在 elasticsearch 中使用带正斜杠的数据聚合

Using an aggregation on data with forward slash in elasticsearch

我有数据,具有这样的属性

apiUrl:/REST/endpoint/123

现在我想显示所有的 url,我正在尝试使用聚合函数(apiUrl.raw 是 not_analyzed 多字段的一部分):

POST /index/type/_search
{
  "aggregations": {
    "application": {
      "terms": {
        "field": "apiUrl.raw"
      }
    }
  }
}

当运行这个查询时,没有返回结果。 我哪里做错了?我希望有一些东西(以及出现的次数):

谢谢!

您的查询 return 非空结果。比较并让我们知道有什么区别:

PUT index
PUT index/type/_mapping
{
  "properties" : {
    "apiUrl": {
      "type": "multi_field",
      "fields": {
        "apiUrl": {"type":"string", "index":"analyzed"},
        "raw": {"type":"string", "index":"not_analyzed"}
      }
    }
  }
}
GET index/type/_mapping
PUT index/type/1
{
  "apiUrl":"/REST/api1/123"
}
PUT index/type/2
{
  "apiUrl":"/REST/otherApi/345"
}
GET index/type/_search?fields=apiUrl.raw
GET index/type/_search
{
  "aggregations": {
    "application": {
      "terms": {
        "field": "apiUrl.raw"
      }
    }
  }
}

回复:

{
   "took": 76,
   "timed_out": false,
   "_shards": {
      "total": 5,
      "successful": 5,
      "failed": 0
   },
   "hits": {
      "total": 2,
      "max_score": 1,
      "hits": [
         {
            "_index": "index",
            "_type": "type",
            "_id": "1",
            "_score": 1,
            "_source": {
               "apiUrl": "/REST/api1/123"
            }
         },
         {
            "_index": "index",
            "_type": "type",
            "_id": "2",
            "_score": 1,
            "_source": {
               "apiUrl": "/REST/otherApi/345"
            }
         }
      ]
   },
   "aggregations": {
      "application": {
         "doc_count_error_upper_bound": 0,
         "sum_other_doc_count": 0,
         "buckets": [
            {
               "key": "/REST/api1/123",
               "doc_count": 1
            },
            {
               "key": "/REST/otherApi/345",
               "doc_count": 1
            }
         ]
      }
   }
}