Elastic Stack (ELK Stack) Eql API

The eql API from Elastic Stack (ELK Stack) — 3 operation(s) for eql.

Operations 5

GET /_eql/search/{id} Get async EQL search results #
DELETE /_eql/search/{id} Delete an async EQL search #
GET /_eql/search/status/{id} Get the async EQL status #
POST /{index}/_eql/search Get EQL search results #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/elk-stack-eql-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

elk-stack-eql-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Elasticsearch Request & Response Specification Eql API
  license:
    name: Apache 2.0
    url: https://github.com/elastic/elasticsearch-specification/blob/main/LICENSE
  version: ''
tags:
- name: eql
paths:
  /_eql/search/{id}:
    get:
      tags:
      - eql
      summary: Get async EQL search results
      description: Get the current status and available results for an async EQL search or a stored synchronous EQL search.
      operationId: eql-get
      parameters:
      - in: path
        name: id
        description: Identifier for the search.
        required: true
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Id'
        style: simple
      - in: query
        name: keep_alive
        description: 'Period for which the search and its results are stored on the cluster.

          Defaults to the keep_alive value set by the search’s EQL search API request.'
        deprecated: false
        schema:
          default: 5d
          allOf:
          - $ref: '#/components/schemas/_types.Duration'
        style: form
      - in: query
        name: wait_for_completion_timeout
        description: 'Timeout duration to wait for the request to finish.

          Defaults to no timeout, meaning the request waits for complete search results.'
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Duration'
        style: form
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/eql._types.EqlSearchResponseBase'
      x-state: Generally available; Added in 7.9.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
    delete:
      tags:
      - eql
      summary: Delete an async EQL search
      description: 'Delete an async EQL search or a stored synchronous EQL search.

        The API also deletes results for the search.'
      operationId: eql-delete
      parameters:
      - in: path
        name: id
        description: 'Identifier for the search to delete.

          A search ID is provided in the EQL search API''s response for an async search.

          A search ID is also provided if the request’s `keep_on_completion` parameter is `true`.'
        required: true
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Id'
        style: simple
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/_types.AcknowledgedResponseBase'
      x-state: Generally available; Added in 7.9.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /_eql/search/status/{id}:
    get:
      tags:
      - eql
      summary: Get the async EQL status
      description: Get the current status for an async EQL search or a stored synchronous EQL search without returning results.
      operationId: eql-get-status
      parameters:
      - in: path
        name: id
        description: Identifier for the search.
        required: true
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Id'
        style: simple
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    description: Identifier for the search.
                    allOf:
                    - $ref: '#/components/schemas/_types.Id'
                  is_partial:
                    description: If true, the search request is still executing. If false, the search is completed.
                    type: boolean
                  is_running:
                    description: If true, the response does not contain complete search results. This could be because either the search is still running (is_running status is false), or because it is already completed (is_running status is true) and results are partial due to failures or timeouts.
                    type: boolean
                  start_time_in_millis:
                    description: For a running search shows a timestamp when the eql search started, in milliseconds since the Unix epoch.
                    allOf:
                    - $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
                  expiration_time_in_millis:
                    description: Shows a timestamp when the eql search will be expired, in milliseconds since the Unix epoch. When this time is reached, the search and its results are deleted, even if the search is still ongoing.
                    allOf:
                    - $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
                  completion_status:
                    description: For a completed search shows the http status code of the completed search.
                    type: number
                required:
                - id
                - is_partial
                - is_running
              examples:
                EqlGetStatusResponseExample1:
                  description: A successful response for getting status information for an async EQL search.
                  value: "{\n  \"id\": \"FmNJRUZ1YWZCU3dHY1BIOUhaenVSRkEaaXFlZ3h4c1RTWFNocDdnY2FSaERnUTozNDE=\",\n  \"is_running\" : true,\n  \"is_partial\" : true,\n  \"start_time_in_millis\" : 1611690235000,\n  \"expiration_time_in_millis\" : 1611690295000\n}"
      x-state: Generally available; Added in 7.9.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /{index}/_eql/search:
    get:
      tags:
      - eql
      summary: Get EQL search results
      description: 'Returns search results for an Event Query Language (EQL) query.

        EQL assumes each document in a data stream or index corresponds to an event.'
      externalDocs:
        description: Learn more about EQL
        url: https://www.elastic.co/docs/explore-analyze/query-filter/languages/eql
        x-previousVersionUrl: https://www.elastic.co/guide/en/elasticsearch/reference/8.19/eql-search-api.html
      operationId: eql-search
      parameters:
      - $ref: '#/components/parameters/eql.search-index'
      - $ref: '#/components/parameters/eql.search-allow_no_indices'
      - $ref: '#/components/parameters/eql.search-allow_partial_search_results'
      - $ref: '#/components/parameters/eql.search-allow_partial_sequence_results'
      - $ref: '#/components/parameters/eql.search-expand_wildcards'
      - $ref: '#/components/parameters/eql.search-ccs_minimize_roundtrips'
      - $ref: '#/components/parameters/eql.search-ignore_unavailable'
      - $ref: '#/components/parameters/eql.search-keep_alive'
      - $ref: '#/components/parameters/eql.search-keep_on_completion'
      - $ref: '#/components/parameters/eql.search-wait_for_completion_timeout'
      requestBody:
        $ref: '#/components/requestBodies/eql.search'
      responses:
        '200':
          $ref: '#/components/responses/eql.search-200'
      x-state: Generally available; Added in 7.9.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
    post:
      tags:
      - eql
      summary: Get EQL search results
      description: 'Returns search results for an Event Query Language (EQL) query.

        EQL assumes each document in a data stream or index corresponds to an event.'
      externalDocs:
        description: Learn more about EQL
        url: https://www.elastic.co/docs/explore-analyze/query-filter/languages/eql
        x-previousVersionUrl: https://www.elastic.co/guide/en/elasticsearch/reference/8.19/eql-search-api.html
      operationId: eql-search-1
      parameters:
      - $ref: '#/components/parameters/eql.search-index'
      - $ref: '#/components/parameters/eql.search-allow_no_indices'
      - $ref: '#/components/parameters/eql.search-allow_partial_search_results'
      - $ref: '#/components/parameters/eql.search-allow_partial_sequence_results'
      - $ref: '#/components/parameters/eql.search-expand_wildcards'
      - $ref: '#/components/parameters/eql.search-ccs_minimize_roundtrips'
      - $ref: '#/components/parameters/eql.search-ignore_unavailable'
      - $ref: '#/components/parameters/eql.search-keep_alive'
      - $ref: '#/components/parameters/eql.search-keep_on_completion'
      - $ref: '#/components/parameters/eql.search-wait_for_completion_timeout'
      requestBody:
        $ref: '#/components/requestBodies/eql.search'
      responses:
        '200':
          $ref: '#/components/responses/eql.search-200'
      x-state: Generally available; Added in 7.9.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
components:
  schemas:
    _types.query_dsl.SpanContainingQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          big:
            description: 'Can be any span query.

              Matching spans from `big` that contain matches from `little` are returned.'
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.SpanQuery'
          little:
            description: 'Can be any span query.

              Matching spans from `big` that contain matches from `little` are returned.'
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.SpanQuery'
        required:
        - big
        - little
    _types.query_dsl.TypeQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          value:
            type: string
        required:
        - value
    _types.aggregations.TopHitsAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
      - type: object
        properties:
          docvalue_fields:
            description: Fields for which to return doc values.
            type: array
            items:
              $ref: '#/components/schemas/_types.query_dsl.FieldAndFormat'
          explain:
            description: If `true`, returns detailed information about score computation as part of a hit.
            default: false
            type: boolean
          fields:
            description: 'Array of wildcard (*) patterns. The request returns values for field names

              matching these patterns in the hits.fields property of the response.'
            type: array
            items:
              $ref: '#/components/schemas/_types.query_dsl.FieldAndFormat'
          from:
            description: Starting document offset.
            default: 0.0
            type: number
          highlight:
            description: Specifies the highlighter to use for retrieving highlighted snippets from one or more fields in the search results.
            allOf:
            - $ref: '#/components/schemas/_global.search._types.Highlight'
          script_fields:
            description: Returns the result of one or more script evaluations for each hit.
            type: object
            additionalProperties:
              $ref: '#/components/schemas/_types.ScriptField'
          size:
            description: The maximum number of top matching hits to return per bucket.
            default: 3.0
            type: number
          sort:
            description: 'Sort order of the top matching hits.

              By default, the hits are sorted by the score of the main query.'
            allOf:
            - $ref: '#/components/schemas/_types.Sort'
          _source:
            description: Selects the fields of the source that are returned.
            allOf:
            - $ref: '#/components/schemas/_global.search._types.SourceConfig'
          stored_fields:
            description: Returns values for the specified stored fields (fields that use the `store` mapping option).
            allOf:
            - $ref: '#/components/schemas/_types.Fields'
          track_scores:
            description: If `true`, calculates and returns document scores, even if the scores are not used for sorting.
            default: false
            type: boolean
          version:
            description: If `true`, returns document version as part of a hit.
            default: false
            type: boolean
          seq_no_primary_term:
            description: If `true`, returns sequence number and primary term of the last modification of each hit.
            type: boolean
    _types.aggregations.BucketSelectorAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
        properties:
          script:
            description: The script to run for this aggregation.
            allOf:
            - $ref: '#/components/schemas/_types.Script'
    _types.query_dsl.CombinedFieldsZeroTerms:
      type: string
      enum:
      - none
      - all
    _types.aggregations.TermsPartition:
      type: object
      properties:
        num_partitions:
          description: The number of partitions.
          type: number
        partition:
          description: The partition number for this request.
          type: number
      required:
      - num_partitions
      - partition
    _types.query_dsl.GeoBoundingBoxQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          type:
            deprecated: true
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.GeoExecution'
          validation_method:
            description: 'Set to `IGNORE_MALFORMED` to accept geo points with invalid latitude or longitude.

              Set to `COERCE` to also try to infer correct latitude or longitude.'
            default: '''strict'''
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.GeoValidationMethod'
          ignore_unmapped:
            description: 'Set to `true` to ignore an unmapped field and not match any documents for this query.

              Set to `false` to throw an exception if the field is not mapped.'
            default: false
            type: boolean
    _types.SortResults:
      type: array
      items:
        $ref: '#/components/schemas/_types.FieldValue'
    _types.aggregations.BucketCorrelationFunctionCountCorrelationIndicator:
      type: object
      properties:
        doc_count:
          description: 'The total number of documents that initially created the expectations. It’s required to be greater

            than or equal to the sum of all values in the buckets_path as this is the originating superset of data

            to which the term values are correlated.'
          type: number
        expectations:
          description: 'An array of numbers with which to correlate the configured `bucket_path` values.

            The length of this value must always equal the number of buckets returned by the `bucket_path`.'
          type: array
          items:
            type: number
        fractions:
          description: 'An array of fractions to use when averaging and calculating variance. This should be used if

            the pre-calculated data and the buckets_path have known gaps. The length of fractions, if provided,

            must equal expectations.'
          type: array
          items:
            type: number
      required:
      - doc_count
      - expectations
    _types.aggregations.ChildrenAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          type:
            description: The child type that should be selected.
            allOf:
            - $ref: '#/components/schemas/_types.RelationName'
    _types.EpochTimeUnitMillis:
      allOf:
      - $ref: '#/components/schemas/_types.UnitMillis'
    _types.aggregations.MatrixAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.Aggregation'
      - type: object
        properties:
          fields:
            description: An array of fields for computing the statistics.
            allOf:
            - $ref: '#/components/schemas/_types.Fields'
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            type: object
            additionalProperties:
              type: number
    _types.query_dsl.DisMaxQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          queries:
            description: 'One or more query clauses.

              Returned documents must match one or more of these queries.

              If a document matches multiple queries, Elasticsearch uses the highest relevance score.'
            type: array
            items:
              $ref: '#/components/schemas/_types.query_dsl.QueryContainer'
          tie_breaker:
            description: Floating point number between 0 and 1.0 used to increase the relevance scores of documents matching multiple query clauses.
            default: 0.0
            type: number
        required:
        - queries
    _types.aggregations.SamplerAggregationExecutionHint:
      type: string
      enum:
      - map
      - global_ordinals
      - bytes_hash
    _types.aggregations.MovingPercentilesAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
        properties:
          window:
            description: The size of window to "slide" across the histogram.
            type: number
          shift:
            description: 'By default, the window consists of the last n values excluding the current bucket.

              Increasing `shift` by 1, moves the starting window position by 1 to the right.'
            default: 0.0
            type: number
          keyed:
            type: boolean
    _types.aggregations.HoltWintersModelSettings:
      type: object
      properties:
        alpha:
          type: number
        beta:
          type: number
        gamma:
          type: number
        pad:
          type: boolean
        period:
          type: number
        type:
          allOf:
          - $ref: '#/components/schemas/_types.aggregations.HoltWintersType'
    eql._types.EqlHits:
      type: object
      properties:
        total:
          description: Metadata about the number of matching events or sequences.
          allOf:
          - $ref: '#/components/schemas/_global.search._types.TotalHits'
        events:
          description: Contains events matching the query. Each object represents a matching event.
          type: array
          items:
            $ref: '#/components/schemas/eql._types.HitsEvent'
        sequences:
          description: Contains event sequences matching the query. Each object represents a matching sequence. This parameter is only returned for EQL queries containing a sequence.
          type: array
          items:
            $ref: '#/components/schemas/eql._types.HitsSequence'
    _types.aggregations.HistogramAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          extended_bounds:
            description: Enables extending the bounds of the histogram beyond the data itself.
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.ExtendedBoundsdouble'
          hard_bounds:
            description: 'Limits the range of buckets in the histogram.

              It is particularly useful in the case of open data ranges that can result in a very large number of buckets.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.ExtendedBoundsdouble'
          field:
            description: The name of the field to aggregate on.
            allOf:
            - $ref: '#/components/schemas/_types.Field'
          interval:
            description: 'The interval for the buckets.

              Must be a positive decimal.'
            type: number
          min_doc_count:
            description: 'Only returns buckets that have `min_doc_count` number of documents.

              By default, the response will fill gaps in the histogram with empty buckets.'
            type: number
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            type: number
          offset:
            description: 'By default, the bucket keys start with 0 and then continue in even spaced steps of `interval`.

              The bucket boundaries can be shifted by using the `offset` option.'
            type: number
          order:
            description: 'The sort order of the returned buckets.

              By default, the returned buckets are sorted by their key ascending.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.AggregateOrder'
          script:
            allOf:
            - $ref: '#/components/schemas/_types.Script'
          format:
            type: string
          keyed:
            description: If `true`, returns buckets as a hash instead of an array, keyed by the bucket keys.
            default: false
            type: boolean
    _types.GeoTilePrecision:
      type: number
    _types.aggregations.DateRangeAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          field:
            description: The date field whose values are use to build ranges.
            allOf:
            - $ref: '#/components/schemas/_types.Field'
          format:
            description: The date format used to format `from` and `to` in the response.
            type: string
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.Missing'
          ranges:
            description: Array of date ranges.
            type: array
            items:
              $ref: '#/components/schemas/_types.aggregations.DateRangeExpression'
          time_zone:
            description: Time zone used to convert dates from another time zone to UTC.
            allOf:
            - $ref: '#/components/schemas/_types.TimeZone'
          keyed:
            description: Set to `true` to associate a unique string key with each bucket and returns the ranges as a hash rather than an array.
            type: boolean
    _types.aggregations.StringStatsAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
      - type: object
        properties:
          show_distribution:
            description: Shows the probability distribution for all characters.
            default: false
            type: boolean
    _types.aggregations.TTestType:
      type: string
      enum:
      - paired
      - homoscedastic
      - heteroscedastic
    _types.TextSimilarityReranker:
      allOf:
      - $ref: '#/components/schemas/_types.RetrieverBase'
      - type: object
        properties:
          retriever:
            description: The nested retriever which will produce the first-level results, that will later be used for reranking.
            allOf:
            - $ref: '#/components/schemas/_types.RetrieverContainer'
          rank_window_size:
            description: This value determines how many documents we will consider from the nested retriever.
            type: number
          inference_id:
            description: Unique identifier of the inference endpoint created using the inference API.
            type: string
          inference_text:
            description: The text snippet used as the basis for similarity comparison.
            type: string
          field:
            description: The document field to be used for text similarity comparisons. This field should contain the text that will be evaluated against the inference_text.
            type: string
          chunk_rescorer:
            description: Whether to rescore on only the best matching chunks.
            x-state: Generally available; Added in 9.2.0
            allOf:
            - $ref: '#/components/schemas/_types.ChunkRescorer'
        required:
        - retriever
        - inference_text
        - field
    _types.aggregations.ParentAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          type:
            description: The child type that should be selected.
            allOf:
            - $ref: '#/components/schemas/_types.RelationName'
    _types.aggregations.MaxBucketAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
    _global.search._types.FieldCollapse:
      type: object
      properties:
        field:
          description: The field to collapse the result set on
          allOf:
          - $ref: '#/components/schemas/_types.Field'
        inner_hits:
          description: The number of inner hits and their sort order
          oneOf:
          - $ref: '#/components/schemas/_global.search._types.InnerHits'
          - type: array
            items:
              $ref: '#/components/schemas/_global.search._types.InnerHits'
        max_concurrent_group_searches:
          description: The number of concurrent requests allowed to retrieve the inner_hits per group
          type: number
        collapse:
          allOf:
          - $ref: '#/components/schemas/_global.search._types.FieldCollapse'
      required:
      - field
    _types.DateTime:
      description: 'A date and time, either as a string whose format can depend on the context (defaulting to ISO 8601), or a

        number of milliseconds since the Epoch. Elasticsearch accepts both as input, but will generally output a string

        representation.'
      oneOf:
      - type: string
      - $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
    _types.query_dsl.RangeQueryBase:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          relation:
            description: Indicates how the range query matches values for `range` fields.
            default: intersects
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.RangeRelation'
          gt:
            description: Greater than.
            type: object
          gte:
            description: Greater than or equal to.
            type: object
          lt:
            description: Less than.
            type: object
          lte:
            description: Less than or equal to.
            type: object
    _types.query_dsl.NumericDecayFunction:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.DecayFunctionBasedoubledouble'
      - type: object
    _types.aggregations.FormattableMetricAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
      - type: object
        properties:
          format:
            type: string
    _types.query_dsl.UntypedRangeQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.RangeQueryBase'
      - type: object
        properties:
          format:
            description: Date format used to convert `date` values in the query.
            allOf:
            - $ref: '#/components/schemas/_types.DateFormat'
          time_zone:
            description: Coordinated Universal Time (UTC) offset or IANA time zone used to convert `date` values in the query to UTC.
            allOf:
            - $ref: '#/components/schemas/_types.TimeZone'
    _types.IndexName:
      type: string
    _types.aggregations.GeoLineSort:
      type: object
      properties:
        field:
          description: The name of the numeric field to use as the sort key for ordering the points.
          allOf:
          - $ref: '#/components/schemas/_types.Field'
      required:
      - field
    eql._types.HitsSequence:
      type: object
      properties:
        events:
          description: Contains events matching the query. Each object represents a matching event.
          type: array
          items:
            $ref: '#/components/schemas/eql._types.HitsEvent'
        join_keys:
          description: Shared field values used to constrain matches in the sequence. These are defined using the by keyword in the EQL query syntax.
          type: array
          items:
            type: object
      required:
      - events
    _types.aggregations.MultiTermLookup:
      allOf:
      - type: object
        properties:
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.Missing'
      - type: object
        properties:
          field:
            description: 'A field from which to retrieve terms.

              It is required if `script` is not provided.'
            allOf:
            - $ref: '#/components/schemas/_types.Field'
          script:
            description: 'A script to calculate terms to aggregate on.

              It is required if `field` is not provided.'
            allOf:
            - $ref: '#/components/schemas/_types.Script'
        minProperties: 1
        maxProperties: 1
    _types.query_dsl.DecayFunctionBaseGeoLocationDistance:
      type: object
      properties:
        multi_value_mode:
          description: Determines how the distance is calculated when a field used for computing the decay contains multiple values.
          default: min
          allOf:
          - $ref: '#/components/schemas/_types.query_dsl.MultiValueMode'
    _types.aggregations.CompositeAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          after:
            description: When paginating, use the `after_key` value returned in the previous response to retrieve the next page.
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.CompositeAggregateKey'
          size:
            description: The number of composite buckets that should be returned.
            default: 10.0
            type: number
          sources:
            description: 'The value sources used to build composite buckets.

              Keys are returned in the order of the `sources` definition.'
            type: array
            items:
              type: object
              additionalProperties:
                $ref: '#/components/schemas/_types.aggregations.CompositeAggregationSource'
              minProperties: 1
              maxProperties: 1
    _types.query_dsl.SemanticQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          field:
            description: The field to query, which must be a semantic_text field type
            type: string
          query:
            description: The query text
            type: string
        required:
        - field
        - query
    _types.aggregations.InferenceAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
        properties:
          model_id:
            description: The ID or alias for the trained model.
            allOf:
            - $ref: '#/components/schemas/_types.Name'
          inference_config:
            description: Contains the inference type and its options.
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.InferenceConfigContainer'
        required:
        - model_id
    _types.aggregations.HoltWintersMovingAverageAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MovingAverageAggregationBase'
      - type: object
        properties:
          model:
            type: string
            enum:
            - holt_winters
          settings:
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.HoltWintersModelSettings'
        re

# --- truncated at 32 KB (346 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/openapi/elk-stack-eql-api-openapi.yml