【发布时间】:2021-06-03 13:56:45
【问题描述】:
我觉得在实践中试图让管道聚合做我想做的事。 我会发布我所拥有的,但想法:
- 创建一个日期范围,并为该范围内过去 10 个月的每个月创建存储桶。明白了。
- 获取每个桶的“大小”字段的最小值和最大值。我只能弄清楚如何使用“stats”agg 来做到这一点,因为如果我尝试将两者都作为单独的 aggs 执行,则会出现重复错误。然而,我不想要其他统计数据。我可以避免这个统计数据吗?
- 对分数求和。我到底是怎么做到的?那是在踢我的尾巴。不知道你能不能对 _score 字段求和。
所以这是我根据常见的地震概念练习的索引:
PUT _bulk
{ "index" : { "_index" : "earthquakes", "_id" : "1" } }
{ "date": "30-09-2020", "magnitude": "3.4", "lon": "74.12", "lat": "43.67" }
{ "index" : { "_index" : "earthquakes", "_id" : "2" } }
{ "date": "30-09-2020", "magnitude": "1.2", "lon": "78.02", "lat": "103.07" }
{ "index" : { "_index" : "earthquakes", "_id" : "3" } }
{ "date": "15-10-2020", "magnitude": "2.5", "lon": "178.02", "lat": "98.41" }
{ "index" : { "_index" : "earthquakes", "_id" : "4" } }
{ "date": "19-11-2020", "magnitude": "1.9", "lon": "14.67", "lat": "100.35" }
{ "index" : { "_index" : "earthquakes", "_id" : "5" } }
{ "date": "13-12-2020", "magnitude": "6.2", "lon": "123.93", "lat": "56.05" }
{ "index" : { "_index" : "earthquakes", "_id" : "6" } }
{ "date": "21-12-2020", "magnitude": "0.2", "lon": "130.31", "lat": "83.41" }
{ "index" : { "_index" : "earthquakes", "_id" : "7" } }
{ "date": "17-01-2021", "magnitude": "0.2", "lon": "10.31", "lat": "98.00" }
{ "index" : { "_index" : "earthquakes", "_id" : "8" } }
{ "date": "23-01-2021", "magnitude": "4.6", "lon": "112.31", "lat": "69.96" }
{ "index" : { "_index" : "earthquakes", "_id" : "9" } }
{ "date": "31-01-2021", "magnitude": "0.4", "lon": "79.43", "lat": "72.14" }
{ "index" : { "_index" : "earthquakes", "_id" : "10" } }
{ "date": "03-02-2021", "magnitude": "7.1", "lon": "120.80", "lat": "50.22" }
这是我汇总的内容。注意:在尝试对 _score 字段求和之前,我已将点击数设为 10...但没有发生:
GET earthquakes/_search
{
"size": 0,
"aggs": {
"range_mag": {
"date_range": {
"field": "date",
"ranges": [
{
"from": "now-10M",
"to": "now"
}
]
},
"aggs": {
"by_month_mag": {
"date_histogram": {
"field": "date",
"calendar_interval": "month"
},
"aggs": {
"stat_mag": {
"stats": {
"field": "magnitude"
}
}
}
}
}
}
}
}
^ 这可行,但要获得最小值和最大值,但会添加我不需要的数据。我没有把我的分数总和,因为它把我逼疯了。有没有更好的方法来完成我想做的事情? 不管怎样,谢谢。在我可以轻松输入或使用文档完成的所有内容中,聚合只是我认为我会得到的一件事,但不知何故觉得卡住了。
【问题讨论】:
-
这个问题几乎是完美的,你错过了映射。这些对我有用 PUT 地震 { "mappings" : { "properties" : { "date" : { "type" : "date", "format": "dd-MM-yyyy" }, "lat" : { "type" : "double" }, "lon" : { "type" : "double" }, "magnitude" : { "type" : "double" } } } }
-
添加了一个答案,分数总和你的意思是从字面上总结所有结果的分数吗?只是出于好奇:您为什么需要这样做?
-
刚刚添加了聚合来求和分数。如果有用,请记得将答案标记为正确,或者如果您需要其他任何内容,请告诉我。
-
llermaly,我没有提到我在索引模板中进行了显式映射来练习索引模板和映射。感谢您提醒我需要更加注意所有细节。是的,我的意思是所有结果的分数总和。为什么?因为这是我没能解决的任务。就那么简单。如果可能的话,我想我一直在努力学习。我开始怀念简单的事情,比如对“脚本”而不是“字段”求和。再次感谢您的帮助。
-
大多数问题没有示例数据、没有映射和/或没有查询,所以这是 9/10。很高兴为您提供帮助
标签: elasticsearch kibana elasticsearch-aggregation