关闭

Kibana User Guide [4.2] » Getting Started with Kibana » Defining Your Index Patterns

标签: ELKKibana
498人阅读 评论(0) 收藏 举报
分类:

Each set of data loaded to Elasticsearch has an index pattern. In the previous section, the Shakespeare data set has an index named shakespeare, and the accounts data set has an index named bank. An index pattern is a string with optional wildcards that can match multiple indices. For example, in the common logging use case, a typical index name contains the date in MM-DD-YYYY format, and an index pattern for May would look something like logstash-2015.05*.

每个加载到ES的数据集都有一个索引模式。在前一部分,莎士比亚数据集有一个叫“莎士比亚”的索引名,而且,计数数据集用一个索引名叫“bank”。索引模式是一个包含可选通配符的字符串,它可以匹配多种索引。例如,在通常的日志使用案例中,一个典型的索引名包括MM-DD-YYYY 格式的日期,而且五月的索引模式看起来像是logstash-2015.05。

For this tutorial, any pattern that matches the name of an index we’ve loaded will work. Open a browser and navigate to localhost:5601. Click the Settings tab, then the Indices tab. Click Add New to define a new index pattern. Two of the sample data sets, the Shakespeare plays and the financial accounts, don’t contain time-series data. Make sure the Index contains time-based events box is unchecked when you create index patterns for these data sets. Specify shakes* as the index pattern for the Shakespeare data set and click Create to define the index pattern, then define a second index pattern named ba*.

在这篇教程中,任何满足我们加载的满足索引名字的模式都将产生作用。打开浏览器,访问localhost:5601。点击‘Settings’按钮,然后是‘Indices’按钮。点击‘Add New’来定义一个新模式。两个数据集中的简单例子,莎士比亚剧本和财务记账,并没有包含时间序列的数据。当你为数据集创建索引模式时,确保‘Index contains time-based events’的使用未受限。为莎士比亚数据集,指定‘shake*’作为索引模式,然后点击‘Create’来定义索引模式,最后定义一个名字是‘ba*’的二级索引模式。

The Logstash data set does contain time-series data, so after clicking Add New to define the index for this data set, make sure the Index contains time-based events box is checked and select the @timestamp field from the Time-field name drop-down.

Logstash数据集包含时间序列的数据,所以,在点击‘Add New’来为数据集定义索引之后,确保‘Index contains time-based events’栏是封闭的,从’Time-field name‘下拉列表选择@timestamp字段。

Discovering Your Data

Discover你的数据

Click the Discover tab to display Kibana’s data discovery functions:

点击’Discover‘键来展示Kibana数据的发现功能。


Right under the tab itself, there is a search box where you can search your data. Searches take a specificquery syntax that enable you to create custom searches, which you can save and load by clicking the buttons to the right of the search box.

在’Discover‘标签的正下方,有一个搜索栏,你在那里可以搜索数据。搜索使用了一种特殊的请求语法,来保证你能创建普通搜索,你可以通过点击搜索栏右边的按钮来保存和加载。

Beneath the search box, the current index pattern is displayed in a drop-down. You can change the index pattern by selecting a different pattern from the drop-down selector.

在搜索栏下方,现在的搜索模式被展现在下拉菜单。你可以从下拉选择器中,选择一个不同的模式,来改变搜索模式。

You can construct searches by using the field names and the values you’re interested in. With numeric fields you can use comparison operators such as greater than (>), less than (<), or equals (=). You can link elements with the logical operators AND, OR, and NOT, all in uppercase.

你可以使用你感兴趣的字段名和值来构建搜索。对于数据字段,你可以使用’>‘,'<'或’=‘。你可以使用键盘上的逻辑操作’AND‘,’OR‘和’NOT‘来连接元素。

Try selecting the ba* index pattern and putting the following search into the search box:

试着选择’ba*‘索引模式,把下面的内容放在索引栏:

account_number:<100 AND balance:>47500

This search returns all account numbers between zero and 99 with balances in excess of 47,500.

If you’re using the linked sample data set, this search returns 5 results: Account numbers 8, 32, 78, 85, and 97.

这次搜索返回了数字在0到99之间,而账目大于47500的内容。

如果你使用链接中的样本数据集,这次搜索将返回5个结果:账目数据8,32,78,85和97。


To narrow the display to only the specific fields of interest, highlight each field in the list that displays under the index pattern and click the Add button. Note how, in this example, adding the account_numberfield changes the display from the full text of five records to a simple list of five account numbers:

为了把展示结果限定成感兴趣的字段,突出索引模式下列表中的每个字段,点击’Add‘按钮。在这个例子中,添加’account_number‘字段,把显示的完整信息变成只显示五个数字:



备注:

材料来自elastic官网。

地址:

https://www.elastic.co/guide/en/kibana/current/tutorial-define-index.html


0
0
查看评论
发表评论
* 以上用户言论只代表其个人观点,不代表CSDN网站的观点或立场

Kibana4 的安装和使用

安排、配置和运行Kibana4 安装方式依然简单,你可以在几分钟内安装好 Kibana 然后开始探索你的 Elasticsearch 索引。只需要预备:• Elasticsearch 1.4.4 ...
  • u012373815
  • u012373815
  • 2016-03-31 20:32
  • 13602

关于浏览器进入Kibana,初始配置时无法create,显示unable to fetch mapping的问题

主要还是因为版本问题,检查Elasticsearch的版本和Kibana是否一致(这点很坑啊,开始我用ES5.4.3+Kibana5.4.2也create不了) 博主开始是用ES5.2.2+Kiba...
  • qq_25650651
  • qq_25650651
  • 2017-06-28 12:54
  • 3458

Kibana的图形化——Tile Map

简介  当我们查看访问网站的流量的来源时,往往通过awk+sed或其他工具分析日志文件,有没有一种方式可以实时查看并且在地图上直观的表现出来?当然,我们的Kibana就可以做到,下面我们来看看如何配置...
  • yanggd1987
  • yanggd1987
  • 2016-01-06 15:13
  • 12678

Kibana User Guide [4.2] » Getting Started with Kibana

Getting Started with Kibana 开始使用Kibana Now that you have Kibana installed, you can step through ...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-18 20:37
  • 547

Kibana User Guide [4.2] » Getting Started with Kibana » Data Visualization: Beyond Discovery

Data Visualization: Beyond Discovery 数据可视化:Discovery之外的内容 The visualization tools available on th...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-19 09:51
  • 1013

Kibana User Guide [4.2] » Getting Started with Kibana » Putting it all Together with Dashboards

Putting it all Together with Dashboards 使用仪表盘整合在一起 A Kibana dashboard is a collection of v...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-19 14:02
  • 410

Kibana User Guide [4.2] » Getting Kibana Up and Running

Getting Kibana Up and Running 启动并运行Kibana You can set up Kibana and start exploring your E...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-18 16:42
  • 938

Kibana User Guide [4.2] » Discover

Discover 发现 You can interactively explore your data from the Discover page. You have access to every...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-19 15:33
  • 1233

Kibana User Guide [4.2] » Visualize » Data Table

Data Table 数据表 Count 计数 The count aggregation returns a raw count of the elements in the selec...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-20 15:00
  • 1824

Kibana User Guide [4.2] » Visualize

Visualize  可视化 You can use the Visualize page to design data visualizations. You can save these ...
  • wang_zhenwei
  • wang_zhenwei
  • 2015-11-19 22:02
  • 1282
    个人资料
    • 访问:646211次
    • 积分:8556
    • 等级:
    • 排名:第2667名
    • 原创:115篇
    • 转载:428篇
    • 译文:37篇
    • 评论:35条
    文章分类