Elasticsearch:索引与搜索
学习 Elasticsearch 这款分布式搜索与分析引擎的基础知识。了解如何为文档建立索引并执行基本查询。
Elasticsearch:索引与搜索 是 CoddyKit 上的免费 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Welcome to Elasticsearch!
Welcome to the first lesson on the ELK Stack! We'll start with Elasticsearch, the 'E' in ELK.
Elasticsearch is a powerful, open-source distributed search and analytics engine. It's designed to store, search, and analyze large volumes of data quickly.
- Distributed: Runs across multiple servers.
- Real-time: Data is available for search almost instantly.
- Scalable: Easily handles growing data needs.
Data as JSON Documents
Elasticsearch stores data as JSON documents. Think of a document as a single record, like a row in a database, but more flexible.
Each document is a collection of fields (key-value pairs) and can contain various data types, including text, numbers, dates, and even other JSON objects.
Here's a simple example of a document:
{"user": "alice", "message": "Hello CoddyKit!"}Understanding Indices
In Elasticsearch, documents are organized into indices. An index is like a database in a relational database system, or a collection in a NoSQL database.
You can have multiple indices, and each index can store documents that are somewhat related. For example, you might have one index for 'logs' and another for 'products'.
- An index is a logical namespace.
- It groups similar documents.
- You search within specific indices.
Indexing Your First Document
Indexing is the process of adding or updating documents in an Elasticsearch index. When you index a document, Elasticsearch stores it and makes it searchable.
Each document needs a unique ID within its index. If you don't provide one, Elasticsearch will generate it for you.
We use HTTP API calls, typically with PUT or POST requests, to interact with Elasticsearch.
Indexing a Document Example
Let's index a simple log document into an index called my_logs. We'll specify an ID of 1.
Try running this command (assuming Elasticsearch is running on localhost:9200):
curl -X PUT "localhost:9200/my_logs/_doc/1?pretty" -H 'Content-Type: application/json' -d'
{
"timestamp": "2023-10-27T10:00:00Z",
"level": "info",
"message": "Application started successfully"
}'Retrieving Documents by ID
Once a document is indexed, you can retrieve it using its unique ID. This is useful when you know exactly which document you want.
To retrieve a document, you send an HTTP GET request to the specific index and document ID endpoint.
This operation is very fast as Elasticsearch can directly fetch the document.
Retrieving a Document Example
Let's retrieve the document we just indexed with ID 1 from the my_logs index.
Run this command to see the stored document:
curl -X GET "localhost:9200/my_logs/_doc/1?pretty"Introduction to Searching
The real power of Elasticsearch comes from its searching capabilities. Instead of knowing an ID, you often want to find documents based on their content.
You can search across all documents in an index (or multiple indices) using various query types. Elasticsearch uses a query language based on JSON.
- Find documents by keywords.
- Filter by date ranges or specific values.
- Combine multiple search criteria.
Basic Search: Match All
The simplest search query is the match_all query. It returns all documents in the specified index.
This is often used to verify that documents are indexed correctly or as a starting point for more complex queries.
You send an HTTP GET request to the _search endpoint of your index.
Match All Query Example
Let's search for all documents in our my_logs index. You'll see the document we indexed earlier.
Run this command:
curl -X GET "localhost:9200/my_logs/_search?pretty" -H 'Content-Type: application/json' -d'
{
"query": {
"match_all": {}
}
}'Quick Check on Indexing
You've learned about documents, indices, and how to index and retrieve data. Let's test your understanding of indexing.
Recap: Indexing and Basic Search
Great job! In this lesson, you've learned the fundamentals of Elasticsearch:
- Elasticsearch is a distributed search and analytics engine.
- Data is stored as JSON documents.
- Documents are organized into indices.
- Indexing adds or updates documents using
PUT/POSTrequests. - Documents can be retrieved by ID using
GETrequests. - Basic searching can be done with queries like
match_all.
Next, we'll dive deeper into Logstash, the 'L' in ELK, to ingest and process data!
用 AI 导师学习 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「Elasticsearch:索引与搜索」课时是免费的吗?
是的 — 「Elasticsearch:索引与搜索」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课程的其余内容,请升级到 CoddyKit PRO。 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课程共包含 4 节课。
「Elasticsearch:索引与搜索」这节课中我会学到什么?
学习 Elasticsearch 这款分布式搜索与分析引擎的基础知识。了解如何为文档建立索引并执行基本查询。 你通过在浏览器中直接运行的动手代码来练习 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry),全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 需要有经验吗?
无需任何先前经验。CoddyKit 上的 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「Elasticsearch:索引与搜索」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课中编写并运行代码吗?
能。每节 System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- Elasticsearch:索引与搜索
- Logstash:数据摄取与处理
- Kibana:可视化与仪表板
- Beats:轻量级数据采集器