Elasticsearch实战 复合聚合查询排序统计

整体查询条件

{
    "size": 0,
    "query": {
        "bool": {
            "must": [
                {
                    "range": {
                        "attack_time": {
                            "from": "2023-02-07 15:00:00",
                            "to": "2023-02-07 16:00:03",
                            "include_lower": true,
                            "include_upper": true,
                            "boost": 1
                        }
                    }
                },
                {
                    "terms": {
                        "alarm_project_id": [
                            1,
                            5
                        ],
                        "boost": 1
                    }
                }
            ],
            "adjust_pure_negative": true,
            "boost": 1
        }
    },
    "aggregations": {
        "agg_composite_project_ip": {
            "composite": {
                "size": 10000000,
                "sources": [
                    {
                        "ip": {
                            "terms": {
                                "field": "ip",
                                "missing_bucket": false,
                                "order": "asc"
                            }
                        }
                    },
                    {
                        "project_id": {
                            "terms": {
                                "field": "alarm_project_id",
                                "missing_bucket": false,
                                "order": "asc"
                            }
                        }
                    }
                ]
            },
            "aggregations": {
                "agg_max_time": {
                    "max": {
                        "field": "attack_time"
                    }
                },
                "agg_max_threat_level": {
                    "max": {
                        "field": "alarm_project_threat_level"
                    }
                },
                "agg_bucket_sort_page": {
                    "bucket_sort": {
                        "sort": [
                            {
                                "agg_max_time": {
                                    "order": "desc"
                                }
                            }
                        ],
                        "from": 0,
                        "size": 10,
                        "gap_policy": "SKIP"
                    }
                }
            }
        },
        "agg_cardinality_project_ip": {
            "cardinality": {
                "script": {
                    "source": "doc['alarm_project_id'].value + doc['ip'].value",
                    "lang": "painless"
                }
            }
        }
    }
}

核心功能Java代码

分页排序

        List<FieldSortBuilder> sorts = new ArrayList<>();
        FieldSortBuilder fieldSort = null;
        Boolean threatLevelSortDesc = alarmDataSearchReq.getThreatLevelSortDesc();
        if (threatLevelSortDesc != null) {
            fieldSort = new FieldSortBuilder("agg_max_threat_level");
            fieldSort.order(threatLevelSortDesc ? SortOrder.DESC : SortOrder.ASC);
        } else {
            fieldSort = new FieldSortBuilder("agg_max_time");
            Boolean timeSortDesc = alarmDataSearchReq.getTimeSortDesc();
            if (timeSortDesc == null || timeSortDesc) {
                fieldSort.order(SortOrder.DESC);
            } else {
                fieldSort.order(SortOrder.ASC);
            }
        }
        sorts.add(fieldSort);

        Integer size = pageReq.getPageSize();
        Integer from = (pageReq.getPage() - 1) * size;
        CompositeAggregationBuilder compositeAggregationBuilder = buildProjectIpCompositeAggregation();
        compositeAggregationBuilder
                .subAggregation(AggregationBuilders.max("agg_max_threat_level")
                        .field(FILED_PROJECT_THREAT_LEVEL))
                .subAggregation(PipelineAggregatorBuilders
                        .bucketSort("agg_bucket_sort_page", sorts).from(from).size(size));

复合聚合

        List<CompositeValuesSourceBuilder<?>> listValuesSource = new ArrayList<>();
        TermsValuesSourceBuilder valuesSourceIp = new TermsValuesSourceBuilder("ip");
        valuesSourceIp.field("ip");
        listValuesSource.add(valuesSourceIp);
        TermsValuesSourceBuilder valuesSourceProject = new TermsValuesSourceBuilder("project_id");
        valuesSourceProject.field(FILED_PROJECT_ID);
        listValuesSource.add(valuesSourceProject);

        CompositeAggregationBuilder compositeAggregationBuilder = AggregationBuilders.composite(
                "agg_composite_project_ip", listValuesSource);
        compositeAggregationBuilder.size(10000000).subAggregation(AggregationBuilders
                .max("agg_max_time").field("attack_time"));

聚合数据查询

List<AlarmDataProjectIpDTO> list = new ArrayList<>();
        ParsedComposite parsedComposite = search.getAggregations().get("agg_composite_project_ip");
        List<ParsedComposite.ParsedBucket> buckets = parsedComposite.getBuckets();
        for (ParsedComposite.ParsedBucket bucket : buckets) {
            AlarmDataProjectIpDTO alarmDataProjectIpDTO = new AlarmDataProjectIpDTO();

            Map<String, Object> key = bucket.getKey();
            alarmDataProjectIpDTO.setIp(key.get("ip").toString());
            alarmDataProjectIpDTO.setProjectId((Integer) key.get("project_id"));

            String maxAttackTime = ((Max) bucket.getAggregations()
                    .get("agg_max_time")).getValueAsString();
            alarmDataProjectIpDTO.setTime(maxAttackTime);

            alarmDataProjectIpDTO.setCount(bucket.getDocCount());

            list.add(alarmDataProjectIpDTO);
        }

聚合统计查询

ParsedCardinality parsedCardinality = search.getAggregations().get("agg_cardinality_project_ip");
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
Elasticsearch 中,可以使用聚合(Aggregation)实现对文档进行聚合统计,其中包括出现次数的统计。下面是一个示例: 假设我们有一个名为 "sales" 的索引,包含以下文档: ``` { "product": "A", "price": 10.0, "timestamp": "2021-08-01T10:00:00Z" } { "product": "B", "price": 15.0, "timestamp": "2021-08-01T10:05:00Z" } { "product": "A", "price": 12.0, "timestamp": "2021-08-01T10:10:00Z" } { "product": "C", "price": 20.0, "timestamp": "2021-08-01T10:15:00Z" } { "product": "A", "price": 8.0, "timestamp": "2021-08-01T10:20:00Z" } { "product": "B", "price": 18.0, "timestamp": "2021-08-01T10:25:00Z" } ``` 现在,我们想要统计每个产品出现的次数,可以使用以下聚合查询: ``` { "aggs": { "products": { "terms": { "field": "product" } } } } ``` 其中,"aggs" 是聚合查询的关键字,"products" 是我们给这个聚合起的名字,"terms" 表示我们要按照某个字段进行分组,"field" 指定了我们要按照哪个字段进行分组。 运行上述查询后,得到的结果如下: ``` { "aggregations": { "products": { "buckets": [ { "key": "A", "doc_count": 3 }, { "key": "B", "doc_count": 2 }, { "key": "C", "doc_count": 1 } ] } } } ``` 其中,"key" 表示产品名称,"doc_count" 表示该产品出现的次数。 如果想要对出现次数进行排序,可以使用以下聚合查询: ``` { "aggs": { "products": { "terms": { "field": "product", "order": { "_count": "desc" } } } } } ``` 其中,"order" 表示按照什么字段进行排序,"_count" 表示按照出现次数进行排序,"desc" 表示降序排列。 运行上述查询后,得到的结果如下: ``` { "aggregations": { "products": { "buckets": [ { "key": "A", "doc_count": 3 }, { "key": "B", "doc_count": 2 }, { "key": "C", "doc_count": 1 } ] } } } ``` 其中,产品 A 出现的次数最多,排在第一位。

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值