You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何编写Elasticsearch查询提取log和namespace_name字段并过滤无关字段

Elasticsearch查询过滤冗余字段解决方案

_source参数仅能控制文档自身存储的业务字段的过滤,你提到的_index、_type、_id、_score都属于Elasticsearch的内置元字段,不在_source的管控范围内,需要搭配filter_path参数才能完全剔除。

标准查询写法

直接在查询请求中新增filter_path参数,指定仅返回需要的内容路径即可,完整示例如下:

GET /你的索引名称/_search
{
  "query": {
    "match_all": {}
  },
  "_source": {
    "includes": ["log", "kubernetes.namespace_name"]
  },
  "filter_path": [
    "hits.hits._source"
  ]
}

参数说明:

  • _source.includes 保留你需要的两个业务字段,过滤其他无关业务字段
  • filter_path 指定仅返回响应中hits.hits._source路径下的内容,自动过滤所有元字段,同时也会去掉顶层的无关响应参数(如查询耗时、分片统计信息等)

如果需要保留部分顶层响应参数,直接在filter_path数组中添加对应的路径即可,比如需要保留查询耗时参数,修改为:

"filter_path": ["took", "hits.hits._source"]

扁平化返回可选方案

如果你不希望返回结果嵌套在_source层级中,可以改用fields参数实现更简洁的结构:

GET /你的索引名称/_search
{
  "query": {
    "match_all": {}
  },
  "fields": ["log", "kubernetes.namespace_name"],
  "_source": false,
  "filter_path": ["hits.hits.fields"]
}

内容的提问来源于stack exchange,提问作者u123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 18:09:02