《Kibana Discover 查询语法》

《Kibana Discover 查询语法》

Kibana 的 Discover 页面用于检索和过滤 Elasticsearch 中的文档。查询语法默认基于 KQL(Kibana Query Language),也可切换为 Lucene 语法。

1 教程参考

2 KQL 基础语法

# 字段精确匹配 status: active # 全文搜索(不指定字段,搜索所有可搜索字段) hello world # 模糊匹配 name: "john smith" # 范围查询(数字 / 日期) views: >= 1000 @timestamp >= now-24h # 通配符 name: john* # 逻辑组合 response: 200 AND method: GET response: 200 OR response: 301 NOT response: 404 # 括号分组 (response: 200 OR response: 301) AND method: GET

3 Lucene 语法(切换语法后使用)

在 Discover 搜索框的过滤器符号处切换为 Lucene 语法:

# must 条件:+ 前缀 +response:200 +method:GET # must_not 条件:- 前缀 response:200 -status:maintenance # 短语与通配符 message:"connection refused" message:conn* # 范围查询 views:[1000 TO 2000] views:{1000 TO 2000} # 不含边界 @timestamp:[2020-01-01 TO 2020-01-31] # 近似匹配(模糊查询) message:connec~

4 反向查询示例

取「非 0」的退出码,即匹配除 0 之外的结果:

# KQL 写法 edge.waf.exitCode != 0 # Lucene 写法 edge.waf.exitCode:(NOT 0)

5 实战小技巧

  • 时间范围:右上角选择最近 15 分钟 / 1 小时 / 自定义时间,影响查询范围。
  • 只看某字段:点击文档左侧字段旁的 add 图标,或使用 _source 过滤。
  • 保存查询:Search Bar 右侧的 save 图标可保存为 Saved Search,供 Dashboard 复用。
  • 表达式参考:Lucene 完整查询语法见 https://lucene.apache.org/core/2_9_4/queryparsersyntax.html。
阅读 — · 全站 —
🎸 我的歌单 0 首