You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch动态模板失效:匹配IP字段未按预期映射

Elasticsearch动态映射未匹配ip字段类型的解决方法

问题原因

你的动态模板配置中,match参数使用了数组["ip*", "*ip"],但Elasticsearch的match仅支持单个通配符模式,不接受数组形式,导致模板规则未被触发,字段被默认映射为text类型。

解决方案

使用match_pattern: "regex"启用正则匹配,通过正则表达式^ip.*|.*ip$匹配所有以ip开头或结尾的字段,同时保留match_mapping_type: "*"确保覆盖所有数据类型的字段。

正确配置示例

创建索引的请求:

PUT my-index
{
  "mappings": {
    "dynamic_templates": [
      {
        "ip_fields": {
          "match_mapping_type": "*",
          "match_pattern": "regex",
          "match": "^ip.*|.*ip$",
          "mapping": {
            "type": "ip"
          }
        }
      }
    ]
  }
}

插入测试文档:

PUT my-index/_doc/1
{
  "three_ip": "12.12.12.12", 
  "ip_four":  "13.13.13.13" 
}

验证结果

查看索引映射,会发现目标字段已正确设置为ip类型:

{
  "mappings": {
    "dynamic_templates": [
      {
        "ip_fields": {
          "match_pattern": "regex",
          "match": "^ip.*|.*ip$",
          "match_mapping_type": "*",
          "mapping": {
            "type": "ip"
          }
        }
      }
    ],
    "properties": {
      "ip_four": {
        "type": "ip"
      },
      "three_ip": {
        "type": "ip"
      }
    }
  }
}

内容的提问来源于stack exchange,提问作者pracsec

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 01:23:28