Elasticsearch指标数据流字段映射冲突排查查询需求
区分目标字段类型的指标数据流索引查询方案
针对映射冲突问题,以下是两种查询语句,分别筛选出目标字段为float和keyword类型的指标数据流索引,同时通过@timestamp缩小时间范围:
1. 查询目标字段为float类型的索引
使用_search API结合聚合获取符合条件的索引列表:
GET _all/_search { "size": 0, "query": { "bool": { "must": [ {"exists": {"field": "your_target_field"}}, {"term": {"_mapping.your_target_field.type": "float"}}, {"range": {"@timestamp": {"gte": "2024-01-01T00:00:00Z", "lte": "2024-06-01T00:00:00Z"}}}, {"prefix": {"_index": "metric-"}} // 替换为你的指标数据流索引前缀 ] } }, "aggs": { "float_indices": { "terms": {"field": "_index", "size": 1000} } } }
2. 查询目标字段为keyword类型的索引
仅修改字段类型的匹配条件即可:
GET _all/_search { "size": 0, "query": { "bool": { "must": [ {"exists": {"field": "your_target_field"}}, {"term": {"_mapping.your_target_field.type": "keyword"}}, {"range": {"@timestamp": {"gte": "2024-01-01T00:00:00Z", "lte": "2024-06-01T00:00:00Z"}}}, {"prefix": {"_index": "metric-"}} // 替换为你的指标数据流索引前缀 ] } }, "aggs": { "keyword_indices": { "terms": {"field": "_index", "size": 1000} } } }
更直观的列表式查询
如果需要直接查看索引创建时间和字段类型,使用_cat/indices API更便捷:
# 查询float类型字段的索引 GET _cat/indices/metric-*/?v&h=index,creation.date.string,mapping.your_target_field.type&q=your_target_field:* AND @timestamp:[2024-01-01T00:00:00Z TO 2024-06-01T00:00:00Z] # 查询keyword类型字段的索引 GET _cat/indices/metric-*/?v&h=index,creation.date.string,mapping.your_target_field.type&q=your_target_field:* AND _mapping.your_target_field.type:keyword AND @timestamp:[2024-01-01T00:00:00Z TO 2024-06-01T00:00:00Z]
注意事项
- 替换
your_target_field为实际字段名,metric-为你的指标数据流索引前缀,时间范围按需调整。 size:1000确保能获取到足够多的索引,若索引数量超过1000,可适当增大该值。
内容的提问来源于stack exchange,提问作者Dave
相关产品推荐
相关产品推荐

