You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch 6.2.2中排序返回的_doc与文档类型_doc的区别

Answers to Your Elasticsearch _doc Questions (v6.2.2)

Hey there! Let's break down your two questions about _doc in Elasticsearch 6.2.2 clearly:

1. What does _doc mean when sorting search results?

_doc is a special sort field that refers to the internal order of documents as stored by Lucene (Elasticsearch's underlying search engine). Here's the breakdown:

  • It reflects the order in which documents were first indexed (more precisely, the unique internal ID Lucene assigns to each document when it's added to the index).
  • It's the fastest sort option available because it doesn't require reading or calculating any field values—Elasticsearch just uses the native ordering already present in the index.
  • In your example sort array:
    "sort": [ 1577413214250, 393 ]
    
    The number 393 is the value of the _doc field for that document. Pairing it with a timestamp ensures we have a unique sort key, which is essential for features like search_after—it avoids confusion when multiple documents have the exact same timestamp.

2. How is _doc as a sort field different from _doc as a document type?

These are totally separate concepts in Elasticsearch 6.2.2:

_doc as a document type

  • Before Elasticsearch 7.x, indices could hold multiple document types (think of them as categories for different document schemas in the same index). _doc was a common default type name you might specify when setting up an index.
  • It's part of the index's structure, used to group documents with different mappings under one index (this feature was deprecated and removed in later versions).

_doc as a sort field

  • It has no connection to document types at all. Instead, it's a special "pseudo-field" that points to Lucene's internal document ID sequence.
  • Its only job is to provide deterministic, fast sorting—especially useful when your primary sort field (like timestamp) has duplicate values, ensuring each document has a unique position in the results.

Why Kibana uses _doc for "Surrounding Documents"

Looking at the Kibana requests you shared, the _doc sort field solves a specific problem:

  • When fetching documents around a target record, Kibana uses @timestamp as the main sort, but adds _doc as a secondary sort. This way, if multiple documents share the exact same timestamp, Elasticsearch can still uniquely identify and return the correct adjacent documents using their internal Lucene IDs.
  • The two requests alternate the _doc sort order (asc then desc) to pull documents both before and after the target record, using search_after with the target's timestamp and _doc ID as the starting point.

内容的提问来源于stack exchange,提问作者luwen miao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:10:29