首页 \ 问答 \ ELK中fieldname和fieldname.raw之间的区别?(Difference between fieldname and fieldname.raw in ELK?)

ELK中fieldname和fieldname.raw之间的区别?(Difference between fieldname and fieldname.raw in ELK?)

在网络上的一些资源之后,我一直在尝试使用ELK堆栈。 但是我没有发现任何明显的资源,可以清楚地解释fieldnamefieldname.raw之间的区别,这个区域名称为fieldname

在这种情况下没有什么可尝试的,但我确实尝试过搜索,但没有运气。 我对此的唯一主要理解是形成Kibana窗口(我不知道如何重现,遗憾地)说: fieldname是一个分析字段。 没有关于fieldname.raw信息

我注意到的另一件事是,当我在Kibana4 Discover中使用fieldname.raw: "value" ,它显示的结果比我看到的fieldname: "value"更少。 由于我分别从这些输入中获得了559和554个结果,所以我看不出哪些丢失了。

我在猜测后缀.raw说明它的含义 - 它可能是来自日志本身的一个字段,无需Logstash的干预。 但我想确定这是否意味着什么。 如果是这样,那么在一个分析领域,我是如何(也是更重要的是,为什么?)得到较少的结果? 有什么Logstash不正确或者是某种错误配置? 任何指针赞赏。


I have been experimenting with ELK stack for a while now following a few resources on the web. But I didn't find any significant resource that clearly explains the difference between fieldname and fieldname.raw for a field with say name fieldname.

There is nothing much to try in this context but I did try and search this but no luck. The only primary understanding that I have on this is form Kibana window (which I don't know how to reproduce, sadly) that said: fieldname is an analyzed field. There was not such info regarding fieldname.raw

One other thing I noticed is that when I use fieldname.raw: "value" in the Kibana4 Discover it shows little more results than what I see fieldname: "value". I could not see which ones were missing since I had 559 and 554 results form these inputs, respectively.

I am guessing the suffix .raw says what it means - It might be a field from the logs itself without any intervention by Logstash. But I want to make sure if that is what it means. If so, then how (and more importantly, why?) did I get less results in an analyzed field? Is there anything that Logstash isn't doing right or is it some kind of misconfiguration? Any pointers are appreciated.


原文:https://stackoverflow.com/questions/31440011
更新时间:2023-08-22 17:08

最满意答案

Rollup.js 在这里记录了一个选项。

感谢Rollup GitHub页面上的Olsonpm


Rollup.js has an outro option documented here.

Thanks to Olsonpm on the Rollup GitHub page

相关问答

更多

相关文章

更多

最新问答

更多
  • 使用通配符获取更多servlet请求变量[重复](Get more servlet request variables using wildcards [duplicate])
  • 返回相同的集合类型,参数化不同(Returning same collection type, differently parameterised)
  • C ++朋友函数模板重载和SFINAE在clang ++,g ++,vc ++中的不同行为(C ++ 14模式)(C++ friend function template overloading and SFINAE different behaviors in clang++, g++, vc++ (C++14 mode))
  • 与paure IoT-Hub的Python paho-MQTT连接(Python paho-MQTT connection with azure IoT-Hub)
  • 编译器警告“来自不同的Objective-C类型的赋值”(Compiler warning “assignment from distinct objective-c type”)
  • C ++编译错误(在此函数中未初始化)[重复](C++ Compile Error (uninitialized in this function) [duplicate])
  • unsigned-signed下溢机制(unsigned-signed underflow mechanism)
  • 快速行查询的数据结构?(Data structure for fast line queries?)
  • 饥荒有手机安卓版的吗
  • Jquery可拖动碰撞检测错误(Jquery draggable collision detection bug)
  • sql调优是怎样来实现的?
  • 无法使占位符输入文本消失(Unable to make the placeholder input text disappear)
  • jQuery改变了两个div的CSS属性(JQuery change CSS property of two div's)
  • JDK中包含的库版本(Versions of libraries included in the JDK)
  • 请问下载的是出现ASP是什么意思
  • Firebase MLkit用于数字液晶显示器的文本识别(Firebase MLkit Text recognition for digital lcd displays)
  • 我可以在任何平台上运行C和C ++吗?(Can I run C and C++ on any platform?)
  • 让小组在C#的特定位置(get panel at specific positions in C#)
  • Nagios为通知设置了更高的间隔(Nagios set higher interval for notifications)
  • 无法向SMTP主机发送电子邮件(unable to send an email to SMTP host)
  • 获取MVC 4使用的DisplayMode后缀(Get the DisplayMode Suffix being used by MVC 4)
  • 如何在.NET代码中验证全球邮政编码(How can I validate worldwide postal codes in my .NET code)
  • 如何通过引用返回对象?(How is returning an object by reference possible?)
  • Clojure:减少大型懒惰收集会占用内存(Clojure: Reducing large lazy collection eats up memory)
  • 矩阵如何存储在内存中?(How are matrices stored in memory?)
  • 每个请求的Java新会话?(Java New Session For Each Request?)
  • 显示作为字符串的SVG(Showing an SVG that I have as a string)
  • 从jansson库里创建json请求的自由内存的正确方式是什么?(what is the proper way of free memory in creating json request from jansson libary?)
  • jQuery插件无法正常工作 - 它是附加的(jQuery plugin not working - it's appended)
  • 使用stat_summary自动调整ylim(Automatically adjusting ylim with stat_summary)