message field has been analyzed using standard analyzer. It means that you
message content has been indexed using lowercase.
a Term Filter does not analyze your query.
"DEBUG" is <> than "debug".
If you want to find your term in the inverted index, you have either to analyze
your query (matchQu
Hi David,
I have done following steps u suggested. The string search is working now.
But for filter I have to always pass strings in lowercase; where as for
query text search I can give the proper string sequence inserted in doc.
query shown below.
May be this is very basic and I'm doing somet
Hi David,
I have done following steps u suggested. The exact string search is working
now.
But when I'm trying the below query for string matching it's giving null
result.
May this is very basic and I'm doing something wrong. I'm a week old on
elasticsearch and trying to understand the query-s
May be this could help?
http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-templates.html#indices-templates
--
David Pilato | Technical Advocate | Elasticsearch.com
@dadoonet | @elasticsearchfr
Le 12 mars 2014 à 11:25:53, Subhadip Bagui (i.ba...@gmail.com) a écrit:
Hi David,
The data is coming through logstash and taking default mapping in
elasticsearch. Can I do update mapping for that index id ?
Pls let me know.
--
You received this message because you are subscribed to the Google Groups
"elasticsearch" group.
To unsubscribe from this group and stop r
Didn't you read my previous answer?
This example has nothing in common with your data!
That said, you need to apply the mapping before indexing any document!
We can't help you without a full curl recreation which actually reproduce your
issue.
I think you are doing something wrong here but it's
Hi Binh,
The query you given is working. Thanks for your help.
But if I change the query and search for string "requestproxyauthentication"
instead, It's not working. Below is the mapping for message field.
I'm trying to understand how elasticsearch analyze the field data. Pls
comment.
"mess
The standard analyzer makes (RequestProxyAuthentication.java) into 1 term
and lowercases it. So this one should match it:
{
"query": {
"constant_score": {
"filter": {
"term": { "message": "requestproxyauthentication.java" }
}
}
}
}
This example has nothing in common with your data!
That said, you need to apply the mapping before indexing any document!
--
David Pilato | Technical Advocate | Elasticsearch.com
@dadoonet | @elasticsearchfr
Le 11 mars 2014 à 14:47:34, Subhadip Bagui (i.ba...@gmail.com) a écrit:
Hi David,
Hi David,
I have done like below for a test sample.
1. deleted index.
2. create index by following
curl -XPUT "http://localhost:9200/movies/"; -d
'{ "index": {"_index": "movies", "_type": "movie", "_id": "1"}}'
3. creating doc
curl -XPUT "http://localhost:9200/movies/movie/1"; -d
'{
So message seems to use a default analyzer…
May be you could try to reproduce your concern with a full curl recreation
which:
delete test index,
create index
put template
create a doc
refresh
query
It could help to understand what's wrong here. I'm probably missing something.
--
David Pilato
mapping...default
{
- "logstash-2014.03.03":{
- "mappings":{
- "apache-access":{
- "dynamic_templates":[
- {
- "string_fields":{
- "mapping":{
- "type":"multi_field",
mapping...
{
- "movies":{
- "mappings":{
- "movie":{
- "properties":{
- "director":{
- "type":"string",
- "fields":{
- "original":{
- "type":"string",
what is your mapping?
--
David Pilato | Technical Advocate | Elasticsearch.com
@dadoonet | @elasticsearchfr
Le 11 mars 2014 à 11:03:00, Subhadip Bagui (i.ba...@gmail.com) a écrit:
Hi David,
Trying to query as following, but still getting null result. Please suggest.
{
"query": {
Hi David,
Trying to query as following, but still getting null result. Please suggest.
{
"query": {
"constant_score": {
"filter": {
"term": { "message": "requestproxyauthentication" }
}
}
}
}
-Subhadip
--
You received this messag
lowercase your term filter.
TermFilter is not analyzed.
--
David ;-)
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
Le 11 mars 2014 à 09:18, Subhadip Bagui a écrit :
Hi,
I've a index in my elasticsearch like below
{
"_index":"logstash-2014.03.03",
"_type":"apache-access",
"_id":"snCPR
Hi,
I've a index in my elasticsearch like below
{
- "_index":"logstash-2014.03.03",
- "_type":"apache-access",
- "_id":"snCPRnSHSvm_aaeuHxB84w",
- "_version":1,
- "found":true,
- "_source":{
- "message":"\tat
org.apache.http.client.protocol.RequestProxyAuthenti
17 matches
Mail list logo