加入Elasticsearch中的reverse_nested聚合

Ser*_*erj 5 elasticsearch

请帮助我找到一种机制来聚合以下域或证明它在当前API中不存在.

    curl -XDELETE 127.0.0.1:9200/test_index

    curl -XPUT 127.0.0.1:9200/test_index -d '{
        "mappings": {
            "contact": {
                "properties": {
                    "facebook_profile": {
                        "type": "nested",
                        "properties": {
                            "education": {
                                "type": "string"
                            },
                            "year": {
                                "type": "integer"
                            }
                        }
                    },
                    "google_profile": {
                        "type": "nested",
                        "properties": {
                            "education": {
                                "type": "string"
                            },
                            "year": {
                                "type": "integer"
                            }
                        }
                    }
                }
            }
        }
    }'

    curl -XPUT 127.0.0.1:9200/test_index/contact/contact1 -d '{
        "google_profile": {
            "education": "stanford", "year": 1990
        }
    }'

    curl -XPUT 127.0.0.1:9200/test_index/contact/contact2 -d '
    {
        "facebook_profile": {
            "education": "stanford", "year": 1990
        }
    }'
Run Code Online (Sandbox Code Playgroud)

如何查询ES以查找有关从特定大学毕业的联系人数量的统计数据?

我找到了一种可能性,但它没有给我想要的结果,因为它不能回答上面关于联系人的问题,而只回答他们的特定配置文件(嵌套文档):

    curl -XPOST '127.0.0.1:9200/test_index/_search?search_type=count&pretty=true' -d '{
        "aggs": {
            "facebook_educations": {
                "aggs": {
                    "field": {
                        "terms": {
                            "field": "contact.facebook_profile.education"
                        },
                        "aggs": {
                            "reverse": {
                                "reverse_nested": {
                                }
                            }
                        }
                    }
                },
                "nested": {
                    "path": "contact.facebook_profile"
                }
            },
            "google_educations": {
                "aggs": {
                    "field": {
                        "terms": {
                            "field": "contact.google_profile.education"
                        },
                        "aggs": {
                            "reverse": {
                                "reverse_nested": {
                                }
                            }
                        }
                    }
                },
                "nested": {
                    "path": "contact.google_profile"
                }
            }
        }
    }'
Run Code Online (Sandbox Code Playgroud)

是什么让我:

    "aggregations" : {
        "facebook_educations" : {
          "doc_count" : 1,
          "field" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [ {
              "key" : "stanford",
              "doc_count" : 1,
              "reverse" : {
                "doc_count" : 1
              }
            } ]
          }
        },
        "google_educations" : {
          "doc_count" : 1,
          "field" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [ {
              "key" : "stanford",
              "doc_count" : 1,
              "reverse" : {
                "doc_count" : 1
              }
            } ]
          }
        }
    }
Run Code Online (Sandbox Code Playgroud)

但在这里我不能确定一个发现的联系人是相同还是不同的doc(父母),我分别无法回答我的初步问题.

谢谢你的任何建议.

Bro*_*keB 0

听起来您正在尝试聚合多个字段。Elasticsearch 不直接支持这一点,但有一些方法可以解决这个问题并获得您正在寻找的结果。

查看Github 上的讨论以及文档中的讨论。

如果我理解正确,无论“stanford”出现在facebook_profile.education或中google_profile.education,您都希望contact在聚合中只计算一次。

您应该能够通过以下两种方式之一执行此操作:

  1. 使用脚本连接存储在字段中的值:

    {
      "aggs": {
        "by_education": {
          "terms": {
            "script": "doc['contact.facebook_profile.education'].values + doc['contact.google_profile.education'].values"
          }
        }
      }
    }
    
    Run Code Online (Sandbox Code Playgroud)
  2. 您可以使用 选项在索引时创建一个新的专用字段,其中包含两个字段的值copy_to。然后在单个字段上聚合。例如,您可以将两个字段的内容复制到名为 的新字段中education_combined。

    {
      "mappings":{
        "contact":{
          "properties":{
            "facebook_profile":{
              "type":"nested",
              "properties":{
                "education":{
                  "type":"string",
                  "copy_to":"education_combined"
                },
                "year":{
                  "type":"integer"
                }
              }
            },
            "google_profile":{
              "type":"nested",
              "properties":{
                "education":{
                  "type":"string",
                  "copy_to":"education_combined"
                },
                "year":{
                  "type":"integer"
                }
              }
            },
            "education_combined":{
              "type":"string"
            }
          }
        }
      }
    }
    
    Run Code Online (Sandbox Code Playgroud)

    然后,简单地聚合education_combined:

    {
      "aggs": {
        "by_education": {
          "terms": { "field": "education_combined" }
        }
      }
    }
    
    Run Code Online (Sandbox Code Playgroud)