如何修改超大ElasticSearch索引的嵌套字段映射为IP类型?
问题:嵌套文本字段无法转换为IP类型
我尝试过某解决方案,但对我无效。我需要将类似*one.second.third*的嵌套文本字段转换为IP类型,于是添加了如下映射:
PUT .the-index-2022.12.20-0000025/_mapping { "properties": { "one": { "type": "object", "properties": { "second": { "type":"object", "properties": { "ip_address1": { "type": "ip" }, "ip_address2": { "type": "ip" } } } } } } }
随后执行了更新命令:
POST .the-index-2022.12.20-0000025/_update_by_query?wait_for_completion=false&slices=auto
命令执行成功,但字段类型仍未改为IP。我又尝试了简化版的映射:
PUT .the-index-2022.12.20-0000025/_mapping { "properties": { "one": { "properties": { "second": { "properties": { "ip_address1": { "type": "ip" }, "ip_address2": { "type": "ip" } } } } } } }
目前我已添加3个新的IP类型字段,当前映射情况如下:
{ ".the-index-2022.12.20-0000025" : { "mappings" : { "one.sec.ip1" : { "full_name" : "one.sec.ip1", "mapping" : { "ip1" : { "type" : "ip" } } }, "one.sec.ip2" : { "full_name" : "one.sec.ip2", "mapping" : { "ip2" : { "type" : "ip" } } }, "one.sec.ip3" : { "full_name" : "one.sec.ip3", "mapping" : { "ip3" : { "type" : "ip" } } } } } }

请问问题出在哪里,还有什么解决办法?
内容的提问来源于stack exchange,提问作者terentius
相关产品推荐
相关产品推荐

