elasticsearch.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Sun, 30 Dec 2018 17:41:54 +0200
changeset 2320 b7a2c43902f3
parent 2318 2463c53f0d9e
child 2321 77c3f7ddcb5f
permissions -rw-r--r--
Cygwin bash completion.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
===============
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
 elasticsearch
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
===============
2203
c9cc487f54a3 Kibana plugins.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2202
diff changeset
     5
.. contents::
c9cc487f54a3 Kibana plugins.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2202
diff changeset
     6
   :local:
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
     8
Elasticsearch documentation
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
     9
===========================
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    10
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    11
https://amsterdam.luminis.eu/2016/10/18/elasticsearch-5-is-coming-what-is-new-and-improved/
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    12
  New features of ES 5.
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
    13
2313
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    14
Releases
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    15
========
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    16
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    17
https://github.com/elastic/elasticsearch/releases
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    18
  Git releases & tags.
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    19
https://www.elastic.co/support/eol
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    20
  Elastic Product End of Life Dates.
ab4d0f12baa6 ES releases.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2281
diff changeset
    21
2318
2463c53f0d9e Install Elasticsearch with Debian Package.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2313
diff changeset
    22
Installing & configuring
2463c53f0d9e Install Elasticsearch with Debian Package.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2313
diff changeset
    23
========================
2463c53f0d9e Install Elasticsearch with Debian Package.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2313
diff changeset
    24
2463c53f0d9e Install Elasticsearch with Debian Package.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2313
diff changeset
    25
https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html
2463c53f0d9e Install Elasticsearch with Debian Package.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2313
diff changeset
    26
  Install Elasticsearch with Debian Package.
2463c53f0d9e Install Elasticsearch with Debian Package.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2313
diff changeset
    27
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    28
REST syntax conventions
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    29
=======================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    30
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    31
To get data in table form use ``/_cat`` endpoint::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    32
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    33
  GET /_cat/nodes
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    34
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    35
To pretty print output append query::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    36
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    37
  GET /_cat/nodes?pretty=1
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    38
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    39
Get base information
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    40
====================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    41
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    42
Cluster health::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    43
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    44
  GET /_cat/health?v
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    45
  GET /_cluster/health?pretty
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    46
  GET /_cluster/health?pretty&level=cluster
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    47
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    48
List of nodes in cluster (ip, RAM, CPU)::
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    49
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    50
  GET /_cat/nodes?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    51
  GET /_cat/master?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    52
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    53
  watch -d curl -s 'localhost:9200/_cat/nodes?v'
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
    54
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    55
List cluster state::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    56
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    57
  GET /_cluster/state?pretty
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    58
2207
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    59
List of tasks executed in cluster::
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    60
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    61
  GET /_cat/tasks?v
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    62
  GET /_cat/tasks?detailed
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    63
  GET _tasks
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    64
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    65
List of indexes (status, health, size)::
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    66
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    67
  GET /_cat/indices
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    68
  GET /_cat/indices?v
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    69
  GET /_cat/indices?v&s=index
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    70
  GET /_cluster/health?pretty&level=indices
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    71
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    72
List of mappings across all indexes::
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    73
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    74
  GET /_mapping
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    75
  GET /_all/_mapping
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    76
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    77
List of shards::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    78
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    79
  GET /_cluster/health?pretty&level=shards
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    80
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    81
https://www.elastic.co/guide/en/elasticsearch/reference/current/_cluster_health.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    82
  Cluster Health.
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    83
https://www.elastic.co/guide/en/elasticsearch/reference/current/_list_all_indices.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    84
  List All Indices.
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    85
https://www.elastic.co/guide/en/elasticsearch/reference/current/cat.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    86
  cat APIs.
2207
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    87
https://www.elastic.co/guide/en/elasticsearch/reference/current/tasks.html
5085ac83075b List of tasks executed in cluster.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2206
diff changeset
    88
  Task Management API.
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    89
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    90
Managing indexes
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    91
================
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    92
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    93
Assign number of shards and replicas::
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    94
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    95
  curl -XPUT -d '{settings: {index: "number_of_shards": 3, "number_of_replicas": 1}}'
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    96
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    97
https://www.elastic.co/guide/en/elasticsearch/reference/current/_delete_an_index.html
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    98
  Delete an Index.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
    99
https://github.com/elastic/curator
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   100
  Manage/archive indices.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   101
https://www.elastic.co/guide/en/elasticsearch/client/curator/current/about.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   102
  Elasticsearch Curator helps you curate, or manage, your Elasticsearch indices and snapshots.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   103
https://www.elastic.co/guide/en/elasticsearch/client/curator/current/about-features.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   104
  Curator allows for many different operations to be performed to both indices and snapshots.
2199
47cadb10f1df Get base information.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
   105
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   106
https://www.elastic.co/guide/en/elasticsearch/guide/current/retiring-data.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   107
  Retiring Data.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   108
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   109
Lucene search syntax
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   110
====================
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   111
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   112
``TERM1 TERM2`` is same as ``TERM1 OR TERM2``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   113
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   114
``"TERM1 TERM2"`` is for phrase.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   115
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   116
``"TERM1 TERM2"~5`` is for proximity.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   117
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   118
``TERM~0.8`` is for fuzzy.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   119
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   120
``*`` is for wildcard.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   121
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   122
Boosting is done with ``^N`` syntax, like ``TERM1^10 TERM2``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   123
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   124
Range with ``[2017-01-01 TO 2017-02-29]``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   125
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   126
Logical ``AND``, ``OR``, ``NOT`` and parentheses for grouping.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   127
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   128
Fields are set before colon, like ``FIELD:TERM``.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   129
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   130
https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   131
  Query String Query
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   132
https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-simple-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   133
  Simple Query String Query
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   134
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   135
ES Query DSL
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   136
============
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   137
2239
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   138
``_exists_:<field>`` for testing field existence.
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   139
a7449247c914 _missing_:<field> was removed from Kibana 5.x.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2223
diff changeset
   140
.. note:: ``_missing_:<field>`` was removed from Kibana 5.x, use ``NOT _exists_:<field>``.
2223
c50753af1f09 ES Query DSL.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2212
diff changeset
   141
2240
1a134a5d929f Fix example.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2239
diff changeset
   142
``-<field>:<val>`` or ``-<field>:"<val>"`` for excluding field value.
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   143
2279
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
   144
``+<field>:<val>`` or ``+<field>:"<val>"`` for including field value.
8c9e8c734f98 Added more examples.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2269
diff changeset
   145
2212
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   146
https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-exists-query.html
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   147
  Exists Query
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   148
aec79721c8aa Fix typo.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2207
diff changeset
   149
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   150
Performance
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   151
===========
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   152
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   153
https://www.elastic.co/guide/en/elasticsearch/reference/5.5/search-profile.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   154
  Profile API.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   155
https://www.elastic.co/guide/en/elasticsearch/reference/current/_explain_analyze.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   156
  Explain Analyze.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   157
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-explain.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   158
  Explain API.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   159
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   160
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-disk-usage.html
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   161
  Tune for disk usage.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   162
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-indexing-speed.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   163
  Tune for indexing speed.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   164
https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-search-speed.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   165
  Tune for search speed.
2269
7002dd57037b Added link.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2240
diff changeset
   166
https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster
7002dd57037b Added link.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2240
diff changeset
   167
  How many shards should I have in my Elasticsearch cluster?
2206
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   168
https://www.elastic.co/blog/filebeat-modiles-access-logs-and-elasticsearch-storage-requirements
e765d2924785 Tune for disk usage.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2203
diff changeset
   169
  Filebeat modules, access logs and Elasticsearch storage requirements.
2281
fdaa046f19ba Setting the heap size.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2279
diff changeset
   170
https://www.elastic.co/guide/en/elasticsearch/reference/master/heap-size.html
fdaa046f19ba Setting the heap size.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2279
diff changeset
   171
  Setting the heap size.
2202
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   172
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   173
JSON search syntax
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   174
==================
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   175
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   176
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-from-size.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   177
  Search results pagination.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   178
https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   179
  Query String Query.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   180
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   181
  Aggregation.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   182
https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   183
  Sort.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   184
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   185
Alerting
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   186
========
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   187
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   188
https://github.com/Yelp/elastalert
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   189
  Easy & Flexible Alerting With Elasticsearch.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   190
http://elastalert.readthedocs.io/en/latest/elastalert.html
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   191
  Easy & Flexible Alerting With Elasticsearch.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   192
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Alerts-in-Dashboard
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   193
  SENTINL Alerts in Dashboard.
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   194
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Config-Example
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   195
  SENTINL Config Example
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   196
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Tutorial
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   197
  SENTINL Tutorial
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   198
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Watcher-Anatomy
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   199
  SENTINL Watcher Anatomy
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   200
https://github.com/sirensolutions/sentinl/wiki/SENTINL-Watcher-Examples
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   201
  SENTINL Watcher Examples
37bf9f7b8560 Managing indexes. Lucene search syntax. Performance. JSON search syntax. Alerting.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 2199
diff changeset
   202