Graylog解决超出ES搜索最大窗口限制问题

今天在查询日志的时候graylog报了一个错:

While retrieving data for this widget, the following error(s) occurred:

Unable to perform search query: Elasticsearch exception type=illegal_argument_exception, reason=Result window is too large, from + size must be less than or equal to: \[10000 but was 12081150. See the scroll api for a more efficient way to request large data sets. This limit can be set by changing the index.max_result_window index level setting.].

说是ES默认设置最大搜索窗口(index.max_result_window)为10000条,也是是搜索可以返回的条数

查了下可以修改index.max_result_window

1.修改现有的索引

在ES所在的服务器中输入以下指令

curl -H "Content-Type: application/json" -XPUT http://127.0.0.1:9200/_all/_settings -d '{ "index" : { "max_result_window" : 1000000}}'

2.修改索引模板,从而新创建的索引也修改index.max_result_window

curl -H "Content-Type: application/json" -XPUT http://127.0.0.1:9200/_template/graylog-gdmp-mapping -d '{

"order": 1,

"index_patterns": [

"gdmp_*"

],

"settings": {

"index": {

"analysis": {

"analyzer": {

"analyzer_keyword": {

"filter": "lowercase",

"tokenizer": "keyword"

}

}

},

"max_result_window": 1000000

}

},

"mappings": {

"_source": {

"enabled": true

},

"dynamic_templates": [

{

"internal_fields": {

"mapping": {

"type": "keyword"

},

"match_mapping_type": "string",

"match": "gl2_*"

}

},

{

"store_generic": {

"mapping": {

"type": "keyword"

},

"match_mapping_type": "string"

}

}

],

"properties": {

"streams": {

"type": "keyword"

},

"message": {

"fielddata": false,

"analyzer": "standard",

"type": "text"

},

"timestamp": {

"format": "uuuu-MM-dd HH:mm:ss.SSS",

"type": "date"

}

}

}

}'

  • 这个 cURL 命令的目的是在 Elasticsearch 中创建或更新名为 graylog-gdmp-mapping 的模板,该模板适用于以 gdmp_ 开头的所有索引,并定义了相应的映射和设置。
相关推荐
ly76898 小时前
倒排索引与 FST 在 Lucene 中的内存布局:segment、docValues 与词典压缩的工程取舍
elasticsearch·lucene·倒排索引·doc values·fst
奈落248 小时前
AI 编程从助手到 Agent:基于两份资料看哪些环节可以交出去,哪些必须自己攥住
大数据·人工智能
Joker可视化开发平台8 小时前
AI短剧接棒真人剧:开机量跌七成,普通人进场窗口在收窄
大数据·人工智能
数据狐(Datafox)8 小时前
淘宝图片搜索 API 落地实战:基于以图搜货搭建跨境电商选品系统
java·大数据·微服务
YangYang9YangYan8 小时前
2027 秋招|数据科学与大数据技术面试项目价值回答思路,告别纯代码描述
大数据·面试·职场和发展
2601_960356389 小时前
2027 校招质量工程师岗位拆解:数学、统计、大数据专业如何判断匹配度
大数据
Elasticsearch9 小时前
利用预计算上下文,更快速、更低成本地开展支持问题调查
elasticsearch
KeyAction666610 小时前
AI改写战争规则,也在改写商业规则:体系对抗时代已经到来
大数据·人工智能
Qyr9911 小时前
2026年全球二极管模组行业市场规模全景研判:竞争格局与发展趋势全解析
大数据·人工智能
小小小米粒12 小时前
重置本地git
大数据·git·elasticsearch