如何将Ingest Pipeline关联至现有Elasticsearch索引?
将Ingest Pipeline关联至现有Elasticsearch索引
你已经创建了一个用于添加摄入时间戳的Ingest Pipeline,代码如下:
PUT _ingest/pipeline/my_timestamp_pipeline { "description": "Adds a field to a document with the time of ingestion", "processors": [ { "set": { "field": "ingest_timestamp", "value": "{{_ingest.timestamp}}" } } ] }
该Pipeline会为每个经过处理的文档添加ingest_timestamp字段,值为文档被摄入时的时间。你通过写入测试文档:
PUT my_index/_doc/1 { "foo": "bar" }
检索后已确认字段成功添加:
{ "_index" : "my_index", "_type" : "_doc", "_id" : "1", "_version" : 1, "found" : true, "_source" : { "foo" : "bar", "ingest_timestamp" : "2018-12-12T12:04:09.921Z" } }
关联Pipeline至现有索引的两种方式
1. 设置索引默认Pipeline(自动处理后续写入文档)
执行以下命令,将你的Pipeline设为目标索引的默认处理流程,后续所有写入该索引的文档都会自动经过这个Pipeline处理:
PUT my_index/_settings { "index.default_pipeline": "my_timestamp_pipeline" }
2. 为现有文档批量应用Pipeline
如果需要给索引中已存在的文档也添加上ingest_timestamp字段,可使用_update_by_query API批量处理:
POST my_index/_update_by_query?pipeline=my_timestamp_pipeline
该命令会遍历索引内所有文档,将Pipeline逻辑应用到每一个文档上,完成字段添加。
内容的提问来源于stack exchange,提问作者caprio
相关产品推荐
相关产品推荐

