《Elasticsearch 常用命令与 DSL 查询》
Elasticsearch 通过 REST API 对外提供服务(默认 9200)。本文整理日常使用频率最高的 _cat 接口、索引管理、文档增删改查与 DSL 查询语法。
1 核心概念回顾
- index(索引):一组有相似结构的文档集合,类似关系数据库中的「库 + 表」。
- type(类型):索引内的逻辑分组(6.x 起一个索引建议只用一个 type,7.x 已移除)。
- document(文档):一条 JSON 记录,类似表中的一行。
- shard / replica:索引被拆分为多个分片(shard),每个分片可包含副本(replica),用于分布式存储与高可用。
2 常用 _cat 接口
# 查看集群健康状态
curl localhost:9200/_cluster/health?pretty
# 查看集群所有索引(重点:索引名、状态、分片数、文档数、存储大小)
curl localhost:9200/_cat/indices?v
# health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
# green open filebeat-6.5.4-2019.06.26 mbwT1vtLSvunebmmeYrANw 3 1 381 0 1mb 521.1kb
# green open .kibana_1 Fn6ZjjvDShaTzJE3t9m0dQ 1 1 2 0 77.2kb 38.6kb
# 查看节点信息
curl localhost:9200/_cat/nodes?v
# 查看索引分片分布
curl localhost:9200/_cat/shards?h=index,shard,prirep,state,node
3 索引管理
# 删除以 filebeat- 开头的索引(注意通配符放在引号内)
curl -XDELETE 'http://localhost:9200/filebeat-*'
# 删除单个索引
curl -XDELETE http://localhost:9200/my-index
# 查看指定索引的 mapping
curl localhost:9200/filebeat-6.5.4-2019.06.26/_mapping
# 查看指定索引的 settings
curl localhost:9200/filebeat-6.5.4-2019.06.26/_settings?pretty
4 文档增删改查
# 新增 / 覆盖文档(指定 _id)
curl -XPUT 'http://localhost:9200/my-index/_doc/1' -H 'Content-Type: application/json' -d '{
"title": "hello world",
"views": 10
}'
# 查询单条文档
curl 'http://localhost:9200/my-index/_doc/1?pretty'
# 删除文档
curl -XDELETE 'http://localhost:9200/my-index/_doc/1'
5 DSL 查询
DSL(Domain Specific Language)即 JSON 形式的查询语句,POST 到 _search。
# match:全文检索(会分词)
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"query": { "match": { "title": "hello" } }
}'
# term:精确匹配(不分词,适合 keyword 字段)
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"query": { "term": { "status": "active" } }
}'
# range:范围查询
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"query": { "range": { "views": { "gte": 10, "lte": 100 } } }
}'
# bool:组合查询(must / should / must_not / filter)
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"query": {
"bool": {
"must": [ { "match": { "title": "hello" } } ],
"must_not": [ { "term": { "status": "deleted" } } ],
"filter": [ { "range": { "views": { "gte": 10 } } } ]
}
}
}'
# 指定返回条数与字段
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"from": 0,
"size": 20,
"_source": ["title", "views"],
"query": { "match_all": {} }
}'
filter不参与相关性打分,只做过滤,性能优于must,适合纯过滤条件的场景。
6 聚合(Aggregation)
# 按 status 分组统计数量
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"size": 0,
"aggs": {
"status_terms": {
"terms": { "field": "status.keyword" }
}
}
}'
# 数值型字段求平均值
curl -XPOST 'http://localhost:9200/my-index/_search?pretty' -H 'Content-Type: application/json' -d '{
"size": 0,
"aggs": {
"avg_views": { "avg": { "field": "views" } }
}
}'
参考文档
- 《Elasticsearch 权威指南(中文版)》:https://www.elastic.co/guide/cn/elasticsearch/guide/cn/preface.html
阅读 —
·
全站 —