# System Indices

**URL:** <https://discuss.elastic.co/t/system-indices/186894>\
**Category:** Elasticsearch\
**Created:** [June 21, 2019, 2:07pm UTC](https://discuss.elastic.co/t/system-indices/186894 "2019-06-21T14:07:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Necus](https://avatars.discourse-cdn.com/v4/letter/n/e47774/32.png) [@Necus](https://discuss.elastic.co/u/Necus)\
**Post date:** [June 21, 2019, 2:07pm UTC](https://discuss.elastic.co/t/system-indices/186894/1 "2019-06-21T14:07:10Z")

</div>

Hello,  
Is there a way to search through all of the fields in system indices?  
For example

## .monitoring-es-6-YYYY.MM.DD

and fields:  
cluster\_name  
cluster\_state.cluster\_uuid  
etc.

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [June 25, 2019, 1:32am UTC](https://discuss.elastic.co/t/system-indices/186894/2 "2019-06-25T01:32:19Z")

</div>

Hi,

For example search for text that start with "new" in all fields of all monitoring indices:

> GET .monitoring-es-6-_/\_search?q=new_

You can check more about query syntax here:

> **[Query string query | Elasticsearch Guide \[7.2\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/query-dsl-query-string-query.html#query-string-syntax)**

If you search in a limited fields list maybe better to check about multi\_match

> **[Multi-match query | Elasticsearch Guide \[7.1\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/query-dsl-multi-match-query.html)**

---

<div class="post-metadata">

**Author:** ![Necus](https://avatars.discourse-cdn.com/v4/letter/n/e47774/32.png) [@Necus](https://discuss.elastic.co/u/Necus)\
**Post date:** [July 4, 2019, 2:00pm UTC](https://discuss.elastic.co/t/system-indices/186894/3 "2019-07-04T14:00:09Z")

</div>

Unfortunatelly it does not work, for some reasone (unknown to me) cluster name and other importart for me fields are in those standard and regular indices unsearchable.  
{  
"took" : 31,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 1,  
"successful" : 1,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : 0,  
"max\_score" : null,  
"hits" :   
}  
}

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [July 4, 2019, 2:04pm UTC](https://discuss.elastic.co/t/system-indices/186894/4 "2019-07-04T14:04:14Z")

</div>

Hi @Necus

Can you provide the search request you run? it may help to understand your problem and find a solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2019, 2:04pm UTC](https://discuss.elastic.co/t/system-indices/186894/5 "2019-08-01T14:04:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
