如果es还没有支持sql查询,可以先在 https://github.com/NLPchina/elasticsearch-sql 找到支持,从README.md中查找对应版本的下载链接和安装方法。
注意:ES7的最终版本是7.17.14,但是sql-plugins并没有对应版本的开发。
Since 7.5.0.0, the path /_sql is changed to /_nlpcn/sql, and the path /_sql/_explain is changed to /_nlpcn/sql/explain.
Kibana-7.2:
POST _sql
{
"query":
"""
select * from
apm_mi_data_stutter_202007
where appPlatformName = ''
"""
}
Cerebro-es7.2:
_plugins/_sql
{
"query":
"select * from logfmt_019_20230208 where org_timestamp = 1675789200000 and id = 'd367f3e2461d428a9e31fd81ce914ce1' and container.name = 'saleapp' limit 0, 100"
}