如果它是0 KIBANA,请从一个值中获取最高的点击率

时间:2019-10-21 09:32:41

标签: elasticsearch kibana

我的第一篇文章,我花了整个周末寻找一个没有好结果的答案

我将尝试解释我的问题,我有此索引

ST ID
0 1
1 1
0 2
1 2
0 2
1 3
0 3

例如,当每个ID为0时,我需要显示每个ID的最后一条记录,例如,在此索引中,我必须仅显示ID 1和ID 2,因为在ID 1和1中,最后一条记录的ST均为0。 2

有人可以帮我解决这个问题吗?

BR

1 个答案:

答案 0 :(得分:0)

映射:

PUT index34
{
  "mappings": {
    "properties": {
      "ST":{
        "type": "integer"
      },
      "ID":{
        "type": "integer"
      },
      "Date":{
        "type": "date"
      }
    }
  }
}

数据:

[
      {
        "_index" : "index34",
        "_type" : "_doc",
        "_id" : "LO7Z7W0B_-hMjUaqtwHw",
        "_score" : 1.0,
        "_source" : {
          "ST" : 1,
          "ID" : 1,
          "Date" : "2019-10-21T12:00:00Z"
        }
      },
      {
        "_index" : "index34",
        "_type" : "_doc",
        "_id" : "Le7Z7W0B_-hMjUaq0QEz",
        "_score" : 1.0,
        "_source" : {
          "ST" : 0,
          "ID" : 1,
          "Date" : "2019-10-21T12:01:00Z"
        }
      },
      {
        "_index" : "index34",
        "_type" : "_doc",
        "_id" : "Lu7a7W0B_-hMjUaqAwE0",
        "_score" : 1.0,
        "_source" : {
          "ST" : 1,
          "ID" : 2,
          "Date" : "2019-10-21T12:02:00Z"
        }
      },
      {
        "_index" : "index34",
        "_type" : "_doc",
        "_id" : "L-7a7W0B_-hMjUaqGAEr",
        "_score" : 1.0,
        "_source" : {
          "ST" : 0,
          "ID" : 2,
          "Date" : "2019-10-21T12:04:00Z"
        }
      },
      {
        "_index" : "index34",
        "_type" : "_doc",
        "_id" : "MO7a7W0B_-hMjUaqNAGA",
        "_score" : 1.0,
        "_source" : {
          "ST" : 0,
          "ID" : 3,
          "Date" : "2019-10-21T12:04:00Z"
        }
      },
      {
        "_index" : "index34",
        "_type" : "_doc",
        "_id" : "Me7a7W0B_-hMjUaqTQFP",
        "_score" : 1.0,
        "_source" : {
          "ST" : 1,
          "ID" : 3,
          "Date" : "2019-10-21T12:06:00Z"
        }
      }
    ]

查询:我得到所有条件的最大日期,然后在ST为零时得到最大值。如果这两个匹配(表示0是最新的文档),那么我将保持存储桶

GET index34/_search
{
  "size": 0,
  "aggs": {
    "ID": {
      "terms": {
        "field": "ID",
        "size": 10000
      },
      "aggs": {
        "maxDate": {
          "max": {
            "field": "Date"
          }
        },
        "pending_status": {
          "filter": {
            "term": {
              "ST": 0
            }
          },
          "aggs": {
            "filtered_maxdate": {
              "max": {
                "field": "Date"   
              }
            }
          }
        },
        "buckets_latest_status_pending": {
          "bucket_selector": {
            "buckets_path": {
              "filtereddate": "pending_status>filtered_maxdate",
              "maxDate": "maxDate"
            },
            "script": "params.filtereddate==params.maxDate"
          }
        }
      }
    }
  }
}

响应:

"aggregations" : {
    "ID" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : 1,
          "doc_count" : 2,
          "pending_status" : {
            "doc_count" : 1,
            "filtered_maxdate" : {
              "value" : 1.57165926E12,
              "value_as_string" : "2019-10-21T12:01:00.000Z"
            }
          },
          "maxDate" : {
            "value" : 1.57165926E12,
            "value_as_string" : "2019-10-21T12:01:00.000Z"
          }
        },
        {
          "key" : 2,
          "doc_count" : 2,
          "pending_status" : {
            "doc_count" : 1,
            "filtered_maxdate" : {
              "value" : 1.57165944E12,
              "value_as_string" : "2019-10-21T12:04:00.000Z"
            }
          },
          "maxDate" : {
            "value" : 1.57165944E12,
            "value_as_string" : "2019-10-21T12:04:00.000Z"
          }
        }
      ]
    }