input {

stdin { codec => json }

}

filter {

mutate {

remove_field => ["@version", "@timestamp", "host"]

}

}

output {

elasticsearch {

hosts => "localhost"

index => today190108

}

}


=====================================================


. aggs : ? 

. cardinality : ?

--------------------------------------------------


POST today190108/_search?size=10

{

  "aggs": {

    "NAME": {

      "cardinality": {

        "field": "data"

      }

    }

  }

}


=====================================================



GET today190108/_search

{

  "size": 0,

  "aggs": {

    "NAME": {

      "filters": {

        "filters": [

          {"match" : { "data" : 10}},

          {"match" : { "data" : 11}}

        ]

      }

    }

  }

}

'ELK > elasticsearch' 카테고리의 다른 글

java api2  (0) 2019.01.25
java api  (0) 2019.01.25
java api _search  (0) 2019.01.25
java elasticsearch api 인덱스 생성  (0) 2019.01.24
Java _ elasticsearch  (0) 2019.01.15