Exists Query无结果返回:如何查询特定字段所有值且排除元字段?
解决方案
问题分析
- 元字段冗余:默认查询会返回
_index、_id、_source等元字段,需要显式关闭这类字段返回。 - 结果量少:原查询中
exists条件检查的是failure_error_code.keyword子字段,而非原始字段failure_error_code,可能导致部分存在原始字段但子字段未生成的文档被过滤;同时原时间范围是1年,与你提到的"近90天"不符。 - 效率问题:直接返回29k+条文档性能较低,推荐用聚合获取所有唯一错误码,而非逐条返回文档。
方案1:返回所有符合条件的文档(无元字段)
GET rds_database-*/_search { "_source": false, // 关闭所有元字段返回 "size": 29344, // 设置为近90天文档总数,确保返回全部结果 "fields": [ "failure_error_code.keyword" ], "query": { "bool": { "filter": [ { "term": { "status.keyword": "F" } }, { "exists": { "field": "failure_error_code" // 检查原始字段是否存在,避免遗漏 } }, { "range": { "@timestamp": { "gte": "now-90d/d", // 修正为近90天范围 "lte": "now/d" } } } ] } } }
方案2:聚合获取所有唯一错误码(推荐,性能更优)
无需返回每条文档,直接统计所有不同的failure_error_code值及出现次数:
GET rds_database-*/_search { "_source": false, "size": 0, // 不返回具体文档,仅返回聚合结果 "query": { "bool": { "filter": [ { "term": { "status.keyword": "F" } }, { "exists": { "field": "failure_error_code" } }, { "range": { "@timestamp": { "gte": "now-90d/d", "lte": "now/d" } } } ] } }, "aggs": { "all_failure_codes": { "terms": { "field": "failure_error_code.keyword", "size": 10000 // 设置足够大的值,确保包含所有唯一错误码(默认仅返回10个) } } } }
内容的提问来源于stack exchange,提问作者Aniket Pant
相关产品推荐
相关产品推荐

