elasticsearch.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Thu, 25 Oct 2018 17:55:27 +0300
changeset 2280 9ffe47dfa862
parent 2279 8c9e8c734f98
child 2281 fdaa046f19ba
permissions -rw-r--r--
SQLcl : Format Query Results with the SET SQLFORMAT Command.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
===============
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
 elasticsearch
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
===============
2203
c9cc487f54a3 Kibana plugins.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2202
diff changeset
     5
.. contents::
c9cc487f54a3 Kibana plugins.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2202
diff changeset
     6
   :local:
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
     8
Elasticsearch documentation
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
     9
===========================
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    10
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    11
https://amsterdam.luminis.eu/2016/10/18/elasticsearch-5-is-coming-what-is-new-and-improved/
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    12
  New features of ES 5.
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    13
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    14
REST syntax conventions
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    15
=======================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    16
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    17
To get data in table form use ``/_cat`` endpoint::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    18
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    19
  GET /_cat/nodes
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    20
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    21
To pretty print output append query::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    22
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    23
  GET /_cat/nodes?pretty=1
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    24
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    25
Get base information
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    26
====================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    27
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    28
Cluster health::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    29
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    30
  GET /_cat/health?v
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    31
  GET /_cluster/health?pretty
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    32
  GET /_cluster/health?pretty&level=cluster
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    33
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    34
List of nodes in cluster (ip, RAM, CPU)::
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    35
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    36
  GET /_cat/nodes?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    37
  GET /_cat/master?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    38
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    39
  watch -d curl -s 'localhost:9200/_cat/nodes?v'
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    40
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    41
List cluster state::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    42
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    43
  GET /_cluster/state?pretty
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    44
2207
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    45
List of tasks executed in cluster::
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    46
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    47
  GET /_cat/tasks?v
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    48
  GET /_cat/tasks?detailed
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    49
  GET _tasks
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    50
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    51
List of indexes (status, health, size)::
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    52
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    53
  GET /_cat/indices
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    54
  GET /_cat/indices?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    55
  GET /_cat/indices?v&s=index
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    56
  GET /_cluster/health?pretty&level=indices
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    57
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    58
List of mappings across all indexes::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    59
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    60
  GET /_mapping
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    61
  GET /_all/_mapping
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    62
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    63
List of shards::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    64
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    65
  GET /_cluster/health?pretty&level=shards
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    66
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    67
https://www.elastic.co/guide/en/elasticsearch/reference/current/_cluster_health.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    68
  Cluster Health.
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    69
https://www.elastic.co/guide/en/elasticsearch/reference/current/_list_all_indices.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    70
  List All Indices.
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    71
https://www.elastic.co/guide/en/elasticsearch/reference/current/cat.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    72
  cat APIs.
2207
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    73
https://www.elastic.co/guide/en/elasticsearch/reference/current/tasks.html
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    74
  Task Management API.
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    75
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    76
Managing indexes
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    77
================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    78
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    79
Assign number of shards and replicas::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    80
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    81
  curl -XPUT -d '{settings: {index: "number_of_shards": 3, "number_of_replicas": 1}}'
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    82
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    83
https://www.elastic.co/guide/en/elasticsearch/reference/current/_delete_an_index.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    84
  Delete an Index.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    85
https://github.com/elastic/curator
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    86
  Manage/archive indices.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    87
https://www.elastic.co/guide/en/elasticsearch/client/curator/current/about.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    88
  Elasticsearch Curator helps you curate, or manage, your Elasticsearch indices and snapshots.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    89
https://www.elastic.co/guide/en/elasticsearch/client/curator/current/about-features.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    90
  Curator allows for many different operations to be performed to both indices and snapshots.
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    91
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    92
https://www.elastic.co/guide/en/elasticsearch/guide/current/retiring-data.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    93
  Retiring Data.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    94
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    95
Lucene search syntax
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    96
====================
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    97
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    98
``TERM1 TERM2`` is same as ``TERM1 OR TERM2``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    99
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   100
``"TERM1 TERM2"`` is for phrase.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   101
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   102
``"TERM1 TERM2"~5`` is for proximity.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   103
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   104
``TERM~0.8`` is for fuzzy.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   105
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   106
``*`` is for wildcard.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   107
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   108
Boosting is done with ``^N`` syntax, like ``TERM1^10 TERM2``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   109
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   110
Range with ``[2017-01-01 TO 2017-02-29]``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   111
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   112
Logical ``AND``, ``OR``, ``NOT`` and parentheses for grouping.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   113
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   114
Fields are set before colon, like ``FIELD:TERM``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   115
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   116
https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   117
  Query String Query
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   118
https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-simple-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   119
  Simple Query String Query
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   120
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   121
ES Query DSL
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   122
============
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   123
2239
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   124
``_exists_:<field>`` for testing field existence.
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   125
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   126
.. note:: ``_missing_:<field>`` was removed from Kibana 5.x, use ``NOT _exists_:<field>``.
2223
c50753af1f09 ES Query DSL.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2212
diff changeset
   127
2240
1a134a5d929f Fix example.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2239
diff changeset
   128
``-<field>:<val>`` or ``-<field>:"<val>"`` for excluding field value.
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   129
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
   130
``+<field>:<val>`` or ``+<field>:"<val>"`` for including field value.
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
   131
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   132
https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-exists-query.html
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   133
  Exists Query
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   134
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   135
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   136
Performance
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   137
===========
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   138
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   139
https://www.elastic.co/guide/en/elasticsearch/reference/5.5/search-profile.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   140
  Profile API.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   141
https://www.elastic.co/guide/en/elasticsearch/reference/current/_explain_analyze.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   142
  Explain Analyze.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   143
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-explain.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   144
  Explain API.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   145
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   146
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-disk-usage.html
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   147
  Tune for disk usage.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   148
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-indexing-speed.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   149
  Tune for indexing speed.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   150
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-search-speed.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   151
  Tune for search speed.
2269
7002dd57037b Added link.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2240
diff changeset
   152
https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster
7002dd57037b Added link.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2240
diff changeset
   153
  How many shards should I have in my Elasticsearch cluster?
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   154
https://www.elastic.co/blog/filebeat-modiles-access-logs-and-elasticsearch-storage-requirements
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   155
  Filebeat modules, access logs and Elasticsearch storage requirements.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   156
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   157
JSON search syntax
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   158
==================
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   159
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   160
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-from-size.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   161
  Search results pagination.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   162
https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   163
  Query String Query.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   164
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   165
  Aggregation.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   166
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   167
  Sort.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   168
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   169
Alerting
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   170
========
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   171
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   172
https://github.com/Yelp/elastalert
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   173
  Easy & Flexible Alerting With Elasticsearch.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   174
http://elastalert.readthedocs.io/en/latest/elastalert.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   175
  Easy & Flexible Alerting With Elasticsearch.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   176
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Alerts-in-Dashboard
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   177
  SENTINL Alerts in Dashboard.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   178
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Config-Example
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   179
  SENTINL Config Example
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   180
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Tutorial
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   181
  SENTINL Tutorial
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   182
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Watcher-Anatomy
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   183
  SENTINL Watcher Anatomy
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   184
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Watcher-Examples
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   185
  SENTINL Watcher Examples
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   186