Elasticsearch Patterns
vibeeval/vibecosystem
Mapping design, query optimization, aggregation patterns, index lifecycle management, and search relevance tuning.
Diagnose slow Elasticsearch Query DSL searches and propose measured fixes.
$ npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills elasticsearch-query-optimization --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-query-optimization .claude/skills/elasticsearch-query-optimization && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "elasticsearch-query-optimization" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimization into .claude/skills/elasticsearch-query-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-query-optimization", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimizationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills elasticsearch-query-optimization --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-query-optimization .agents/skills/elasticsearch-query-optimization && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "elasticsearch-query-optimization" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimization into .agents/skills/elasticsearch-query-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-query-optimization", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills elasticsearch-query-optimization --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-query-optimization .cursor/skills/elasticsearch-query-optimization && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "elasticsearch-query-optimization" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimization into .cursor/skills/elasticsearch-query-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-query-optimization", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/elasticsearch/elasticsearch-query-optimization--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills elasticsearch-query-optimization --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-query-optimization .gemini/skills/elasticsearch-query-optimization && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "elasticsearch-query-optimization" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimization into .gemini/skills/elasticsearch-query-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-query-optimization", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills elasticsearch-query-optimizationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-query-optimization .github/skills/elasticsearch-query-optimization && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-query-optimization" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimization into .github/skills/elasticsearch-query-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-query-optimization", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills elasticsearch-query-optimization --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-query-optimization .opencode/skills/elasticsearch-query-optimization && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-query-optimization" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-query-optimization into .opencode/skills/elasticsearch-query-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-query-optimization", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
elasticsearch-query-optimizationDiagnose slow Elasticsearch Query DSL searches and propose measured fixes.
Elasticsearch Query Optimization is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Diagnose slow Elasticsearch Query DSL searches and propose measured fixes. Use when a search is slow, profile output shows an expensive clause, exact-match filters sit in scoring context, or leading wildcards dominate latency. Ground every recommendation in search profiling — move non-scoring clauses to filter context, eliminate leading wildcards, and re-profile to confirm improvement.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/query-optimization-reference.md`). Compatibility notes: Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; relies on the search profiling API available on all deployment…
It sits in Backend & APIs, covering Search implementation and Query optimization. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; relies on the search profiling API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support.
From compatibility in the SKILL.md frontmatter.
Elasticsearch Query Optimization loads about 2.8k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,200 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,200 words, ~2,824 tokens.
.claude/skills/elasticsearch-query-optimization/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Diagnose why a Query DSL search is slow, identify the dominant cost from the profile (not guesswork), rewrite the query to remove that cost while preserving match semantics, and re-measure with profiling enabled.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
Scope: Query DSL searches via
POST /{index}/_search. This skill does not migrate queries to ES|QL — it optimizes the existing bool/match/term/wildcard structure the user already runs.Ground rule: Never recommend "add shards" or "scale hardware" as the primary fix when the profile names a specific clause (for example
WildcardQueryat ~3.8s). Fix the query first; infrastructure changes require evidence the query is already optimal.
Confirm connectivity and locate the target index. Call GET /. If the call fails, stop — do not guess endpoints
or credentials. When the user names an index pattern (for example logs-*), narrow candidates with
GET /_cat/indices and pick the index or pattern the query actually targets.
Decision: proceed only when the index is known. Data needed: index name or pattern, and the slow Query DSL body (from the user or from a saved search).
Profile the slow query to find the dominant cost. Call POST /{index}/_search with "profile": true and the
user's query unchanged. Read took, then inspect profile.shards[].searches[].query — sort child collectors by
time_in_nanos and identify the top contributor.
Decision: classify the bottleneck from profile evidence:
TermQuery / PointRangeQuery / MatchNoDocsQuery inside must alongside a scoring clause — exact-match or
range filters are being scored unnecessarily. Likely fix: move them to filter context (step 4a).WildcardQuery with a leading * (for example message:*timeout*) — cannot use the inverted index; scans
terms per document. Likely fix: remove the leading wildcard (step 4b).MatchQuery on a text field — expected scoring cost; optimize only if profile shows it dominates after
filter-context fixes.aggregation time — separate from query tuning; profile the agg tree (out of scope unless the user asked
about aggs).Data needed: profile tree with type, description, time_in_nanos, and breakdown (especially next_doc for
wildcards). Quote the top contributor verbatim when explaining the diagnosis.
Inspect field mappings before rewriting. Call GET /{index}/_mapping. For every clause you will move or rewrite,
confirm the field type:
term / terms / filter on exact values — field must be keyword (or another non-analyzed type). A term
on a text field is a common bug; if types are wrong, say so and suggest the correct sub-field (for example
service.keyword) or a mapping change — do not silently rewrite.match / match_phrase — target a text field (analyzed).wildcard — works on keyword or wildcard types; leading * still forces a scan regardless of type.Decision: only propose rewrites that match confirmed types. Data needed: mapping for each field referenced in the query.
Rewrite the query to remove the profiled bottleneck.
must to filterWhen exact-match term/terms/range/match on a keyword (or other non-scoring intent) clauses sit in must
alongside a full-text match that should drive relevance:
bool.filter (or a filter array entry)._score in bool.must (typically the full-text match).Why: filter context skips scoring and participates in the filter/bitset cache on repeated queries. Semantics: the same documents match; only scoring and performance change — state this explicitly.
Example rewrite pattern:
{
"query": {
"bool": {
"filter": [{ "term": { "status": "active" } }, { "term": { "tenant_id": "acme" } }],
"must": [{ "match": { "description": "wireless keyboard" } }]
}
}
}When the profile shows WildcardQuery with description like message:*timeout* and high next_doc time, the
leading * prevents index lookup. Choose a fix based on mapping and user intent (substring vs prefix vs exact):
| Intent | Preferred rewrite |
|---|---|
| Full-text substring in logs | match or match_phrase on the analyzed message text field |
| Literal substring on keyword | wildcard-typed field, or reindex with ngram analyzer |
Prefix only (timeout*) | prefix query on keyword, or edge ngram at index time |
Also move any non-scoring exact match (for example { "match": { "service": "checkout" } } on a keyword) into
filter — use term on the keyword field when the mapping confirms it.
Example rewrite pattern:
{
"query": {
"bool": {
"filter": [{ "term": { "service.keyword": "checkout" } }],
"must": [{ "match": { "message": "timeout" } }]
}
}
}Adjust field names (service vs service.keyword) to match the mapping from step 3.
When semantics are uncertain (for example changing wildcard to match may include analyzed tokens the wildcard
excluded), call POST /{index}/_validate/query?explain=true with the rewritten query and read the explanation for
obvious mismatches.
Decision: pick the smallest rewrite that addresses the profiled cost. Data needed: rewritten Query DSL body.
Re-profile the rewritten query and compare. Call POST /{index}/_search again with "profile": true and the
rewritten query. Compare took and the top profile collector to the baseline from step 2.
Decision: report success only when the dominant collector changed or time_in_nanos dropped materially. If the
profile still shows a leading wildcard or scored filters, iterate — do not declare victory from took alone without
profile confirmation.
Data needed: before/after profile summaries (top collector type, description, time_in_nanos).
Report findings in this order.
WildcardQuery message:*timeout* ≈ 3.8s, mostly next_doc").GET /{index}/_mapping.took from step 5.match vs substring
wildcard).must when a text query drives ranking.match/match_phrase; reserve
wildcard for suffix patterns (timeout*) on keyword or wildcard-typed fields.mustInput: bool.must contains term on status, term on tenant_id, and match on description.
Diagnosis: profile shows scored TermQuery collectors alongside MatchQuery; exact filters do not need scoring.
Fix: move both term clauses to filter; keep match in must. Confirm status and tenant_id are keyword.
Input: wildcard message:*timeout* plus match on service in must. Profile: WildcardQuery ~3.8s.
Diagnosis: leading * forces term enumeration; not an index/shard problem.
Fix: match on analyzed message; move service to filter as term on keyword. Re-profile — expect
WildcardQuery to disappear or shrink to negligible time.
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET / | elastic es info |
GET /_cat/indices | elastic es cat indices --index '<pattern>' |
GET /{index}/_mapping | elastic es indices get-mapping --index '<index>' |
POST /{index}/_search | elastic es search --index '<index>' --input-file '<search-body.json>' |
POST /{index}/_validate/query?explain=true | elastic es indices validate-query --index '<index>' --explain true --query '<json>' |
Include "profile": true in the search JSON body (or pass --profile true) when profiling in steps 2 and 5.
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/elasticsearch/elasticsearch-query-optimization of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Elasticsearch Query Optimization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Elasticsearch Query Optimization this skillelastic/agent-skills | 592 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch Patternsvibeeval/vibecosystem | 531 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence | |
| Foundatio Repositoriesexceptionless/Exceptionless | 2.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch Authnaspectrr/deer | 405 | — | ~1.2k | Automated safety check: Notes | MIT | |
| Elasticsearch Authzaspectrr/deer | 405 | — | ~1.8k | Automated safety check: Pass | MIT |
vibeeval/vibecosystem
Mapping design, query optimization, aggregation patterns, index lifecycle management, and search relevance tuning.
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
exceptionless/Exceptionless
Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.
aspectrr/deer
Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.
aspectrr/deer
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.
aspectrr/deer
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Diagnose slow Elasticsearch Query DSL searches and propose measured fixes. Elasticsearch Query Optimization is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Diagnose slow Elasticsearch Query DSL searches and propose measured fixes.
Elasticsearch Query Optimization fits situations like: A search is slow; profile output shows an expensive clause; exact-match filters sit in scoring context; leading wildcards dominate latency.
Run `npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-query-optimization in elastic/agent-skills) into .claude/skills/elasticsearch-query-optimization in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-query-optimization in elastic/agent-skills) into .agents/skills/elasticsearch-query-optimization in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-query-optimization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-query-optimization, .gemini/skills/elasticsearch-query-optimization, .github/skills/elasticsearch-query-optimization and .opencode/skills/elasticsearch-query-optimization in your project.
SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Query Optimization is instructions for the agent only. Compatibility (from SKILL.md): Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; relies on the search profiling API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support..
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Elasticsearch Query Optimization is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Elasticsearch Query Optimization: Elasticsearch Patterns (vibeeval/vibecosystem, 531 stars), Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars) and Elasticsearch Authn (aspectrr/deer, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 2, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.