You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Elasticsearch Watcher链式输入中传递结果至terms查询

问题原因

错误根源在第三个search输入的terms查询写法:你把{{ctx.payload.second._value}}套在了数组[]里,模板渲染时会把整个IP列表转换成单个字符串(如"{0=10.20.70.200, 1=10.20.70.210}"),但terms查询需要的是字符串数组,而非包含列表字符串的数组,导致Elasticsearch将这个字符串当作单个IP解析,触发格式非法报错。

解决方法

直接将source.ip的值设置为{{ctx.payload.second._value}}即可,无需额外套数组——因为_value本身已经是一个IP列表数组。

修改后的完整Watcher执行请求
POST _watcher/watch/_execute
{
  "watch": {
    "trigger": {
      "schedule": {
        "interval": "10s"
      }
    },
    "input": {
      "chain": {
        "inputs": [
          {
            "first": {
              "search": {
                "request": {
                  "indices": [
                    "test-index"
                  ],
                  "body": {
                    "size": 0,
                    "aggs": {
                      "destination_ip_aggs": {
                        "terms": {
                          "field": "destination.ip",
                          "size": 2
                        }
                      }
                    }
                  }
                }
              }
            }
          },
          {
            "second": {
              "transform": {
                "script": {
                  "lang": "painless",
                  "source": """List ips = new ArrayList();
        for(def bucket: ctx.payload.first.aggregations.destination_ip_aggs.buckets) {
          ips.add(bucket.key)
        }
    return ips;
    """
                }
              }
            }
          },
          {
            "third": {
              "search": {
                "request": {
                  "indices": [
                    "test-index"
                  ],
                  "body": {
                    "query": {
                      "terms": {
                        "source.ip": "{{ctx.payload.second._value}}"
                      }
                    }
                  }
                }
              }
            }
          }
        ]
      }
    },
    "actions": {
      "log_error": {
        "logging": {
          "text": "{{ctx.payload.second._value}}"
        }
      }
    }
  }
}
验证说明

修改后,第三个search的terms查询会直接使用_value对应的数组["10.20.70.200", "10.20.70.210"],完全符合Elasticsearch对terms查询参数的格式要求,不会再触发IP格式错误。

内容的提问来源于stack exchange,提问作者Bhavya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 23:47:45