0
votes

I need to translate OLD queries from ES2.0 to ES6.1 ... and it seems not easy at all ... the original one is :

{
    "size":0,
    "query": {
        "bool": {
            "filter": {
                "bool": {
                    "must": {
                        "query": {
                            "match": {
                                "my_hits": {
                                    "query": 0,
                                    "type": "phrase"
                                }
                            }
                        }
                    }
                }
            }
        }
    },
    "fields": "ip",
    "aggregations": {
        "par_ip": {
            "terms": {
                "field": "ip",
                "min_doc_count": 2,
                "size": 10000,
                "order": {
                    "_term": "asc"
                }
            }
        }
    }
}

I think that the first part could be converted to :

{
 "size": 0,
 "query": {
    "match" : {
        "my_hits": "0"
    }
  }
}

but for the rest I am stuck ...

"type": "illegal_argument_exception", "reason": "Fielddata is disabled on text fields by default. Set fielddata=true on [ip] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead."

EDIT : I think you will need thoses informations :

"mappings": { ... "ip": { "type": "text", "fields": { "keyword": { "type": "keyword", "ignore_above": 256 } } },

Thanks for your help ! Stéphane

1
to delete !!!!! - Stéphane MERLE
i think it's the "fields": "ip" line that is causing the trouble. Try removing it? If it works, try with "fields": "ip.keyword" - Archit Saxena

1 Answers

0
votes

If you want to preserve the filter clause, which will not take scoring into consideration, so no result ordering control, one possible translation would be:

{
    "size":0,
    "query": {
        "bool": {
            "filter": {
              "match_phrase": {
                "my_hits": "some query"
              }
          }
        }
    },
    "stored_fields": "ip",
    "aggregations": {
        "par_ip": {
            "terms": {
                "field": "ip",
                "min_doc_count": 2,
                "size": 10000,
                "order": {
                    "_term": "asc"
                }
            }
        }
    }
}

here also change fields field to stored_fields, the match query with type phrase is now a match_phrase query. In case you want the query to influence the score of the results, you should avoid the filter clause:

{
    "size":0,
    "query": {
       "match_phrase": {
          "my_hits": "some query"
       }
    },
    "stored_fields": "ip",
    "aggregations": {
        "par_ip": {
            "terms": {
                "field": "ip",
                "min_doc_count": 2,
                "size": 10000,
                "order": {
                    "_term": "asc"
                }
            }
        }
    }
}

you will have to mark the ip field as stored "store": true in the mapping if you want to retrieve it as a stored_field