Elastic Stack (ELK Stack) Sql API

The sql API from Elastic Stack (ELK Stack) — 6 operation(s) for sql.

Operations 8

POST /_sql/close Clear an SQL search cursor #
DELETE /_sql/async/delete/{id} Delete an async SQL search #
GET /_sql/async/{id} Get async SQL search results #
GET /_sql/async/status/{id} Get the async SQL search status #
GET /_sql Get SQL search results #
POST /_sql Get SQL search results #
GET /_sql/translate Translate SQL into Elasticsearch queries #
POST /_sql/translate Translate SQL into Elasticsearch queries #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/elk-stack-sql-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

elk-stack-sql-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Elasticsearch Request & Response Specification Sql API
  license:
    name: Apache 2.0
    url: https://github.com/elastic/elasticsearch-specification/blob/main/LICENSE
  version: ''
tags:
- name: sql
paths:
  /_sql/close:
    post:
      tags:
      - sql
      summary: Clear an SQL search cursor
      operationId: sql-clear-cursor
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                cursor:
                  description: Cursor to clear.
                  type: string
              required:
              - cursor
            examples:
              ClearSqlCursorRequestExample1:
                description: Run `POST _sql/close` to clear an SQL search cursor.
                value: "{\n  \"cursor\": \"sDXF1ZXJ5QW5kRmV0Y2gBAAAAAAAAAAEWYUpOYklQMHhRUEtld3RsNnFtYU1hQQ==:BAFmBGRhdGUBZgVsaWtlcwFzB21lc3NhZ2UBZgR1c2Vy9f///w8=\"\n}"
        required: true
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  succeeded:
                    type: boolean
                required:
                - succeeded
      x-state: Generally available; Added in 6.3.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /_sql/async/delete/{id}:
    delete:
      tags:
      - sql
      summary: Delete an async SQL search
      description: 'Delete an async SQL search or a stored synchronous SQL search.

        If the search is still running, the API cancels it.


        If the Elasticsearch security features are enabled, only the following users can use this API to delete a search:


        * Users with the `cancel_task` cluster privilege.

        * The user who first submitted the search.


        ## Required authorization


        * Cluster privileges: `cancel_task`

        '
      operationId: sql-delete-async
      parameters:
      - in: path
        name: id
        description: The identifier for the search.
        required: true
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Id'
        style: simple
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/_types.AcknowledgedResponseBase'
      x-state: Generally available; Added in 7.15.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /_sql/async/{id}:
    get:
      tags:
      - sql
      summary: Get async SQL search results
      description: 'Get the current status and available results for an async SQL search or stored synchronous SQL search.


        If the Elasticsearch security features are enabled, only the user who first submitted the SQL search can retrieve the search using this API.'
      operationId: sql-get-async
      parameters:
      - in: path
        name: id
        description: The identifier for the search.
        required: true
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Id'
        style: simple
      - in: query
        name: delimiter
        description: 'The separator for CSV results.

          The API supports this parameter only for CSV responses.'
        deprecated: false
        schema:
          default: ','
          type: string
        style: form
      - in: query
        name: format
        description: 'The format for the response.

          You must specify a format using this parameter or the `Accept` HTTP header.

          If you specify both, the API uses this parameter.'
        deprecated: false
        schema:
          type: string
        style: form
      - in: query
        name: keep_alive
        description: 'The retention period for the search and its results.

          It defaults to the `keep_alive` period for the original SQL search.'
        deprecated: false
        schema:
          default: 5d
          allOf:
          - $ref: '#/components/schemas/_types.Duration'
        style: form
      - in: query
        name: wait_for_completion_timeout
        description: 'The period to wait for complete results.

          It defaults to no timeout, meaning the request waits for complete search results.'
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Duration'
        style: form
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    description: 'Identifier for the search.

                      This value is returned only for async and saved synchronous searches.

                      For CSV, TSV, and TXT responses, this value is returned in the `Async-ID` HTTP header.'
                    allOf:
                    - $ref: '#/components/schemas/_types.Id'
                  is_running:
                    description: 'If `true`, the search is still running.

                      If `false`, the search has finished.

                      This value is returned only for async and saved synchronous searches.

                      For CSV, TSV, and TXT responses, this value is returned in the `Async-partial` HTTP header.'
                    type: boolean
                  is_partial:
                    description: 'If `true`, the response does not contain complete search results.

                      If `is_partial` is `true` and `is_running` is `true`, the search is still running.

                      If `is_partial` is `true` but `is_running` is `false`, the results are partial due to a failure or timeout.

                      This value is returned only for async and saved synchronous searches.

                      For CSV, TSV, and TXT responses, this value is returned in the `Async-partial` HTTP header.'
                    type: boolean
                  columns:
                    description: Column headings for the search results. Each object is a column.
                    type: array
                    items:
                      $ref: '#/components/schemas/sql._types.Column'
                  cursor:
                    description: 'The cursor for the next set of paginated results.

                      For CSV, TSV, and TXT responses, this value is returned in the `Cursor` HTTP header.'
                    type: string
                  rows:
                    description: The values for the search results.
                    type: array
                    items:
                      $ref: '#/components/schemas/sql._types.Row'
                required:
                - id
                - is_running
                - is_partial
                - rows
      x-state: Generally available; Added in 7.15.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /_sql/async/status/{id}:
    get:
      tags:
      - sql
      summary: Get the async SQL search status
      description: 'Get the current status of an async SQL search or a stored synchronous SQL search.


        ## Required authorization


        * Cluster privileges: `monitor`

        '
      operationId: sql-get-async-status
      parameters:
      - in: path
        name: id
        description: The identifier for the search.
        required: true
        deprecated: false
        schema:
          $ref: '#/components/schemas/_types.Id'
        style: simple
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  expiration_time_in_millis:
                    description: The timestamp, in milliseconds since the Unix epoch, when Elasticsearch will delete the search and its results, even if the search is still running.
                    allOf:
                    - $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
                  id:
                    description: The identifier for the search.
                    type: string
                  is_running:
                    description: 'If `true`, the search is still running.

                      If `false`, the search has finished.'
                    type: boolean
                  is_partial:
                    description: 'If `true`, the response does not contain complete search results.

                      If `is_partial` is `true` and `is_running` is `true`, the search is still running.

                      If `is_partial` is `true` but `is_running` is `false`, the results are partial due to a failure or timeout.'
                    type: boolean
                  start_time_in_millis:
                    description: 'The timestamp, in milliseconds since the Unix epoch, when the search started.

                      The API returns this property only for running searches.'
                    allOf:
                    - $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
                  completion_status:
                    description: 'The HTTP status code for the search.

                      The API returns this property only for completed searches.'
                    allOf:
                    - $ref: '#/components/schemas/_types.uint'
                required:
                - expiration_time_in_millis
                - id
                - is_running
                - is_partial
                - start_time_in_millis
      x-state: Generally available; Added in 7.15.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /_sql:
    get:
      tags:
      - sql
      summary: Get SQL search results
      description: 'Run an SQL request.


        ## Required authorization


        * Index privileges: `read`

        '
      operationId: sql-query-1
      parameters:
      - $ref: '#/components/parameters/sql.query-format'
      requestBody:
        $ref: '#/components/requestBodies/sql.query'
      responses:
        '200':
          $ref: '#/components/responses/sql.query-200'
      x-state: Generally available; Added in 6.3.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
    post:
      tags:
      - sql
      summary: Get SQL search results
      description: 'Run an SQL request.


        ## Required authorization


        * Index privileges: `read`

        '
      operationId: sql-query
      parameters:
      - $ref: '#/components/parameters/sql.query-format'
      requestBody:
        $ref: '#/components/requestBodies/sql.query'
      responses:
        '200':
          $ref: '#/components/responses/sql.query-200'
      x-state: Generally available; Added in 6.3.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
  /_sql/translate:
    get:
      tags:
      - sql
      summary: Translate SQL into Elasticsearch queries
      description: 'Translate an SQL search into a search API request containing Query DSL.

        It accepts the same request body parameters as the SQL search API, excluding `cursor`.


        ## Required authorization


        * Index privileges: `read`

        '
      operationId: sql-translate-1
      requestBody:
        $ref: '#/components/requestBodies/sql.translate'
      responses:
        '200':
          $ref: '#/components/responses/sql.translate-200'
      x-state: Generally available; Added in 6.3.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
    post:
      tags:
      - sql
      summary: Translate SQL into Elasticsearch queries
      description: 'Translate an SQL search into a search API request containing Query DSL.

        It accepts the same request body parameters as the SQL search API, excluding `cursor`.


        ## Required authorization


        * Index privileges: `read`

        '
      operationId: sql-translate
      requestBody:
        $ref: '#/components/requestBodies/sql.translate'
      responses:
        '200':
          $ref: '#/components/responses/sql.translate-200'
      x-state: Generally available; Added in 6.3.0
      x-metaTags:
      - content: Elasticsearch
        name: product_name
components:
  schemas:
    _types.query_dsl.SpanContainingQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          big:
            description: 'Can be any span query.

              Matching spans from `big` that contain matches from `little` are returned.'
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.SpanQuery'
          little:
            description: 'Can be any span query.

              Matching spans from `big` that contain matches from `little` are returned.'
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.SpanQuery'
        required:
        - big
        - little
    _types.query_dsl.TypeQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          value:
            type: string
        required:
        - value
    _types.aggregations.TopHitsAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
      - type: object
        properties:
          docvalue_fields:
            description: Fields for which to return doc values.
            type: array
            items:
              $ref: '#/components/schemas/_types.query_dsl.FieldAndFormat'
          explain:
            description: If `true`, returns detailed information about score computation as part of a hit.
            default: false
            type: boolean
          fields:
            description: 'Array of wildcard (*) patterns. The request returns values for field names

              matching these patterns in the hits.fields property of the response.'
            type: array
            items:
              $ref: '#/components/schemas/_types.query_dsl.FieldAndFormat'
          from:
            description: Starting document offset.
            default: 0.0
            type: number
          highlight:
            description: Specifies the highlighter to use for retrieving highlighted snippets from one or more fields in the search results.
            allOf:
            - $ref: '#/components/schemas/_global.search._types.Highlight'
          script_fields:
            description: Returns the result of one or more script evaluations for each hit.
            type: object
            additionalProperties:
              $ref: '#/components/schemas/_types.ScriptField'
          size:
            description: The maximum number of top matching hits to return per bucket.
            default: 3.0
            type: number
          sort:
            description: 'Sort order of the top matching hits.

              By default, the hits are sorted by the score of the main query.'
            allOf:
            - $ref: '#/components/schemas/_types.Sort'
          _source:
            description: Selects the fields of the source that are returned.
            allOf:
            - $ref: '#/components/schemas/_global.search._types.SourceConfig'
          stored_fields:
            description: Returns values for the specified stored fields (fields that use the `store` mapping option).
            allOf:
            - $ref: '#/components/schemas/_types.Fields'
          track_scores:
            description: If `true`, calculates and returns document scores, even if the scores are not used for sorting.
            default: false
            type: boolean
          version:
            description: If `true`, returns document version as part of a hit.
            default: false
            type: boolean
          seq_no_primary_term:
            description: If `true`, returns sequence number and primary term of the last modification of each hit.
            type: boolean
    _types.aggregations.BucketSelectorAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
        properties:
          script:
            description: The script to run for this aggregation.
            allOf:
            - $ref: '#/components/schemas/_types.Script'
    _types.query_dsl.CombinedFieldsZeroTerms:
      type: string
      enum:
      - none
      - all
    _types.aggregations.TermsPartition:
      type: object
      properties:
        num_partitions:
          description: The number of partitions.
          type: number
        partition:
          description: The partition number for this request.
          type: number
      required:
      - num_partitions
      - partition
    _types.query_dsl.GeoBoundingBoxQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          type:
            deprecated: true
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.GeoExecution'
          validation_method:
            description: 'Set to `IGNORE_MALFORMED` to accept geo points with invalid latitude or longitude.

              Set to `COERCE` to also try to infer correct latitude or longitude.'
            default: '''strict'''
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.GeoValidationMethod'
          ignore_unmapped:
            description: 'Set to `true` to ignore an unmapped field and not match any documents for this query.

              Set to `false` to throw an exception if the field is not mapped.'
            default: false
            type: boolean
    _types.SortResults:
      type: array
      items:
        $ref: '#/components/schemas/_types.FieldValue'
    _types.aggregations.BucketCorrelationFunctionCountCorrelationIndicator:
      type: object
      properties:
        doc_count:
          description: 'The total number of documents that initially created the expectations. It’s required to be greater

            than or equal to the sum of all values in the buckets_path as this is the originating superset of data

            to which the term values are correlated.'
          type: number
        expectations:
          description: 'An array of numbers with which to correlate the configured `bucket_path` values.

            The length of this value must always equal the number of buckets returned by the `bucket_path`.'
          type: array
          items:
            type: number
        fractions:
          description: 'An array of fractions to use when averaging and calculating variance. This should be used if

            the pre-calculated data and the buckets_path have known gaps. The length of fractions, if provided,

            must equal expectations.'
          type: array
          items:
            type: number
      required:
      - doc_count
      - expectations
    _types.aggregations.ChildrenAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          type:
            description: The child type that should be selected.
            allOf:
            - $ref: '#/components/schemas/_types.RelationName'
    _types.EpochTimeUnitMillis:
      allOf:
      - $ref: '#/components/schemas/_types.UnitMillis'
    _types.aggregations.MatrixAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.Aggregation'
      - type: object
        properties:
          fields:
            description: An array of fields for computing the statistics.
            allOf:
            - $ref: '#/components/schemas/_types.Fields'
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            type: object
            additionalProperties:
              type: number
    _types.query_dsl.DisMaxQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          queries:
            description: 'One or more query clauses.

              Returned documents must match one or more of these queries.

              If a document matches multiple queries, Elasticsearch uses the highest relevance score.'
            type: array
            items:
              $ref: '#/components/schemas/_types.query_dsl.QueryContainer'
          tie_breaker:
            description: Floating point number between 0 and 1.0 used to increase the relevance scores of documents matching multiple query clauses.
            default: 0.0
            type: number
        required:
        - queries
    _types.aggregations.SamplerAggregationExecutionHint:
      type: string
      enum:
      - map
      - global_ordinals
      - bytes_hash
    _types.aggregations.MovingPercentilesAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
        properties:
          window:
            description: The size of window to "slide" across the histogram.
            type: number
          shift:
            description: 'By default, the window consists of the last n values excluding the current bucket.

              Increasing `shift` by 1, moves the starting window position by 1 to the right.'
            default: 0.0
            type: number
          keyed:
            type: boolean
    _types.aggregations.HoltWintersModelSettings:
      type: object
      properties:
        alpha:
          type: number
        beta:
          type: number
        gamma:
          type: number
        pad:
          type: boolean
        period:
          type: number
        type:
          allOf:
          - $ref: '#/components/schemas/_types.aggregations.HoltWintersType'
    _types.aggregations.HistogramAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          extended_bounds:
            description: Enables extending the bounds of the histogram beyond the data itself.
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.ExtendedBoundsdouble'
          hard_bounds:
            description: 'Limits the range of buckets in the histogram.

              It is particularly useful in the case of open data ranges that can result in a very large number of buckets.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.ExtendedBoundsdouble'
          field:
            description: The name of the field to aggregate on.
            allOf:
            - $ref: '#/components/schemas/_types.Field'
          interval:
            description: 'The interval for the buckets.

              Must be a positive decimal.'
            type: number
          min_doc_count:
            description: 'Only returns buckets that have `min_doc_count` number of documents.

              By default, the response will fill gaps in the histogram with empty buckets.'
            type: number
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            type: number
          offset:
            description: 'By default, the bucket keys start with 0 and then continue in even spaced steps of `interval`.

              The bucket boundaries can be shifted by using the `offset` option.'
            type: number
          order:
            description: 'The sort order of the returned buckets.

              By default, the returned buckets are sorted by their key ascending.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.AggregateOrder'
          script:
            allOf:
            - $ref: '#/components/schemas/_types.Script'
          format:
            type: string
          keyed:
            description: If `true`, returns buckets as a hash instead of an array, keyed by the bucket keys.
            default: false
            type: boolean
    _types.GeoTilePrecision:
      type: number
    _types.aggregations.DateRangeAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          field:
            description: The date field whose values are use to build ranges.
            allOf:
            - $ref: '#/components/schemas/_types.Field'
          format:
            description: The date format used to format `from` and `to` in the response.
            type: string
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.Missing'
          ranges:
            description: Array of date ranges.
            type: array
            items:
              $ref: '#/components/schemas/_types.aggregations.DateRangeExpression'
          time_zone:
            description: Time zone used to convert dates from another time zone to UTC.
            allOf:
            - $ref: '#/components/schemas/_types.TimeZone'
          keyed:
            description: Set to `true` to associate a unique string key with each bucket and returns the ranges as a hash rather than an array.
            type: boolean
    _types.aggregations.StringStatsAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
      - type: object
        properties:
          show_distribution:
            description: Shows the probability distribution for all characters.
            default: false
            type: boolean
    _types.aggregations.TTestType:
      type: string
      enum:
      - paired
      - homoscedastic
      - heteroscedastic
    _types.TextSimilarityReranker:
      allOf:
      - $ref: '#/components/schemas/_types.RetrieverBase'
      - type: object
        properties:
          retriever:
            description: The nested retriever which will produce the first-level results, that will later be used for reranking.
            allOf:
            - $ref: '#/components/schemas/_types.RetrieverContainer'
          rank_window_size:
            description: This value determines how many documents we will consider from the nested retriever.
            type: number
          inference_id:
            description: Unique identifier of the inference endpoint created using the inference API.
            type: string
          inference_text:
            description: The text snippet used as the basis for similarity comparison.
            type: string
          field:
            description: The document field to be used for text similarity comparisons. This field should contain the text that will be evaluated against the inference_text.
            type: string
          chunk_rescorer:
            description: Whether to rescore on only the best matching chunks.
            x-state: Generally available; Added in 9.2.0
            allOf:
            - $ref: '#/components/schemas/_types.ChunkRescorer'
        required:
        - retriever
        - inference_text
        - field
    _types.aggregations.ParentAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: object
        properties:
          type:
            description: The child type that should be selected.
            allOf:
            - $ref: '#/components/schemas/_types.RelationName'
    _types.aggregations.MaxBucketAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.PipelineAggregationBase'
      - type: object
    _global.search._types.FieldCollapse:
      type: object
      properties:
        field:
          description: The field to collapse the result set on
          allOf:
          - $ref: '#/components/schemas/_types.Field'
        inner_hits:
          description: The number of inner hits and their sort order
          oneOf:
          - $ref: '#/components/schemas/_global.search._types.InnerHits'
          - type: array
            items:
              $ref: '#/components/schemas/_global.search._types.InnerHits'
        max_concurrent_group_searches:
          description: The number of concurrent requests allowed to retrieve the inner_hits per group
          type: number
        collapse:
          allOf:
          - $ref: '#/components/schemas/_global.search._types.FieldCollapse'
      required:
      - field
    _types.DateTime:
      description: 'A date and time, either as a string whose format can depend on the context (defaulting to ISO 8601), or a

        number of milliseconds since the Epoch. Elasticsearch accepts both as input, but will generally output a string

        representation.'
      oneOf:
      - type: string
      - $ref: '#/components/schemas/_types.EpochTimeUnitMillis'
    _types.query_dsl.RangeQueryBase:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.QueryBase'
      - type: object
        properties:
          relation:
            description: Indicates how the range query matches values for `range` fields.
            default: intersects
            allOf:
            - $ref: '#/components/schemas/_types.query_dsl.RangeRelation'
          gt:
            description: Greater than.
            type: object
          gte:
            description: Greater than or equal to.
            type: object
          lt:
            description: Less than.
            type: object
          lte:
            description: Less than or equal to.
            type: object
    _types.query_dsl.NumericDecayFunction:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.DecayFunctionBasedoubledouble'
      - type: object
    _types.aggregations.FormattableMetricAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.MetricAggregationBase'
      - type: object
        properties:
          format:
            type: string
    _types.query_dsl.UntypedRangeQuery:
      allOf:
      - $ref: '#/components/schemas/_types.query_dsl.RangeQueryBase'
      - type: object
        properties:
          format:
            description: Date format used to convert `date` values in the query.
            allOf:
            - $ref: '#/components/schemas/_types.DateFormat'
          time_zone:
            description: Coordinated Universal Time (UTC) offset or IANA time zone used to convert `date` values in the query to UTC.
            allOf:
            - $ref: '#/components/schemas/_types.TimeZone'
    _types.aggregations.GeoLineSort:
      type: object
      properties:
        field:
          description: The name of the numeric field to use as the sort key for ordering the points.
          allOf:
          - $ref: '#/components/schemas/_types.Field'
      required:
      - field
    _types.IndexName:
      type: string
    _types.aggregations.MultiTermLookup:
      allOf:
      - type: object
        properties:
          missing:
            description: 'The value to apply to documents that do not have a value.

              By default, documents without a value are ignored.'
            allOf:
            - $ref: '#/components/schemas/_types.aggregations.Missing'
      - type: object
        properties:
          field:
            description: 'A field from which to retrieve terms.

              It is required if `script` is not provided.'
            allOf:
            - $ref: '#/components/schemas/_types.Field'
          script:
            description: 'A script to calculate terms to aggregate on.

              It is required if `field` is not provided.'
            allOf:
            - $ref: '#/components/schemas/_types.Script'
        minProperties: 1
        maxProperties: 1
    _types.query_dsl.DecayFunctionBaseGeoLocationDistance:
      type: object
      properties:
        multi_value_mode:
          description: Determines how the distance is calculated when a field used for computing the decay contains multiple values.
          default: min
          allOf:
          - $ref: '#/components/schemas/_types.query_dsl.MultiValueMode'
    _types.aggregations.CompositeAggregation:
      allOf:
      - $ref: '#/components/schemas/_types.aggregations.BucketAggregationBase'
      - type: objec

# --- truncated at 32 KB (344 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/openapi/elk-stack-sql-api-openapi.yml