Authenticating with curl¶
# API key (preferred: scoped, revocable, no password involved)
curl -s -H "Authorization: ApiKey $ES_API_KEY" "$ES_URL/"
# Basic auth (curl prompts for the password if you leave it off)
curl -s -u elastic "$ES_URL/"
# Self-managed cluster with the auto-generated CA
curl -s --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic https://localhost:9200/
Create an API key in Kibana (Stack Management → API keys) or with POST _security/api_key. Use the base64 encoded value in the header.
For requests with a body, add -H 'Content-Type: application/json'.
_cat APIs¶
The _cat APIs return aligned text meant for people to read. Parameters that work on all of them:
| Parameter | Effect |
|---|---|
v |
Show column headers |
help |
List the available columns |
h=col1,col2 |
Choose columns |
s=col:desc |
Sort |
bytes=gb |
Fixed size unit, easier to compare |
format=json |
Machine-readable output, for scripts and jq |
Useful ones:
GET _cat/health?v
GET _cat/nodes?v&h=name,node.role,heap.percent,ram.percent,cpu,load_1m,disk.used_percent
GET _cat/indices/*,-.*?v&s=index # non-system indices only
GET _cat/indices?v&s=pri.store.size:desc&bytes=gb # biggest first
GET _cat/shards?v&s=store:desc
GET _cat/allocation?v
GET _cat/aliases?v
GET _cat/templates?v
GET _cat/count/[ index ]?v
In _cat/indices/*,-.*, the -.* excludes indices whose names start with a dot (system and hidden indices).
From curl¶
curl -s -H "Authorization: ApiKey $ES_API_KEY" \
"$ES_URL/_cat/indices/*,-.*?v&s=index"
# JSON for scripting
curl -s -H "Authorization: ApiKey $ES_API_KEY" \
"$ES_URL/_cat/indices?format=json&bytes=b" | jq -r '.[] | "\(.index)\t\(."store.size")"'
For automation, prefer the JSON APIs (_cluster/health, _nodes/stats, GET <index>/_stats) over _cat, because column layouts can change between versions. See cluster health and metrics.