【问题标题】:Apply filter in Elastic search query在弹性搜索查询中应用过滤器
【发布时间】:2018-02-06 15:54:15
【问题描述】:

我想在聚合查询后应用过滤器。例如,使用下面的聚合查询,我只想获取我们拥有所有窗口的那些条目。

注意:我们不必使用include,因为它使用正则表达式,这很耗时,我们不能忽略大小写。

查询:

GET /record_new/_search
{"size":0, "aggs" : {
        "software_tags" : {
            "terms" : {

                "field" : "software_tags.keyword",
                  "size" : 100


            }
        }
    }
}

回复:

{
  "took": 77,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 5706542,
    "max_score": 0,
    "hits": []
  },
  "aggregations": {
    "software_tags": {
      "doc_count_error_upper_bound": 5514,
      "sum_other_doc_count": 581800,
      "buckets": [
        {
          "key": "Microsoft Windows",
          "doc_count": 70641
        },
        {
          "key": "Bitcoin",
          "doc_count": 35423
        },
        {
          "key": "Linux",
          "doc_count": 33230
        },
        {
          "key": "ICQ",
          "doc_count": 21934
        },
        {
          "key": "PHP",
          "doc_count": 20562
        },
        {
          "key": "Windows XP",
          "doc_count": 19720
        },
        {
          "key": "Android (operating system)",
          "doc_count": 17774
        },
        {
          "key": "C++",
          "doc_count": 14792
        },
        {
          "key": "Pretty Good Privacy",
          "doc_count": 14307
        },
        {
          "key": "Tor (anonymity network)",
          "doc_count": 14110
        }
      ]
    }
  }
}

我也尝试过过滤,但没有得到不正确的输出。在输出中,我们也得到了 linux。我不知道这里发生了什么。

GET /record_new/_search
{"size":0, "query": {
    "constant_score": {
      "filter": 
        { "term": { "software_tags": "windows"   }}

    }
  }, "aggs" : {
        "software_tags" : {
            "terms" : {

                "field" : "software_tags.keyword",
                  "size" : 10


            }
        }
    }
}

输出:

{
  "took": 11,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 93181,
    "max_score": 0,
    "hits": []
  },
  "aggregations": {
    "software_tags": {
      "doc_count_error_upper_bound": 1640,
      "sum_other_doc_count": 171831,
      "buckets": [
        {
          "key": "Microsoft Windows",
          "doc_count": 70641
        },
        {
          "key": "Windows XP",
          "doc_count": 19720
        },
        {
          "key": "Windows 7",
          "doc_count": 12692
        },
        {
          "key": "Linux",
          "doc_count": 12311
        },
        {
          "key": "Windows Vista",
          "doc_count": 10172
        },
        {
          "key": "Windows NT",
          "doc_count": 5417
        },
        {
          "key": "Windows Registry",
          "doc_count": 5055
        },
        {
          "key": "Windows 8",
          "doc_count": 4829
        },
        {
          "key": "Windows 2000",
          "doc_count": 4738
        },
        {
          "key": "Windows 10",
          "doc_count": 4611
        }
      ]
    }
  }
}

【问题讨论】:

  • 请问为什么在聚合之前不对其进行过滤?所以你只聚合那些在 software_tags 中有 Windows 的?
  • @MrSimple 我已经用过滤器更新了问题。我收到不正确的回复。

标签: elasticsearch kibana


【解决方案1】:

试试这个查询,它应该在 software_tag 中寻找带有窗口的记录:

{
  "size":0,
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "software_tags: *windows* AND NOT *linux* AND NOT *<next OS name to exclude>*",
            "analyze_wildcard": true
          }
        }
      ]
    }
  }, "aggs" : {
        "software_tags" : {
            "terms" : {

                "field" : "software_tags.keyword",
                  "size" : 10


            }
        }
    }
}

它可能比通常的查询慢一点,但那是因为查询中的通配符。

【讨论】:

  • 你也在用kibana吗?如果是,请在“发现”菜单中尝试:software_tag: xwindowsx(通配符代替 x 标记)
  • 对不起,有一个错字,我写的是software_tag而不是software_tags
  • 它正在工作,但它仍然返回不相关的响应。如果您看到我提到的使用过滤器的输出。我们在输出中也得到了“Linux”。知道为什么会这样吗?
  • 我调整了查询​​,但由于我没有数据,我不确定它是否有帮助。希望它有效。
  • 如果软件标签不是数组,我认为您发送的查询是正确的。具有 values=["linux","Windows 7", "Windows XP"] 的 software_tags 也出现在解决方案中,因为我们在数组中有窗口。有什么方法可以从与正则表达式匹配的数组中获取该值
猜你喜欢
  • 1970-01-01
  • 2015-01-25
  • 2020-07-25
  • 2019-12-17
  • 2016-08-28
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多