You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Elasticsearch中实现跨索引关联查询?求解决方案

Elasticsearch Cross-Index Query for Version Filtered Logs

Hey there! Let's work through this cross-index query problem you're stuck on. You need to pull logs only for hosts running version v1, and since your data lives across two separate indices (logs and versions), we can use Elasticsearch's built-in tools to connect them without messy workarounds.

Solution 1: Terms Lookup (Quick Ad-Hoc Query)

The simplest approach is using a terms lookup query—this lets us fetch matching host values from the versions index and use them to filter the logs index directly. Here's the full query DSL:

GET /logs/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "terms": {
            "host": {
              "index": "versions",
              "path": "host",
              "query": {
                "term": {
                  "version": "v1"
                }
              }
            }
          }
        }
      ]
    }
  }
}

Breakdown of how this works:

  • We use bool/filter to skip scoring logic, which makes the query faster
  • The terms query on logs.host pulls all host values from the versions index that match our version condition
  • The nested query filters the versions index to only include entries where version: v1
  • path: "host" tells Elasticsearch which field from versions to use as filter values for the logs index

This will return exactly the logs you're expecting: all entries for hosts a1 and a2.

Solution 2: Enrich Policy (For Repeated Queries)

If you need to run this kind of version-filtered log query often, an Enrich Policy is more efficient—it pre-builds a lookup cache to speed up repeated cross-index filtering. Here's how to set it up:

Step 1: Create the Enrich Policy

PUT /_enrich/policy/host_version_policy
{
  "match": {
    "indices": "versions",
    "match_field": "host",
    "enrich_fields": ["version"]
  }
}

Step 2: Execute the Policy (Build the Lookup Cache)

POST /_enrich/policy/host_version_policy/_execute

Step 3: Query Using the Enrich Policy

GET /logs/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "enrich": {
            "policy_name": "host_version_policy",
            "field": "host",
            "target_field": "enriched",
            "query": {
              "term": {
                "enriched.version": "v1"
              }
            }
          }
        }
      ]
    }
  }
}

Why choose this?

The enrich policy creates a persistent lookup table, so subsequent queries will run faster than repeated terms lookups. It's perfect if you need to filter logs by host version on a regular basis.

Expected Results

Both queries will return the exact dataset you're looking for:

timestamp:1, host:a1, log: "sample log1"
timestamp:2, host:a1, log: "sample log2"
timestamp:3, host:a1, log: "sample log3"
timestamp:1, host:a2, log: "sample log4"
timestamp:2, host:a2, log: "sample log5"
timestamp:3, host:a2, log: "sample log6"

内容的提问来源于stack exchange,提问作者cramer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 03:55:42