Kibana 7.9.0搜索type_instance:port-channel42无结果的问题求助
port-channel42 Hey there, let's break down why you can't find port-channel42 but can pull up other port-channel* entries. Here are actionable fixes and checks to resolve this:
1. Use Exact Phrase Matching First
Your current partial search for type_instance:"port-" works because it's a prefix match, but the type_instance field is likely being tokenized (split into smaller text chunks) by Elasticsearch's default analyzer. For example, port-channel42 might get split into port and channel42—so searching without quotes only looks for those individual tokens, not the full phrase.
Try wrapping your target term in double quotes to force an exact match:
type_instance:"port-channel42"
2. Leverage the Keyword Subfield (If Available)
Many text fields in Elasticsearch come with a companion keyword subfield that stores the raw, un-tokenized value—this is ideal for precise matches. To check if this exists:
- Open Kibana's Dev Tools tab
- Run this command to inspect your index mapping (replace the index name if yours differs):
GET collectd-09-2020.09.09/_mapping - Look for the
type_instancefield. If you see a structure like this:
Use the keyword subfield for your search instead:"type_instance": { "type": "text", "fields": { "keyword": { "type": "keyword", "ignore_above": 256 } } }type_instance.keyword:"port-channel42"
3. Confirm the Data Actually Exists
Before adjusting search syntax, double-check that port-channel42 data is present in your index. Run a broader search to list all relevant entries:
host:"host-1" and plugin:snmp and collectd_type:if_octets
Scroll through the results to verify if port-channel42 is ever logged. If it's missing, the issue might lie with your elastic-collectd data collection setup, not the search itself.
4. Try Wildcard Matching (For Uncertain Cases)
If you're unsure about the exact spelling or suffix, a wildcard search can help catch variations:
type_instance:port-channel*42
This will match any type_instance value that starts with port-channel and ends with 42.
内容的提问来源于stack exchange,提问作者VallingSki

