我的表结构有一个分区键,行键和一个包含JSON数据的列。我想基于分区键和JSON数据中的特定值来查询表。
示例JSON数据:
filter {
mutate {
add_field => {
# Create a new field with string value of the UTC event date
"timestamp_extract" => "%{@timestamp}"
}
}
date {
# Parse UTC string value and convert it to my timezone into a new field
match => [ "timestamp_extract", "yyyy-MM-dd HH:mm:ss Z" ]
timezone => "Europe/Rome"
locale => "en"
remove_field => [ "timestamp_extract" ]
target => "timestamp_europe"
}
}
我创建的查询是
{"ConsumerId":"7","value01":"850.58"}
但它没有给我预期的结果。任何人都可以帮我正确查询吗?