_name
delete:
tags:
- enrich
summary: Delete an enrich policy
description: Deletes an existing enrich policy and its enrich index.
operationId: enrich-delete-policy
parameters:
- in: path
name: name
description: Enrich policy to delete.
required: true
deprecated: false
schema:
$ref: '#/components/schemas/_types.Name'
style: simple
- in: query
name: master_timeout
description: Period to wait for a connection to the master node.
deprecated: false
schema:
default: 30s
allOf:
- $ref: '#/components/schemas/_types.Duration'
style: form
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/_types.AcknowledgedResponseBase'
x-state: Generally available; Added in 7.5.0
x-metaTags:
- content: Elasticsearch
name: product_name
/_enrich/policy/{name}/_execute:
put:
tags:
- enrich
summary: Run an enrich policy
description: Create the enrich index for an existing enrich policy.
operationId: enrich-execute-policy
parameters:
- in: path
name: name
description: Enrich policy to execute.
required: true
deprecated: false
schema:
$ref: '#/components/schemas/_types.Name'
style: simple
- in: query
name: master_timeout
description: Period to wait for a connection to the master node.
deprecated: false
schema:
default: 30s
allOf:
- $ref: '#/components/schemas/_types.Duration'
style: form
- in: query
name: wait_for_completion
description: If `true`, the request blocks other enrich policy execution requests until complete.
deprecated: false
schema:
default: true
type: boolean
style: form
responses:
'200':
description: ''
content:
application/json:
schema:
type: object
properties:
status:
allOf:
- $ref: '#/components/schemas/enrich.execute_policy.ExecuteEnrichPolicyStatus'
task:
allOf:
- $ref: '#/components/schemas/_types.TaskId'
x-state: Generally available; Added in 7.5.0
x-metaTags:
- content: Elasticsearch
name: product_name
/_enrich/policy:
get:
tags:
- enrich
summary: Get an enrich policy
description: Returns information about an enrich policy.
operationId: enrich-get-policy-1
parameters:
- $ref: '#/components/parameters/enrich.get_policy-master_timeout'
responses:
'200':
$ref: '#/components/responses/enrich.get_policy-200'
x-state: Generally available; Added in 7.5.0
x-metaTags:
- content: Elasticsearch
name: product_name
/_enrich/_stats:
get:
tags:
- enrich
summary: Get enrich stats
description: Returns enrich coordinator statistics and information about enrich policies that are currently executing.
operationId: enrich-stats
parameters:
- in: query
name: master_timeout
description: Period to wait for a connection to the master node.
deprecated: false
schema:
default: 30s
allOf:
- $ref: '#/components/schemas/_types.Duration'
style: form
responses:
'200':
description: ''
content:
application/json:
schema:
type: object
properties:
coordinator_stats:
description: Objects containing information about each coordinating ingest node for configured enrich processors.
type: array
items:
$ref: '#/components/schemas/enrich.stats.CoordinatorStats'
executing_policies:
description: Objects containing information about each enrich policy that is currently executing.
type: array
items:
$ref: '#/components/schemas/enrich.stats.ExecutingPolicy'
cache_stats:
description: Objects containing information about the enrich cache stats on each ingest node.
x-state: Generally available; Added in 7.16.0
type: array
items:
$ref: '#/components/schemas/enrich.stats.CacheStats'
required:
- coordinator_stats
- executing_policies
x-state: Generally available; Added in 7.5.0
x-metaTags:
- content: Elasticsearch
name: product_name
components:
schemas:
_types.query_dsl.SpanContainingQuery:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.QueryBase'
- type: object
properties:
big:
description: 'Can be any span query.
Matching spans from `big` that contain matches from `little` are returned.'
allOf:
- $ref: '#/components/schemas/_types.query_dsl.SpanQuery'
little:
description: 'Can be any span query.
Matching spans from `big` that contain matches from `little` are returned.'
allOf:
- $ref: '#/components/schemas/_types.query_dsl.SpanQuery'
required:
- big
- little
_types.query_dsl.TypeQuery:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.QueryBase'
- type: object
properties:
value:
type: string
required:
- value
_types.aggregations.TopHitsAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
- type: object
properties:
docvalue_fields:
description: Fields for which to return doc values.
type: array
items:
$ref: '#/components/schemas/_types.query_dsl.FieldAndFormat'
explain:
description: If `true`, returns detailed information about score computation as part of a hit.
default: false
type: boolean
fields:
description: 'Array of wildcard (*) patterns. The request returns values for field names
matching these patterns in the hits.fields property of the response.'
type: array
items:
$ref: '#/components/schemas/_types.query_dsl.FieldAndFormat'
from:
description: Starting document offset.
default: 0.0
type: number
highlight:
description: Specifies the highlighter to use for retrieving highlighted snippets from one or more fields in the search results.
allOf:
- $ref: '#/components/schemas/_global.search._types.Highlight'
script_fields:
description: Returns the result of one or more script evaluations for each hit.
type: object
additionalProperties:
$ref: '#/components/schemas/_types.ScriptField'
size:
description: The maximum number of top matching hits to return per bucket.
default: 3.0
type: number
sort:
description: 'Sort order of the top matching hits.
By default, the hits are sorted by the score of the main query.'
allOf:
- $ref: '#/components/schemas/_types.Sort'
_source:
description: Selects the fields of the source that are returned.
allOf:
- $ref: '#/components/schemas/_global.search._types.SourceConfig'
stored_fields:
description: Returns values for the specified stored fields (fields that use the `store` mapping option).
allOf:
- $ref: '#/components/schemas/_types.Fields'
track_scores:
description: If `true`, calculates and returns document scores, even if the scores are not used for sorting.
default: false
type: boolean
version:
description: If `true`, returns document version as part of a hit.
default: false
type: boolean
seq_no_primary_term:
description: If `true`, returns sequence number and primary term of the last modification of each hit.
type: boolean
_types.aggregations.BucketSelectorAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
- type: object
properties:
script:
description: The script to run for this aggregation.
allOf:
- $ref: '#/components/schemas/_types.Script'
_types.query_dsl.CombinedFieldsZeroTerms:
type: string
enum:
- none
- all
_types.aggregations.TermsPartition:
type: object
properties:
num_partitions:
description: The number of partitions.
type: number
partition:
description: The partition number for this request.
type: number
required:
- num_partitions
- partition
_types.query_dsl.GeoBoundingBoxQuery:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.QueryBase'
- type: object
properties:
type:
deprecated: true
allOf:
- $ref: '#/components/schemas/_types.query_dsl.GeoExecution'
validation_method:
description: 'Set to `IGNORE_MALFORMED` to accept geo points with invalid latitude or longitude.
Set to `COERCE` to also try to infer correct latitude or longitude.'
default: '''strict'''
allOf:
- $ref: '#/components/schemas/_types.query_dsl.GeoValidationMethod'
ignore_unmapped:
description: 'Set to `true` to ignore an unmapped field and not match any documents for this query.
Set to `false` to throw an exception if the field is not mapped.'
default: false
type: boolean
_types.SortResults:
type: array
items:
$ref: '#/components/schemas/_types.FieldValue'
_types.aggregations.BucketCorrelationFunctionCountCorrelationIndicator:
type: object
properties:
doc_count:
description: 'The total number of documents that initially created the expectations. It’s required to be greater
than or equal to the sum of all values in the buckets_path as this is the originating superset of data
to which the term values are correlated.'
type: number
expectations:
description: 'An array of numbers with which to correlate the configured `bucket_path` values.
The length of this value must always equal the number of buckets returned by the `bucket_path`.'
type: array
items:
type: number
fractions:
description: 'An array of fractions to use when averaging and calculating variance. This should be used if
the pre-calculated data and the buckets_path have known gaps. The length of fractions, if provided,
must equal expectations.'
type: array
items:
type: number
required:
- doc_count
- expectations
_types.aggregations.ChildrenAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
- type: object
properties:
type:
description: The child type that should be selected.
allOf:
- $ref: '#/components/schemas/_types.RelationName'
_types.EpochTimeUnitMillis:
allOf:
- $ref: '#/components/schemas/_types.UnitMillis'
_types.aggregations.MatrixAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.Aggregation'
- type: object
properties:
fields:
description: An array of fields for computing the statistics.
allOf:
- $ref: '#/components/schemas/_types.Fields'
missing:
description: 'The value to apply to documents that do not have a value.
By default, documents without a value are ignored.'
type: object
additionalProperties:
type: number
_types.query_dsl.DisMaxQuery:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.QueryBase'
- type: object
properties:
queries:
description: 'One or more query clauses.
Returned documents must match one or more of these queries.
If a document matches multiple queries, Elasticsearch uses the highest relevance score.'
type: array
items:
$ref: '#/components/schemas/_types.query_dsl.QueryContainer'
tie_breaker:
description: Floating point number between 0 and 1.0 used to increase the relevance scores of documents matching multiple query clauses.
default: 0.0
type: number
required:
- queries
_types.aggregations.SamplerAggregationExecutionHint:
type: string
enum:
- map
- global_ordinals
- bytes_hash
_types.aggregations.MovingPercentilesAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
- type: object
properties:
window:
description: The size of window to "slide" across the histogram.
type: number
shift:
description: 'By default, the window consists of the last n values excluding the current bucket.
Increasing `shift` by 1, moves the starting window position by 1 to the right.'
default: 0.0
type: number
keyed:
type: boolean
_types.aggregations.HoltWintersModelSettings:
type: object
properties:
alpha:
type: number
beta:
type: number
gamma:
type: number
pad:
type: boolean
period:
type: number
type:
allOf:
- $ref: '#/components/schemas/_types.aggregations.HoltWintersType'
_types.aggregations.HistogramAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
- type: object
properties:
extended_bounds:
description: Enables extending the bounds of the histogram beyond the data itself.
allOf:
- $ref: '#/components/schemas/_types.aggregations.ExtendedBoundsdouble'
hard_bounds:
description: 'Limits the range of buckets in the histogram.
It is particularly useful in the case of open data ranges that can result in a very large number of buckets.'
allOf:
- $ref: '#/components/schemas/_types.aggregations.ExtendedBoundsdouble'
field:
description: The name of the field to aggregate on.
allOf:
- $ref: '#/components/schemas/_types.Field'
interval:
description: 'The interval for the buckets.
Must be a positive decimal.'
type: number
min_doc_count:
description: 'Only returns buckets that have `min_doc_count` number of documents.
By default, the response will fill gaps in the histogram with empty buckets.'
type: number
missing:
description: 'The value to apply to documents that do not have a value.
By default, documents without a value are ignored.'
type: number
offset:
description: 'By default, the bucket keys start with 0 and then continue in even spaced steps of `interval`.
The bucket boundaries can be shifted by using the `offset` option.'
type: number
order:
description: 'The sort order of the returned buckets.
By default, the returned buckets are sorted by their key ascending.'
allOf:
- $ref: '#/components/schemas/_types.aggregations.AggregateOrder'
script:
allOf:
- $ref: '#/components/schemas/_types.Script'
format:
type: string
keyed:
description: If `true`, returns buckets as a hash instead of an array, keyed by the bucket keys.
default: false
type: boolean
_types.GeoTilePrecision:
type: number
_types.aggregations.DateRangeAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
- type: object
properties:
field:
description: The date field whose values are use to build ranges.
allOf:
- $ref: '#/components/schemas/_types.Field'
format:
description: The date format used to format `from` and `to` in the response.
type: string
missing:
description: 'The value to apply to documents that do not have a value.
By default, documents without a value are ignored.'
allOf:
- $ref: '#/components/schemas/_types.aggregations.Missing'
ranges:
description: Array of date ranges.
type: array
items:
$ref: '#/components/schemas/_types.aggregations.DateRangeExpression'
time_zone:
description: Time zone used to convert dates from another time zone to UTC.
allOf:
- $ref: '#/components/schemas/_types.TimeZone'
keyed:
description: Set to `true` to associate a unique string key with each bucket and returns the ranges as a hash rather than an array.
type: boolean
_types.aggregations.StringStatsAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
- type: object
properties:
show_distribution:
description: Shows the probability distribution for all characters.
default: false
type: boolean
_types.aggregations.TTestType:
type: string
enum:
- paired
- homoscedastic
- heteroscedastic
_types.TextSimilarityReranker:
allOf:
- $ref: '#/components/schemas/_types.RetrieverBase'
- type: object
properties:
retriever:
description: The nested retriever which will produce the first-level results, that will later be used for reranking.
allOf:
- $ref: '#/components/schemas/_types.RetrieverContainer'
rank_window_size:
description: This value determines how many documents we will consider from the nested retriever.
type: number
inference_id:
description: Unique identifier of the inference endpoint created using the inference API.
type: string
inference_text:
description: The text snippet used as the basis for similarity comparison.
type: string
field:
description: The document field to be used for text similarity comparisons. This field should contain the text that will be evaluated against the inference_text.
type: string
chunk_rescorer:
description: Whether to rescore on only the best matching chunks.
x-state: Generally available; Added in 9.2.0
allOf:
- $ref: '#/components/schemas/_types.ChunkRescorer'
required:
- retriever
- inference_text
- field
_types.aggregations.ParentAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
- type: object
properties:
type:
description: The child type that should be selected.
allOf:
- $ref: '#/components/schemas/_types.RelationName'
_types.aggregations.MaxBucketAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
- type: object
_global.search._types.FieldCollapse:
type: object
properties:
field:
description: The field to collapse the result set on
allOf:
- $ref: '#/components/schemas/_types.Field'
inner_hits:
description: The number of inner hits and their sort order
oneOf:
- $ref: '#/components/schemas/_global.search._types.InnerHits'
- type: array
items:
$ref: '#/components/schemas/_global.search._types.InnerHits'
max_concurrent_group_searches:
description: The number of concurrent requests allowed to retrieve the inner_hits per group
type: number
collapse:
allOf:
- $ref: '#/components/schemas/_global.search._types.FieldCollapse'
required:
- field
_types.DateTime:
description: 'A date and time, either as a string whose format can depend on the context (defaulting to ISO 8601), or a
number of milliseconds since the Epoch. Elasticsearch accepts both as input, but will generally output a string
representation.'
oneOf:
- type: string
- $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
_types.query_dsl.RangeQueryBase:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.QueryBase'
- type: object
properties:
relation:
description: Indicates how the range query matches values for `range` fields.
default: intersects
allOf:
- $ref: '#/components/schemas/_types.query_dsl.RangeRelation'
gt:
description: Greater than.
type: object
gte:
description: Greater than or equal to.
type: object
lt:
description: Less than.
type: object
lte:
description: Less than or equal to.
type: object
_types.query_dsl.NumericDecayFunction:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.DecayFunctionBasedoubledouble'
- type: object
_types.aggregations.FormattableMetricAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
- type: object
properties:
format:
type: string
_types.query_dsl.UntypedRangeQuery:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.RangeQueryBase'
- type: object
properties:
format:
description: Date format used to convert `date` values in the query.
allOf:
- $ref: '#/components/schemas/_types.DateFormat'
time_zone:
description: Coordinated Universal Time (UTC) offset or IANA time zone used to convert `date` values in the query to UTC.
allOf:
- $ref: '#/components/schemas/_types.TimeZone'
_types.IndexName:
type: string
_types.aggregations.GeoLineSort:
type: object
properties:
field:
description: The name of the numeric field to use as the sort key for ordering the points.
allOf:
- $ref: '#/components/schemas/_types.Field'
required:
- field
_types.aggregations.MultiTermLookup:
allOf:
- type: object
properties:
missing:
description: 'The value to apply to documents that do not have a value.
By default, documents without a value are ignored.'
allOf:
- $ref: '#/components/schemas/_types.aggregations.Missing'
- type: object
properties:
field:
description: 'A field from which to retrieve terms.
It is required if `script` is not provided.'
allOf:
- $ref: '#/components/schemas/_types.Field'
script:
description: 'A script to calculate terms to aggregate on.
It is required if `field` is not provided.'
allOf:
- $ref: '#/components/schemas/_types.Script'
minProperties: 1
maxProperties: 1
_types.query_dsl.DecayFunctionBaseGeoLocationDistance:
type: object
properties:
multi_value_mode:
description: Determines how the distance is calculated when a field used for computing the decay contains multiple values.
default: min
allOf:
- $ref: '#/components/schemas/_types.query_dsl.MultiValueMode'
_types.aggregations.CompositeAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
- type: object
properties:
after:
description: When paginating, use the `after_key` value returned in the previous response to retrieve the next page.
allOf:
- $ref: '#/components/schemas/_types.aggregations.CompositeAggregateKey'
size:
description: The number of composite buckets that should be returned.
default: 10.0
type: number
sources:
description: 'The value sources used to build composite buckets.
Keys are returned in the order of the `sources` definition.'
type: array
items:
type: object
additionalProperties:
$ref: '#/components/schemas/_types.aggregations.CompositeAggregationSource'
minProperties: 1
maxProperties: 1
enrich.stats.CoordinatorStats:
type: object
properties:
executed_searches_total:
type: number
node_id:
allOf:
- $ref: '#/components/schemas/_types.Id'
queue_size:
type: number
remote_requests_current:
type: number
remote_requests_total:
type: number
required:
- executed_searches_total
- node_id
- queue_size
- remote_requests_current
- remote_requests_total
_types.query_dsl.SemanticQuery:
allOf:
- $ref: '#/components/schemas/_types.query_dsl.QueryBase'
- type: object
properties:
field:
description: The field to query, which must be a semantic_text field type
type: string
query:
description: The query text
type: string
required:
- field
- query
_types.aggregations.InferenceAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
- type: object
properties:
model_id:
description: The ID or alias for the trained model.
allOf:
- $ref: '#/components/schemas/_types.Name'
inference_config:
description: Contains the inference type and its options.
allOf:
- $ref: '#/components/schemas/_types.aggregations.InferenceConfigContainer'
required:
- model_id
_types.aggregations.HoltWintersMovingAverageAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.MovingAverageAggregationBase'
- type: object
properties:
model:
type: string
enum:
- holt_winters
settings:
allOf:
- $ref: '#/components/schemas/_types.aggregations.HoltWintersModelSettings'
required:
- model
- settings
_types.query_dsl.TextQueryType:
type: string
enum:
- best_fields
- most_fields
- cross_fields
- phrase
- phrase_prefix
- bool_prefix
_types.analysis.StopWords:
description: 'Language value, such as _arabic_ or _thai_. Defaults to _english_.
Each language value corresponds to a predefined list of stop words in Lucene. See Stop words by language for supported language values and their stop words.
Also accepts an array of stop words.'
oneOf:
- $ref: '#/components/schemas/_types.analysis.StopWordLanguage'
- type: array
items:
type: string
_types.aggregations.ScriptedMetricAggregation:
allOf:
- $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
- type: object
properties:
combine_script:
description: 'Runs once on each shard after document collection is complete.
Allows the aggregation to consolidate the state returned from each shard.'
allOf:
- $ref: '#/components/schemas/_types.Script'
init_script:
description: 'Runs prior to any collection of documents.
Allows the aggregation to set up any initial state.'
allOf:
- $ref: '#/components/schemas/_types.Script'
map_script:
description: 'Run once per document collected.
If no `combine_script` is specified, the resultin
# --- truncated at 32 KB (336 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/openapi/elk-stack-enrich-api-openapi.yml