You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RedisJSON与Python3:JSON.GET及索引查询无结果的解决方法

Redis导入Zeek日志字段查询失败的解决过程

问题场景

作为Redis新手,尝试导入Zeek日志数据,为多个字段创建索引后进行字段查询,但始终无法通过@orig_ip查询,也没法用JSON.GET获取id.*相关字段的结果。

错误的索引创建代码

# 索引创建选项
index_def = IndexDefinition(
                index_type=IndexType.JSON,
                prefix = ['uid:'],
                score = 0.5,
                score_field = 'doc_score'
)

# 模式定义
schema = (  
            TagField('$.orig_l2_addr', as_name='orig_mac'),
            TagField('$.id.orig_h', as_name='orig_ip'), # 错误的字段路径
            TagField('$.id.resp_h', as_name='resp_ip'), # 错误的字段路径
            NumericField('$.orig_bytes', as_name='orig_bytes'),
            NumericField('$.resp_bytes', as_name='resp_bytes'),
            NumericField('$.ts', as_name='timestamp')
)

r.ft('py_conn_idx').create_index(schema, definition = index_def)

使用错误模式的查询结果(无返回值)

执行查询代码:

search_result4 = r.ft('py_conn_idx').search(Query('@orig_ip:{192\.168\.210\.27}'))

返回结果:

Results for "@orig_ip:{192\.168\.210\.27}":
0

解决方法:修正字段引用

问题根源在于Zeek并非用点来创建嵌套对象,而是字段名本身包含点,导致原本的JSON路径解析错误。需要改用如下方式定义索引模式:

# 模式定义
schema = (  
            TagField('$.orig_l2_addr', as_name='orig_mac'),
            TagField('$.["id.orig_h"]', as_name='orig_ip'), # 修正后的字段引用
            TagField('$.["id.resp_h"]', as_name='resp_ip'), # 修正后的字段引用
            NumericField('$.orig_bytes', as_name='orig_bytes'),
            NumericField('$.resp_bytes', as_name='resp_bytes'),
            NumericField('$.ts', as_name='timestamp')
)

重新创建索引后,查询成功返回结果:

Results for "@orig_ip:{192\.168\.210\.27}":
Document {'id': 'uid:CPvYfTI4Zb1Afp2l5',....

内容的提问来源于Stack Exchange,提问作者Taylor Paul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 12:00:24