如何執行JOIN在相同指數elasticsearch操作JOIN操作?如何執行elasticsearch
這是FOW每個文件組領域:
"@version": "1",
"@timestamp": "2016-04-26T15:56:05.379Z",
"phone": "..."
"path": "...",
"host": "...",
"type": "...",
"clientip": "...",
"ident": "-",
"auth": "-",
"timestamp": "...",
"verb": "...",
"uripath": "...",
"httpversion": "1.1",
"response": "200",
"bytes": "515",
"timetaken": "383",
"event_type": "type1"
}
如果我會得到電話的有(EVENT_TYPE的TYPE1文件,時間戳DATE1之間和DATE2)和(TYPE2的EVENT_TYPE, 時間戳 DATE3和
之間date4)在MySQL的思維是兩種觀點
之間的連接
從文檔它說,「dis_max」功能,可以在這裏使用。你有過這個嗎? –