Elasticsearch Query Language (DSL)
Dive into the powerful Elasticsearch Query DSL for complex data retrieval and aggregation. Learn to craft advanced search queries.
Elasticsearch Query Language (DSL) is a free System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Unlocking Elasticsearch Query Power
Welcome to the world of Elasticsearch Query DSL! DSL stands for Domain Specific Language. It's the powerful, flexible way to search and analyze data in Elasticsearch.
Instead of simple keywords, DSL lets you build complex queries using a JSON-based structure. This gives you fine-grained control over how your data is found and processed.
Basic Text Search: Match Query
The match query is your go-to for full-text searches. It analyzes the search text and the field content, making it great for finding relevant documents even with slight variations.
Here's how to find products containing the word 'laptop':
{
"query": {
"match": {
"product_name": "laptop"
}
}
}Exact Phrase Search: Match Phrase
Sometimes you need to find an exact sequence of words. That's where the match_phrase query comes in handy. It ensures all words in your query appear in the field, in the specified order.
Let's search for the exact phrase 'high performance' in a product description:
{
"query": {
"match_phrase": {
"description": "high performance"
}
}
}Exact Value Search: Term Query
The term query is used for finding exact values in fields that are not analyzed, like keywords, numbers, or dates. It won't break down your search term into individual words.
This is perfect for filtering by specific IDs, statuses, or categories. Note the .keyword suffix, often used for exact string matching:
{
"query": {
"term": {
"status.keyword": "active"
}
}
}Filtering by Range: Range Query
Need to find documents within a specific numerical or date range? The range query is what you need. It supports operators like gte (greater than or equal), gt (greater than), lte (less than or equal), and lt (less than).
Find products priced between $100 and $500:
{
"query": {
"range": {
"price": {
"gte": 100,
"lte": 500
}
}
}
}Combining Queries: Boolean Logic
The bool query is the most powerful way to combine multiple queries using boolean logic:
must: All queries must match.should: At least one query should match (influences relevance score).must_not: Queries must not match.filter: Queries must match, but don't affect the relevance score (good for caching).
Boolean Query in Action
Let's find 'electronics' products priced under $1000, but specifically exclude any from the 'obsolete' brand. Notice how filter is used for the price range, as it doesn't need to contribute to the score.
{
"query": {
"bool": {
"must": [
{ "match": { "category": "electronics" } }
],
"filter": [
{ "range": { "price": { "lte": 1000 } } }
],
"must_not": [
{ "match": { "brand": "obsolete" } }
]
}
}
}Beyond Search: Aggregations
Elasticsearch DSL isn't just for searching; it's also for powerful analytics using aggregations. Aggregations allow you to group your data, calculate metrics, and gain insights from large datasets.
Think of them like the GROUP BY clause in SQL, but much more flexible and efficient for large-scale data.
Grouping Data: Terms Aggregation
The terms aggregation is used to group documents by the values of a specific field, similar to facets. It's great for understanding the distribution of data, like finding the most popular categories or brands.
Here's how to get the top 5 product categories:
{
"aggs": {
"top_categories": {
"terms": {
"field": "category.keyword",
"size": 5
}
}
}
}Calculating Metrics: Avg Aggregation
Metric aggregations compute statistics over numeric fields. Common examples include avg, sum, min, max, and count.
You can combine them with terms aggregations to get statistics per group. Let's find the average price for each product category:
{
"aggs": {
"avg_price_by_category": {
"terms": {
"field": "category.keyword"
},
"aggs": {
"average_price": {
"avg": {
"field": "price"
}
}
}
}
}
}Quick Check on Queries
You want to find all documents where the status field is exactly 'pending' AND the priority is 'high'. Which combination of queries would you primarily use?
Recap: DSL's Power Unleashed
Congratulations! You've dived into the powerful world of Elasticsearch Query DSL.
- You learned how to use
matchandmatch_phrasefor text searching. - You explored
termfor exact value lookups andrangefor filtering. - You mastered combining queries with the flexible
boolquery. - And you got an introduction to aggregations like
termsandavgfor deep data analysis.
Keep exploring the DSL to unlock even more insights from your data!
Frequently asked questions
Is the “Elasticsearch Query Language (DSL)” lesson free?
Yes — the full text of “Elasticsearch Query Language (DSL)” is free to read here on the web, and the System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) course, upgrade to CoddyKit PRO.
What will I learn in “Elasticsearch Query Language (DSL)”?
Dive into the powerful Elasticsearch Query DSL for complex data retrieval and aggregation. Learn to craft advanced search queries. You practise System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)?
No prior experience is required. System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Elasticsearch Query Language (DSL)” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) lesson?
Yes. Every System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Elasticsearch Query Language (DSL)
- Logstash Filters and Pipelines
- Kibana Discover and Lens
- Index Lifecycle Management (ILM)