如果这只是文档的一小部分,
{ "metricName" : "call", "createdDate" : "2019-10-31T00:00:00.000Z", "responseCode: "200" }
{ "metricName" : "email", "createdDate" : "2019-10-31T00:00:00.000Z", "responseCode: "400" }
{ "metricName" : "chat", "createdDate" : "2019-10-31T00:00:00.000Z", "responseCode: "300" }
.
.
我需要在一个查询中执行以下操作。
最佳答案
聚合API允许使用子聚合按多个字段进行分组。假设要按字段field1,field2和field3分组:
通过此查询可以解决您的1,2和3个问题。
POST /stackoverflow/_search?size=0
{
"query": {
"bool": {
"must": [
{
"match_phrase": {
"createdDate": {
"query": "2019-10-31T00:00:00.000Z",
"slop": 0,
"zero_terms_query": "NONE",
"boost": 1
}
}
},
{
"match_phrase": {
"responseCode": {
"query": "200",
"slop": 0,
"zero_terms_query": "NONE",
"boost": 1
}
}
},
{
"match_phrase": {
"metricName": {
"query": "call",
"slop": 0,
"zero_terms_query": "NONE",
"boost": 1
}
}
}
]
}
},
"aggr": {
"agg1": {
"terms": {
"field": "metricName",
"size": 10,
"order": [
{
"_count": "desc"
},
{
"_key": "asc"
}
]
}
},
"aggs": {
"agg2": {
"terms": {
"field": "createdDate",
"size": 10,
"order": [
{
"_count": "desc"
},
{
"_key": "asc"
}
]
}
}
}
}
}
关于elasticsearch - 如何在Elasticsearch中使用汇总值计算平均值?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/58622894/