Elasticsearch : indexation et recherche
Apprenez les bases d’Elasticsearch, un moteur distribué de recherche et d’analyse. Comprenez comment indexer des documents et effectuer des requêtes élémentaires.
Elasticsearch : indexation et recherche est une leçon System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) gratuite sur CoddyKit. Ceci est la leçon 1 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry), et ta progression se synchronise sur le web et l'application CoddyKit. Le cours System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) comprend 4 leçons au total.
Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.
Welcome to Elasticsearch!
Welcome to the first lesson on the ELK Stack! We'll start with Elasticsearch, the 'E' in ELK.
Elasticsearch is a powerful, open-source distributed search and analytics engine. It's designed to store, search, and analyze large volumes of data quickly.
- Distributed: Runs across multiple servers.
- Real-time: Data is available for search almost instantly.
- Scalable: Easily handles growing data needs.
Data as JSON Documents
Elasticsearch stores data as JSON documents. Think of a document as a single record, like a row in a database, but more flexible.
Each document is a collection of fields (key-value pairs) and can contain various data types, including text, numbers, dates, and even other JSON objects.
Here's a simple example of a document:
{"user": "alice", "message": "Hello CoddyKit!"}Understanding Indices
In Elasticsearch, documents are organized into indices. An index is like a database in a relational database system, or a collection in a NoSQL database.
You can have multiple indices, and each index can store documents that are somewhat related. For example, you might have one index for 'logs' and another for 'products'.
- An index is a logical namespace.
- It groups similar documents.
- You search within specific indices.
Indexing Your First Document
Indexing is the process of adding or updating documents in an Elasticsearch index. When you index a document, Elasticsearch stores it and makes it searchable.
Each document needs a unique ID within its index. If you don't provide one, Elasticsearch will generate it for you.
We use HTTP API calls, typically with PUT or POST requests, to interact with Elasticsearch.
Indexing a Document Example
Let's index a simple log document into an index called my_logs. We'll specify an ID of 1.
Try running this command (assuming Elasticsearch is running on localhost:9200):
curl -X PUT "localhost:9200/my_logs/_doc/1?pretty" -H 'Content-Type: application/json' -d'
{
"timestamp": "2023-10-27T10:00:00Z",
"level": "info",
"message": "Application started successfully"
}'Retrieving Documents by ID
Once a document is indexed, you can retrieve it using its unique ID. This is useful when you know exactly which document you want.
To retrieve a document, you send an HTTP GET request to the specific index and document ID endpoint.
This operation is very fast as Elasticsearch can directly fetch the document.
Retrieving a Document Example
Let's retrieve the document we just indexed with ID 1 from the my_logs index.
Run this command to see the stored document:
curl -X GET "localhost:9200/my_logs/_doc/1?pretty"Introduction to Searching
The real power of Elasticsearch comes from its searching capabilities. Instead of knowing an ID, you often want to find documents based on their content.
You can search across all documents in an index (or multiple indices) using various query types. Elasticsearch uses a query language based on JSON.
- Find documents by keywords.
- Filter by date ranges or specific values.
- Combine multiple search criteria.
Basic Search: Match All
The simplest search query is the match_all query. It returns all documents in the specified index.
This is often used to verify that documents are indexed correctly or as a starting point for more complex queries.
You send an HTTP GET request to the _search endpoint of your index.
Match All Query Example
Let's search for all documents in our my_logs index. You'll see the document we indexed earlier.
Run this command:
curl -X GET "localhost:9200/my_logs/_search?pretty" -H 'Content-Type: application/json' -d'
{
"query": {
"match_all": {}
}
}'Quick Check on Indexing
You've learned about documents, indices, and how to index and retrieve data. Let's test your understanding of indexing.
Recap: Indexing and Basic Search
Great job! In this lesson, you've learned the fundamentals of Elasticsearch:
- Elasticsearch is a distributed search and analytics engine.
- Data is stored as JSON documents.
- Documents are organized into indices.
- Indexing adds or updates documents using
PUT/POSTrequests. - Documents can be retrieved by ID using
GETrequests. - Basic searching can be done with queries like
match_all.
Next, we'll dive deeper into Logstash, the 'L' in ELK, to ingest and process data!
Questions Fréquemment Posées
La leçon « Elasticsearch : indexation et recherche » est-elle gratuite ?
Oui — le texte complet de « Elasticsearch : indexation et recherche » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry), passe à CoddyKit PRO. Le cours System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) comprend 4 leçons au total.
Qu'est-ce que j'apprendrai dans « Elasticsearch : indexation et recherche » ?
Apprenez les bases d’Elasticsearch, un moteur distribué de recherche et d’analyse. Comprenez comment indexer des documents et effectuer des requêtes élémentaires. Tu pratiques System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.
Dois-je avoir de l'expérience pour commencer System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) ?
Aucune expérience préalable n'est requise. System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 1 sur 4.
Combien de temps prend la leçon « Elasticsearch : indexation et recherche » ?
La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.
Peux-tu écrire et exécuter du code dans cette leçon System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) ?
Oui. Chaque leçon System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.
Toutes les leçons de ce cours
- Elasticsearch : indexation et recherche
- Logstash : ingestion et traitement des données
- Kibana : visualisation et tableaux de bord
- Beats : agents légers de transmission des données