0Pricing
System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) · レッスン

Elasticsearch:インデックス作成と検索

分散検索・分析エンジンであるElasticsearchの基礎を学びます。ドキュメントのインデックスを作成し、基本的なクエリを実行する方法を理解します。

「Elasticsearch:インデックス作成と検索」はCoddyKit上の無料System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)レッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSystem Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)コースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Welcome to Elasticsearch!

Welcome to the first lesson on the ELK Stack! We'll start with Elasticsearch, the 'E' in ELK.

Elasticsearch is a powerful, open-source distributed search and analytics engine. It's designed to store, search, and analyze large volumes of data quickly.

  • Distributed: Runs across multiple servers.
  • Real-time: Data is available for search almost instantly.
  • Scalable: Easily handles growing data needs.

Data as JSON Documents

Elasticsearch stores data as JSON documents. Think of a document as a single record, like a row in a database, but more flexible.

Each document is a collection of fields (key-value pairs) and can contain various data types, including text, numbers, dates, and even other JSON objects.

Here's a simple example of a document:

{"user": "alice", "message": "Hello CoddyKit!"}

Understanding Indices

In Elasticsearch, documents are organized into indices. An index is like a database in a relational database system, or a collection in a NoSQL database.

You can have multiple indices, and each index can store documents that are somewhat related. For example, you might have one index for 'logs' and another for 'products'.

  • An index is a logical namespace.
  • It groups similar documents.
  • You search within specific indices.

Indexing Your First Document

Indexing is the process of adding or updating documents in an Elasticsearch index. When you index a document, Elasticsearch stores it and makes it searchable.

Each document needs a unique ID within its index. If you don't provide one, Elasticsearch will generate it for you.

We use HTTP API calls, typically with PUT or POST requests, to interact with Elasticsearch.

Indexing a Document Example

Let's index a simple log document into an index called my_logs. We'll specify an ID of 1.

Try running this command (assuming Elasticsearch is running on localhost:9200):

curl -X PUT "localhost:9200/my_logs/_doc/1?pretty" -H 'Content-Type: application/json' -d'
{
  "timestamp": "2023-10-27T10:00:00Z",
  "level": "info",
  "message": "Application started successfully"
}'

Retrieving Documents by ID

Once a document is indexed, you can retrieve it using its unique ID. This is useful when you know exactly which document you want.

To retrieve a document, you send an HTTP GET request to the specific index and document ID endpoint.

This operation is very fast as Elasticsearch can directly fetch the document.

Retrieving a Document Example

Let's retrieve the document we just indexed with ID 1 from the my_logs index.

Run this command to see the stored document:

curl -X GET "localhost:9200/my_logs/_doc/1?pretty"

Introduction to Searching

The real power of Elasticsearch comes from its searching capabilities. Instead of knowing an ID, you often want to find documents based on their content.

You can search across all documents in an index (or multiple indices) using various query types. Elasticsearch uses a query language based on JSON.

  • Find documents by keywords.
  • Filter by date ranges or specific values.
  • Combine multiple search criteria.

Basic Search: Match All

The simplest search query is the match_all query. It returns all documents in the specified index.

This is often used to verify that documents are indexed correctly or as a starting point for more complex queries.

You send an HTTP GET request to the _search endpoint of your index.

Match All Query Example

Let's search for all documents in our my_logs index. You'll see the document we indexed earlier.

Run this command:

curl -X GET "localhost:9200/my_logs/_search?pretty" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match_all": {}
  }
}'

Quick Check on Indexing

You've learned about documents, indices, and how to index and retrieve data. Let's test your understanding of indexing.

Recap: Indexing and Basic Search

Great job! In this lesson, you've learned the fundamentals of Elasticsearch:

  • Elasticsearch is a distributed search and analytics engine.
  • Data is stored as JSON documents.
  • Documents are organized into indices.
  • Indexing adds or updates documents using PUT/POST requests.
  • Documents can be retrieved by ID using GET requests.
  • Basic searching can be done with queries like match_all.

Next, we'll dive deeper into Logstash, the 'L' in ELK, to ingest and process data!

よくある質問

「Elasticsearch:インデックス作成と検索」レッスンは無料ですか?

はい。「Elasticsearch:インデックス作成と検索」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)コースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)コースには全4レッスンが含まれています。

「Elasticsearch:インデックス作成と検索」で何を学びますか?

分散検索・分析エンジンであるElasticsearchの基礎を学びます。ドキュメントのインデックスを作成し、基本的なクエリを実行する方法を理解します。 ブラウザで直接実行するハンズオンコードでSystem Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)を演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)を始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのSystem Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)は初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。

「Elasticsearch:インデックス作成と検索」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このSystem Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)レッスンでコードを書いて実行できますか?

はい。すべてのSystem Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)レッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. Elasticsearch:インデックス作成と検索
  2. Logstash:データ取り込みと処理
  3. Kibana:可視化とダッシュボード
  4. Beats:軽量データシッパー
← System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)に戻る