Andrew Mercer
on this page

Authenticating with curl

# API key (preferred: scoped, revocable, no password involved)
curl -s -H "Authorization: ApiKey $ES_API_KEY" "$ES_URL/"

# Basic auth (curl prompts for the password if you leave it off)
curl -s -u elastic "$ES_URL/"

# Self-managed cluster with the auto-generated CA
curl -s --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic https://localhost:9200/

Create an API key in Kibana (Stack Management → API keys) or with POST _security/api_key. Use the base64 encoded value in the header.

For requests with a body, add -H 'Content-Type: application/json'.

_cat APIs

The _cat APIs return aligned text meant for people to read. Parameters that work on all of them:

Parameter Effect
v Show column headers
help List the available columns
h=col1,col2 Choose columns
s=col:desc Sort
bytes=gb Fixed size unit, easier to compare
format=json Machine-readable output, for scripts and jq

Useful ones:

GET _cat/health?v
GET _cat/nodes?v&h=name,node.role,heap.percent,ram.percent,cpu,load_1m,disk.used_percent
GET _cat/indices/*,-.*?v&s=index                 # non-system indices only
GET _cat/indices?v&s=pri.store.size:desc&bytes=gb  # biggest first
GET _cat/shards?v&s=store:desc
GET _cat/allocation?v
GET _cat/aliases?v
GET _cat/templates?v
GET _cat/count/[ index ]?v

In _cat/indices/*,-.*, the -.* excludes indices whose names start with a dot (system and hidden indices).

From curl

curl -s -H "Authorization: ApiKey $ES_API_KEY" \
  "$ES_URL/_cat/indices/*,-.*?v&s=index"

# JSON for scripting
curl -s -H "Authorization: ApiKey $ES_API_KEY" \
  "$ES_URL/_cat/indices?format=json&bytes=b" | jq -r '.[] | "\(.index)\t\(."store.size")"'

For automation, prefer the JSON APIs (_cluster/health, _nodes/stats, GET <index>/_stats) over _cat, because column layouts can change between versions. See cluster health and metrics.