[[search-request-body]] === Request Body Search Specifies search criteria as request body parameters. [source,console] -------------------------------------------------- GET /my-index-000001/_search { "query" : { "term" : { "user.id" : "kimchy" } } } -------------------------------------------------- // TEST[setup:my_index] [[search-request-body-api-request]] ==== {api-request-title} `GET //_search { "query": {} }` [[search-request-body-api-desc]] ==== {api-description-title} The search request can be executed with a search DSL, which includes the <>, within its body. [[search-request-body-api-path-params]] ==== {api-path-parms-title} ``:: (Optional, string) Comma-separated list of data streams, indices, and index aliases to search. Wildcard (`*`) expressions are supported. + To search all data streams and indices in a cluster, omit this parameter or use `_all` or `*`. [[search-request-body-api-request-body]] ==== {api-request-body-title} See the search API's <>. ==== Fast check for any matching docs NOTE: `terminate_after` is always applied **after** the `post_filter` and stops the query as well as the aggregation executions when enough hits have been collected on the shard. Though the doc count on aggregations may not reflect the `hits.total` in the response since aggregations are applied **before** the post filtering. In case we only want to know if there are any documents matching a specific query, we can set the `size` to `0` to indicate that we are not interested in the search results. Also we can set `terminate_after` to `1` to indicate that the query execution can be terminated whenever the first matching document was found (per shard). [source,console] -------------------------------------------------- GET /_search?q=user.id:elkbee&size=0&terminate_after=1 -------------------------------------------------- // TEST[setup:my_index] The response will not contain any hits as the `size` was set to `0`. The `hits.total` will be either equal to `0`, indicating that there were no matching documents, or greater than `0` meaning that there were at least as many documents matching the query when it was early terminated. Also if the query was terminated early, the `terminated_early` flag will be set to `true` in the response. [source,console-result] -------------------------------------------------- { "took": 3, "timed_out": false, "terminated_early": true, "_shards": { "total": 1, "successful": 1, "skipped" : 0, "failed": 0 }, "hits": { "total" : { "value": 1, "relation": "eq" }, "max_score": null, "hits": [] } } -------------------------------------------------- // TESTRESPONSE[s/"took": 3/"took": $body.took/] The `took` time in the response contains the milliseconds that this request took for processing, beginning quickly after the node received the query, up until all search related work is done and before the above JSON is returned to the client. This means it includes the time spent waiting in thread pools, executing a distributed search across the whole cluster and gathering all the results. [[request-body-search-docvalue-fields]] ==== Doc value fields See <>. [[request-body-search-collapse]] ==== Field collapsing See <>. [[request-body-search-highlighting]] ==== Highlighting See <>. include::request/index-boost.asciidoc[] include::request/inner-hits.asciidoc[] include::request/min-score.asciidoc[] [[request-body-search-queries-and-filters]] ==== Named queries See <>. include::request/post-filter.asciidoc[] include::request/preference.asciidoc[] include::request/rescore.asciidoc[] [[request-body-search-script-fields]] ==== Script Fields See <>. [[request-body-search-scroll]] ==== Scroll See <>. [[_clear_scroll_api]] ===== Clear scroll API See <>. [[sliced-scroll]] ===== Sliced scroll See <>. [[request-body-search-search-after]] ==== Search After See <>. include::request/search-type.asciidoc[] [[request-body-search-sort]] ==== Sort See <>. [[request-body-search-source-filtering]] ==== Source filtering See <>. [[request-body-search-stored-fields]] ==== Stored fields See <>. include::request/track-total-hits.asciidoc[]