Elasticsearch query_string語法查詢
1.根據字段名查詢(Field names)
接口(interface)爲app
interface: app
接口(interface)爲app或live
interface: (app OR live)
精確匹配, 接口是app
interface: “app”
2.通配符(Fuzziness)
‘?’表示單個字符,’*’表示0個或多個字符
- 查找視頻域名
domain: *.video.sina.com.cn
3.範圍查詢(Range)
502次數大於等於50
code502: [50 TO *]
總數大於等於10且小於50
total: [10 TO 50}
4.布爾運算(Boolean operators)
AND
domain: *.video.sina.com.cn AND interface: app
NOT
NOT interface: app
OR
interface: app OR interface: live
5.正則表達式(Regular expressions)
匹配200、300、400、500狀態碼
status:/[2-5]00/
匹配兩個域名
domain:/[nl].portal.com/