elasticsearch.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Sun, 30 Dec 2018 00:46:36 +0200
changeset 2317 897bb1696e5f
parent 2313 ab4d0f12baa6
child 2318 2463c53f0d9e
permissions -rw-r--r--
LXC releases. Supported templates.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
===============
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
 elasticsearch
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
===============
2203
c9cc487f54a3 Kibana plugins.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2202
diff changeset
     5
.. contents::
c9cc487f54a3 Kibana plugins.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2202
diff changeset
     6
   :local:
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
     8
Elasticsearch documentation
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
     9
===========================
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    10
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    11
https://amsterdam.luminis.eu/2016/10/18/elasticsearch-5-is-coming-what-is-new-and-improved/
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    12
  New features of ES 5.
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    13
2313
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    14
Releases
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    15
========
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    16
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    17
https://github.com/elastic/elasticsearch/releases
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    18
  Git releases & tags.
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    19
https://www.elastic.co/support/eol
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    20
  Elastic Product End of Life Dates.
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    21
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    22
REST syntax conventions
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    23
=======================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    24
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    25
To get data in table form use ``/_cat`` endpoint::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    26
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    27
  GET /_cat/nodes
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    28
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    29
To pretty print output append query::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    30
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    31
  GET /_cat/nodes?pretty=1
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    32
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    33
Get base information
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    34
====================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    35
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    36
Cluster health::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    37
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    38
  GET /_cat/health?v
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    39
  GET /_cluster/health?pretty
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    40
  GET /_cluster/health?pretty&level=cluster
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    41
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    42
List of nodes in cluster (ip, RAM, CPU)::
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    43
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    44
  GET /_cat/nodes?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    45
  GET /_cat/master?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    46
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    47
  watch -d curl -s 'localhost:9200/_cat/nodes?v'
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    48
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    49
List cluster state::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    50
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    51
  GET /_cluster/state?pretty
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    52
2207
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    53
List of tasks executed in cluster::
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    54
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    55
  GET /_cat/tasks?v
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    56
  GET /_cat/tasks?detailed
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    57
  GET _tasks
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    58
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    59
List of indexes (status, health, size)::
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    60
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    61
  GET /_cat/indices
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    62
  GET /_cat/indices?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    63
  GET /_cat/indices?v&s=index
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    64
  GET /_cluster/health?pretty&level=indices
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    65
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    66
List of mappings across all indexes::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    67
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    68
  GET /_mapping
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    69
  GET /_all/_mapping
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    70
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    71
List of shards::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    72
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    73
  GET /_cluster/health?pretty&level=shards
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    74
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    75
https://www.elastic.co/guide/en/elasticsearch/reference/current/_cluster_health.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    76
  Cluster Health.
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    77
https://www.elastic.co/guide/en/elasticsearch/reference/current/_list_all_indices.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    78
  List All Indices.
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    79
https://www.elastic.co/guide/en/elasticsearch/reference/current/cat.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    80
  cat APIs.
2207
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    81
https://www.elastic.co/guide/en/elasticsearch/reference/current/tasks.html
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    82
  Task Management API.
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    83
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    84
Managing indexes
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    85
================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    86
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    87
Assign number of shards and replicas::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    88
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    89
  curl -XPUT -d '{settings: {index: "number_of_shards": 3, "number_of_replicas": 1}}'
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    90
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    91
https://www.elastic.co/guide/en/elasticsearch/reference/current/_delete_an_index.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    92
  Delete an Index.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    93
https://github.com/elastic/curator
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    94
  Manage/archive indices.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    95
https://www.elastic.co/guide/en/elasticsearch/client/curator/current/about.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    96
  Elasticsearch Curator helps you curate, or manage, your Elasticsearch indices and snapshots.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    97
https://www.elastic.co/guide/en/elasticsearch/client/curator/current/about-features.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    98
  Curator allows for many different operations to be performed to both indices and snapshots.
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    99
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   100
https://www.elastic.co/guide/en/elasticsearch/guide/current/retiring-data.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   101
  Retiring Data.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   102
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   103
Lucene search syntax
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   104
====================
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   105
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   106
``TERM1 TERM2`` is same as ``TERM1 OR TERM2``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   107
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   108
``"TERM1 TERM2"`` is for phrase.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   109
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   110
``"TERM1 TERM2"~5`` is for proximity.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   111
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   112
``TERM~0.8`` is for fuzzy.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   113
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   114
``*`` is for wildcard.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   115
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   116
Boosting is done with ``^N`` syntax, like ``TERM1^10 TERM2``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   117
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   118
Range with ``[2017-01-01 TO 2017-02-29]``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   119
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   120
Logical ``AND``, ``OR``, ``NOT`` and parentheses for grouping.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   121
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   122
Fields are set before colon, like ``FIELD:TERM``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   123
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   124
https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   125
  Query String Query
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   126
https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-simple-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   127
  Simple Query String Query
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   128
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   129
ES Query DSL
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   130
============
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   131
2239
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   132
``_exists_:<field>`` for testing field existence.
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   133
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   134
.. note:: ``_missing_:<field>`` was removed from Kibana 5.x, use ``NOT _exists_:<field>``.
2223
c50753af1f09 ES Query DSL.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2212
diff changeset
   135
2240
1a134a5d929f Fix example.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2239
diff changeset
   136
``-<field>:<val>`` or ``-<field>:"<val>"`` for excluding field value.
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   137
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
   138
``+<field>:<val>`` or ``+<field>:"<val>"`` for including field value.
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
   139
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   140
https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-exists-query.html
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   141
  Exists Query
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   142
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   143
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   144
Performance
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   145
===========
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   146
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   147
https://www.elastic.co/guide/en/elasticsearch/reference/5.5/search-profile.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   148
  Profile API.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   149
https://www.elastic.co/guide/en/elasticsearch/reference/current/_explain_analyze.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   150
  Explain Analyze.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   151
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-explain.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   152
  Explain API.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   153
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   154
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-disk-usage.html
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   155
  Tune for disk usage.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   156
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-indexing-speed.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   157
  Tune for indexing speed.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   158
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-search-speed.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   159
  Tune for search speed.
2269
7002dd57037b Added link.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2240
diff changeset
   160
https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster
7002dd57037b Added link.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2240
diff changeset
   161
  How many shards should I have in my Elasticsearch cluster?
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   162
https://www.elastic.co/blog/filebeat-modiles-access-logs-and-elasticsearch-storage-requirements
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   163
  Filebeat modules, access logs and Elasticsearch storage requirements.
2281
fdaa046f19ba Setting the heap size.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2279
diff changeset
   164
https://www.elastic.co/guide/en/elasticsearch/reference/master/heap-size.html
fdaa046f19ba Setting the heap size.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2279
diff changeset
   165
  Setting the heap size.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   166
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   167
JSON search syntax
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   168
==================
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   169
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   170
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-from-size.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   171
  Search results pagination.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   172
https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   173
  Query String Query.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   174
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   175
  Aggregation.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   176
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   177
  Sort.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   178
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   179
Alerting
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   180
========
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   181
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   182
https://github.com/Yelp/elastalert
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   183
  Easy & Flexible Alerting With Elasticsearch.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   184
http://elastalert.readthedocs.io/en/latest/elastalert.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   185
  Easy & Flexible Alerting With Elasticsearch.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   186
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Alerts-in-Dashboard
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   187
  SENTINL Alerts in Dashboard.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   188
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Config-Example
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   189
  SENTINL Config Example
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   190
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Tutorial
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   191
  SENTINL Tutorial
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   192
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Watcher-Anatomy
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   193
  SENTINL Watcher Anatomy
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   194
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Watcher-Examples
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   195
  SENTINL Watcher Examples
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   196