如何在Elasticsearch中实现跨索引关联查询?求解决方案
Hey there! Let's work through this cross-index query problem you're stuck on. You need to pull logs only for hosts running version v1, and since your data lives across two separate indices (logs and versions), we can use Elasticsearch's built-in tools to connect them without messy workarounds.
Solution 1: Terms Lookup (Quick Ad-Hoc Query)
The simplest approach is using a terms lookup query—this lets us fetch matching host values from the versions index and use them to filter the logs index directly. Here's the full query DSL:
GET /logs/_search { "query": { "bool": { "filter": [ { "terms": { "host": { "index": "versions", "path": "host", "query": { "term": { "version": "v1" } } } } } ] } } }
Breakdown of how this works:
- We use
bool/filterto skip scoring logic, which makes the query faster - The
termsquery onlogs.hostpulls all host values from theversionsindex that match our version condition - The nested
queryfilters theversionsindex to only include entries whereversion: v1 path: "host"tells Elasticsearch which field fromversionsto use as filter values for thelogsindex
This will return exactly the logs you're expecting: all entries for hosts a1 and a2.
Solution 2: Enrich Policy (For Repeated Queries)
If you need to run this kind of version-filtered log query often, an Enrich Policy is more efficient—it pre-builds a lookup cache to speed up repeated cross-index filtering. Here's how to set it up:
Step 1: Create the Enrich Policy
PUT /_enrich/policy/host_version_policy { "match": { "indices": "versions", "match_field": "host", "enrich_fields": ["version"] } }
Step 2: Execute the Policy (Build the Lookup Cache)
POST /_enrich/policy/host_version_policy/_execute
Step 3: Query Using the Enrich Policy
GET /logs/_search { "query": { "bool": { "filter": [ { "enrich": { "policy_name": "host_version_policy", "field": "host", "target_field": "enriched", "query": { "term": { "enriched.version": "v1" } } } } ] } } }
Why choose this?
The enrich policy creates a persistent lookup table, so subsequent queries will run faster than repeated terms lookups. It's perfect if you need to filter logs by host version on a regular basis.
Expected Results
Both queries will return the exact dataset you're looking for:
timestamp:1, host:a1, log: "sample log1"
timestamp:2, host:a1, log: "sample log2"
timestamp:3, host:a1, log: "sample log3"
timestamp:1, host:a2, log: "sample log4"
timestamp:2, host:a2, log: "sample log5"
timestamp:3, host:a2, log: "sample log6"
内容的提问来源于stack exchange,提问作者cramer

