﻿---
title: stack es fleet search cli command
description: Run a Fleet search. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4097/reference/elastic-cli/cli/stack/es/fleet/search
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es fleet search cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es fleet search --index <index> [options]
```

Run a Fleet search.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--index string required">
    A single target to search. If the target is an index alias, it must resolve to a single index.
  </definition>
  <definition term="--allow-no-indices">
    A setting that does two separate checks on the index expression.
    If `false`, the request returns an error (1) if any wildcard expression
    (including `_all` and `*`) resolves to zero matching indices or (2) if the
    complete set of resolved indices, aliases or data streams is empty after all
    expressions are evaluated. If `true`, index expressions that resolve to no
    indices are allowed and the request returns an empty result.
  </definition>
  <definition term="--analyzer string">
  </definition>
  <definition term="--analyze-wildcard">
  </definition>
  <definition term="--batched-reduce-size number">
  </definition>
  <definition term="--ccs-minimize-roundtrips">
  </definition>
  <definition term="--default-operator enum">
    **Values:** and, or
  </definition>
  <definition term="--df string">
  </definition>
  <definition term="--docvalue-fields string[]">
    Array of wildcard (*) patterns. The request returns doc values for field
    names matching these patterns in the hits.fields property of the response.
    **Repeatable:** pass `--docvalue-fields` multiple times to supply more than one value
  </definition>
  <definition term="--expand-wildcards enum">
    **Values:** all, open, closed, hidden, none
    **Repeatable:** pass `--expand-wildcards` multiple times to supply more than one value
  </definition>
  <definition term="--explain">
    If true, returns detailed information about score computation as part of a hit.
  </definition>
  <definition term="--ignore-throttled">
  </definition>
  <definition term="--ignore-unavailable">
    If `false`, the request returns an error if it targets a concrete (non-wildcarded)
    index, alias, or data stream that is missing, closed, or otherwise unavailable.
    If `true`, unavailable concrete targets are silently ignored.
  </definition>
  <definition term="--lenient">
  </definition>
  <definition term="--max-concurrent-shard-requests number">
  </definition>
  <definition term="--preference string">
  </definition>
  <definition term="--pre-filter-shard-size number">
  </definition>
  <definition term="--request-cache">
  </definition>
  <definition term="--routing string">
    **Repeatable:** pass `--routing` multiple times to supply more than one value
  </definition>
  <definition term="--scroll string">
  </definition>
  <definition term="--search-type enum">
    **Values:** query_then_fetch, dfs_query_then_fetch
  </definition>
  <definition term="--stats string[]">
    Stats groups to associate with the search. Each group maintains a statistics
    aggregation for its associated searches. You can retrieve these stats using
    the indices stats API.
    **Repeatable:** pass `--stats` multiple times to supply more than one value
  </definition>
  <definition term="--stored-fields string">
    List of stored fields to return as part of a hit. If no fields are specified,
    no stored fields are included in the response. If this field is specified, the _source
    parameter defaults to false. You can pass _source: true to return both source fields
    and stored fields in the search response.
    **Repeatable:** pass `--stored-fields` multiple times to supply more than one value
  </definition>
  <definition term="--suggest-field string">
    Specifies which field to use for suggestions.
  </definition>
  <definition term="--suggest-mode enum">
    **Values:** missing, popular, always
  </definition>
  <definition term="--suggest-size number">
  </definition>
  <definition term="--suggest-text string">
    The source text for which the suggestions should be returned.
  </definition>
  <definition term="--terminate-after number">
    Maximum number of documents to collect for each shard. If a query reaches this
    limit, Elasticsearch terminates the query early. Elasticsearch collects documents
    before sorting. Defaults to 0, which does not terminate query execution early.
  </definition>
  <definition term="--timeout string">
    Specifies the period of time to wait for a response from each shard. If no response
    is received before the timeout expires, the request fails and returns an error.
    Defaults to no timeout.
  </definition>
  <definition term="--track-total-hits number">
    Number of hits matching the query to count accurately. If true, the exact
    number of hits is returned at the cost of some performance. If false, the
    response does not include the total number of hits matching the query.
    Defaults to 10,000 hits.
  </definition>
  <definition term="--track-scores">
    If true, calculate and return document scores, even if the scores are not used for sorting.
  </definition>
  <definition term="--typed-keys">
  </definition>
  <definition term="--rest-total-hits-as-int">
  </definition>
  <definition term="--version">
    If true, returns document version as part of a hit.
  </definition>
  <definition term="--source string">
    Indicates which source fields are returned for matching documents. These
    fields are returned in the hits._source property of the search response.
  </definition>
  <definition term="--source-excludes string">
    **Repeatable:** pass `--source-excludes` multiple times to supply more than one value
  </definition>
  <definition term="--source-includes string">
    **Repeatable:** pass `--source-includes` multiple times to supply more than one value
  </definition>
  <definition term="--seq-no-primary-term">
    If true, returns sequence number and primary term of the last modification
    of each hit. See Optimistic concurrency control.
  </definition>
  <definition term="--q string">
  </definition>
  <definition term="--size number">
    The number of hits to return. By default, you cannot page through more
    than 10,000 hits using the from and size parameters. To page through more
    hits, use the search_after parameter.
  </definition>
  <definition term="--from number">
    Starting document offset. By default, you cannot page through more than 10,000
    hits using the from and size parameters. To page through more hits, use the
    search_after parameter.
  </definition>
  <definition term="--sort string">
    **Repeatable:** pass `--sort` multiple times to supply more than one value
  </definition>
  <definition term="--wait-for-checkpoints string[]">
    A comma separated list of checkpoints. When configured, the search API will only be executed on a shard
    after the relevant checkpoint has become visible for search. Defaults to an empty list which will cause
    Elasticsearch to immediately execute the search.
    **Repeatable:** pass `--wait-for-checkpoints` multiple times to supply more than one value
  </definition>
  <definition term="--allow-partial-search-results">
    If true, returns partial results if there are shard request timeouts or shard failures.
    If false, returns an error with no partial results.
    Defaults to the configured cluster setting `search.default_allow_partial_results`, which is true by default.
  </definition>
  <definition term="--aggregations string">
  </definition>
  <definition term="--collapse string">
  </definition>
  <definition term="--ext string">
    Configuration of search extensions defined by Elasticsearch plugins.
  </definition>
  <definition term="--highlight string">
  </definition>
  <definition term="--indices-boost string[]">
    Boosts the _score of documents from specified indices.
    **Repeatable:** pass `--indices-boost` multiple times to supply more than one value
  </definition>
  <definition term="--min-score number">
    Minimum _score for matching documents. Documents with a lower _score are
    not included in search results and results collected by aggregations.
  </definition>
  <definition term="--post-filter string">
  </definition>
  <definition term="--profile">
  </definition>
  <definition term="--query string">
    Defines the search definition using the Query DSL.
  </definition>
  <definition term="--rescore string">
    **Repeatable:** pass `--rescore` multiple times to supply more than one value
  </definition>
  <definition term="--script-fields string">
    Retrieve a script evaluation (based on different fields) for each hit.
  </definition>
  <definition term="--search-after string[]">
    **Repeatable:** pass `--search-after` multiple times to supply more than one value
  </definition>
  <definition term="--slice string">
  </definition>
  <definition term="--fields string[]">
    Array of wildcard (*) patterns. The request returns values for field names
    matching these patterns in the hits.fields property of the response.
    **Repeatable:** pass `--fields` multiple times to supply more than one value
  </definition>
  <definition term="--suggest string">
  </definition>
  <definition term="--pit string">
    Limits the search to a point in time (PIT). If you provide a PIT, you
    cannot specify an <index> in the request path.
  </definition>
  <definition term="--runtime-mappings string">
    Defines one or more runtime fields in the search request. These fields take
    precedence over mapped fields with the same name.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>