【发布时间】:2020-05-19 05:36:33
【问题描述】:
我正在开发 Spring Boot - JHipster 基础项目。
我正在使用带有附件插件的 Elasticsearch 6.8.6。 其中,内容字段包含我的文档的数据。
现在,当我搜索“192.168.31.167”时,它会给出适当的结果。但是,当我搜索这个“192.168.31.167:9200”时,它会给出一个空结果。
简而言之,它不适用于空格字符。 有人可以指导我。如何处理?
映射:
{
"document" : {
"mappings" : {
"doc" : {
"properties" : {
"attachment" : {
"properties" : {
"content" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"content_length" : {
"type" : "long"
},
"content_type" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
}
}
},
"content" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"createdDate" : {
"type" : "date"
},
"holder" : {
"type" : "long"
},
"id" : {
"type" : "long"
},
"name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
},
"tag" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
}
}
}
}
}
}
}
}
虚拟数据:
{
"took" : 2,
"timed_out" : false,
"_shards" : {
"total" : 3,
"successful" : 3,
"skipped" : 0,
"failed" : 0
},
"hits" : {
"total" : 1,
"max_score" : 1.0,
"hits" : [
{
"_index" : "document",
"_type" : "doc",
"_id" : "1",
"_score" : 1.0,
"_source" : {
"createdDate" : "2020-05-19T03:56:36+0000",
"attachment" : {
"content_type" : "text/plain; charset=ISO-8859-1",
"content" : "version: '2'\nservices:\n docy-kibana:\n image: docker.elastic.co/kibana/kibana:6.8.6\n ports:\n - 5601:5601\n\n environment:\n SERVER_NAME: kibana.example.org\n ELASTICSEARCH_HOSTS: http://192.168.31.167:9200/\n XPACK_MONITORING_ENABLED: ${true}\n# XPACK_ENCRYPTEDSAVEDOBJECTS.ENCRYPTIONKEY: test\n XPACK_MONITORING_UI_CONTAINER_ELASTICSEARCH_ENABLED: ${true}",
"content_length" : 390
},
"name" : "kibana_3_202005190926.yml",
"holder" : 3,
"id" : 1,
"tag" : "configuration",
"content" : "dmVyc2lvbjogJzInCnNlcnZpY2VzOgogIGRvY3kta2liYW5hOgogICAgaW1hZ2U6IGRvY2tlci5lbGFzdGljLmNvL2tpYmFuYS9raWJhbmE6Ni44LjYKICAgIHBvcnRzOgogICAgICAtIDU2MDE6NTYwMQoKICAgIGVudmlyb25tZW50OgogICAgICBTRVJWRVJfTkFNRToga2liYW5hLmV4YW1wbGUub3JnCiAgICAgIEVMQVNUSUNTRUFSQ0hfSE9TVFM6IGh0dHA6Ly8xOTIuMTY4LjMxLjE2Nzo5MjAwLwogICAgICBYUEFDS19NT05JVE9SSU5HX0VOQUJMRUQ6ICR7dHJ1ZX0KIyAgICAgIFhQQUNLX0VOQ1JZUFRFRFNBVkVET0JKRUNUUy5FTkNSWVBUSU9OS0VZOiB0ZXN0CiAgICAgIFhQQUNLX01PTklUT1JJTkdfVUlfQ09OVEFJTkVSX0VMQVNUSUNTRUFSQ0hfRU5BQkxFRDogJHt0cnVlfQo="
}
}
]
}
}
代码生成的Elasticsearch请求:
{
"bool" : {
"must" : [
{
"bool" : {
"should" : [
{
"query_string" : {
"query" : "*192.168.31.167:9200*",
"fields" : [
"content^1.0",
"name^2.0",
"tag^3.0"
],
"type" : "best_fields",
"default_operator" : "or",
"max_determinized_states" : 10000,
"enable_position_increments" : true,
"fuzziness" : "AUTO",
"fuzzy_prefix_length" : 0,
"fuzzy_max_expansions" : 50,
"phrase_slop" : 0,
"analyze_wildcard" : true,
"escape" : false,
"auto_generate_synonyms_phrase_query" : true,
"fuzzy_transpositions" : true,
"boost" : 1.0
}
},
{
"wildcard" : {
"attachment.content" : {
"wildcard" : "*192.168.31.167:9200*",
"boost" : 1.0
}
}
}
],
"adjust_pure_negative" : true,
"boost" : 1.0
}
},
{
"bool" : {
"should" : [
{
"wildcard" : {
"tag.keyword" : {
"wildcard" : "*information*",
"boost" : 1.0
}
}
},
{
"wildcard" : {
"tag.keyword" : {
"wildcard" : "*user*",
"boost" : 1.0
}
}
}
],
"adjust_pure_negative" : true,
"boost" : 1.0
}
}
],
"adjust_pure_negative" : true,
"boost" : 1.0
}
}
【问题讨论】:
-
您应该提供一种方法让我们重新创建问题(映射、查询、示例文档等)。这里有太多的未知数。
-
抱歉,问题已更新。
-
您可以查看此线程,它提供了从文本正文中提取 ip:port 的解决方案:stackoverflow.com/a/34986008/4604579。我将继续使用该分析器添加另一个子字段并在该字段上进行搜索。
-
值得注意的是,如果您要按照上述线程中的建议选择分析器方式,我很乐意确保该插件适用于 ES 6.8。
-
@DhwanilPatel 很长时间以来,您都没有接受并支持我的答案,如果您的问题得到解决,如果您能接受并支持答案,那就太好了
标签: elasticsearch