Evidence-backed facts
- Elasticsearch exposes GET and POST search operations across clusters, indexes, data streams, and aliases with explicit request and response contracts. informative
- Searching a secured target requires the applicable read index privilege, and cross-cluster or point-in-time searches add their own privilege boundaries. informative
- Indexing, updating, deleting, API-key creation, and security changes are different operations and cannot be inferred from search access. informative
- Bearer, basic, and API-key credentials are secrets; a search response does not prove completeness, freshness, exact ranking, mutation authority, or production integration. informative