Skip to content

SQL and ES|QL

  • Elasticsearch

The SQL panel runs SQL through the Elasticsearch SQL API, and ES|QL where the cluster has it. SQL can also be translated to Query DSL, so you can see, run and reuse the search it stands for.

The Elasticsearch SQL tab: a SELECT counting products and their lowest and highest prices per wood, translated to Query DSL with a composite aggregation.The Elasticsearch SQL tab: a SELECT counting products and their lowest and highest prices per wood, translated to Query DSL with a composite aggregation.
Run SQL on Elasticsearch and translate it to the Query DSL it becomes.
  1. Double-click SQL in the sidebar.

  2. Pick SQL or ES|QL in the toolbar. A language the cluster does not have is disabled; its tooltip says so (the SQL API is missing from the OSS distribution, and ES|QL arrived in 8.11).

  3. Type a query, for example:

    SELECT status, COUNT(*) AS orders, SUM(total) AS revenue
    FROM orders
    GROUP BY status
  4. Choose Run, or press Ctrl + Enter (Cmd + Enter on macOS). Cancel stops a running query.

Results page with the server’s cursor: more rows load as you scroll, or with Load more. The status line lists the row count, the time taken and each column’s type.

Queries are reads, so they run on read-only profiles too.

With SQL selected, choose Translate to DSL. A DSL tab opens next to Results with the translated Query DSL and the index it targets.

Button What it does
Run DSL Runs the translated search here
Open in console Opens a console with the search as a request you can edit and send

When the search returns aggregations, switch between Aggregations and Response. The aggregations show as a Tree of aggregations, buckets with their document counts and metrics, or as a Table with one row per innermost bucket.

To build Query DSL from the mapping instead, use the query builder in the documents view.

Documents Querybara 0.1.1 · built frombc9f5aa