Elasticsearch 6.2.2中排序返回的_doc与文档类型_doc的区别
Answers to Your Elasticsearch
_doc Questions (v6.2.2) Hey there! Let's break down your two questions about _doc in Elasticsearch 6.2.2 clearly:
1. What does _doc mean when sorting search results?
_doc is a special sort field that refers to the internal order of documents as stored by Lucene (Elasticsearch's underlying search engine). Here's the breakdown:
- It reflects the order in which documents were first indexed (more precisely, the unique internal ID Lucene assigns to each document when it's added to the index).
- It's the fastest sort option available because it doesn't require reading or calculating any field values—Elasticsearch just uses the native ordering already present in the index.
- In your example
sortarray:
The number"sort": [ 1577413214250, 393 ]393is the value of the_docfield for that document. Pairing it with a timestamp ensures we have a unique sort key, which is essential for features likesearch_after—it avoids confusion when multiple documents have the exact same timestamp.
2. How is _doc as a sort field different from _doc as a document type?
These are totally separate concepts in Elasticsearch 6.2.2:
_doc as a document type
- Before Elasticsearch 7.x, indices could hold multiple document types (think of them as categories for different document schemas in the same index).
_docwas a common default type name you might specify when setting up an index. - It's part of the index's structure, used to group documents with different mappings under one index (this feature was deprecated and removed in later versions).
_doc as a sort field
- It has no connection to document types at all. Instead, it's a special "pseudo-field" that points to Lucene's internal document ID sequence.
- Its only job is to provide deterministic, fast sorting—especially useful when your primary sort field (like timestamp) has duplicate values, ensuring each document has a unique position in the results.
Why Kibana uses _doc for "Surrounding Documents"
Looking at the Kibana requests you shared, the _doc sort field solves a specific problem:
- When fetching documents around a target record, Kibana uses
@timestampas the main sort, but adds_docas a secondary sort. This way, if multiple documents share the exact same timestamp, Elasticsearch can still uniquely identify and return the correct adjacent documents using their internal Lucene IDs. - The two requests alternate the
_docsort order (ascthendesc) to pull documents both before and after the target record, usingsearch_afterwith the target's timestamp and_docID as the starting point.
内容的提问来源于stack exchange,提问作者luwen miao
相关产品推荐
相关产品推荐

