假设我在Elasticsearch索引中有以下文档(包含日志):
PUT logs/_doc/1
{
"commonId" : "111111",
"comment" : "abc",
"phase" : "start"
}
PUT logs/_doc/2
{
"commonId" : "111111",
"comment" : "cde",
"customerNumber" : "234-333"
}
PUT logs/_doc/3
{
"commonId" : "222222",
"comment" : "efg",
"phase" : "stop"
}
PUT logs/_doc/4
{
"commonId" : "222222",
"comment" : "jkl",
"customerNumber" : "234-555"
}
所有日志中常见的是 commonId 属性。
问题是:
我希望以某种方式处理日志:
是否可以通过任何Elasticsearch查询执行此操作?我通常不会对X-Pack的任何付费选项感兴趣。