Compare commits
219
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
370ff0fc57 | ||
|
|
c2f1018b36 | ||
|
|
dda5e2a535 | ||
|
|
0686ae05b5 | ||
|
|
973d967514 | ||
|
|
dcb3a0c02d | ||
|
|
65d2ef4860 | ||
|
|
d4c20f0402 | ||
|
|
9a5c8cd6ae | ||
|
|
48d1603ed1 | ||
|
|
01a9fb6d6d | ||
|
|
cbdefc2463 | ||
|
|
a38eb15400 | ||
|
|
dc69f8010b | ||
|
|
268f1d9571 | ||
|
|
f8cac33ebc | ||
|
|
eda842a36d | ||
|
|
7c425f102d | ||
|
|
c85fd21b4f | ||
|
|
430b9fed50 | ||
|
|
e8a863e943 | ||
|
|
b12dab6705 | ||
|
|
d2ba96967b | ||
|
|
a9144167d8 | ||
|
|
07b0650128 | ||
|
|
bff43bed13 | ||
|
|
75efdfeae8 | ||
|
|
30378f0076 | ||
|
|
4ffdce6377 | ||
|
|
21ae64aac9 | ||
|
|
ba9f432622 | ||
|
|
35a7b186fc | ||
|
|
6a36ee4535 | ||
|
|
2a0cf500cc | ||
|
|
125585f04e | ||
|
|
ed8230cb02 | ||
|
|
5a1a4cfdef | ||
|
|
b030194981 | ||
|
|
c507de5b9f | ||
|
|
2c713e43ad | ||
|
|
243c7315e4 | ||
|
|
0fc6a9e057 | ||
|
|
eaba608cfd | ||
|
|
b1d3a5906b | ||
|
|
34068f01bd | ||
|
|
ecea83707d | ||
|
|
f29b04bdb9 | ||
|
|
cda046f727 | ||
|
|
ffe3f77993 | ||
|
|
60b1859f1e | ||
|
|
baa5622f9d | ||
|
|
dc48c6ced5 | ||
|
|
62611a7605 | ||
|
|
94503ea959 | ||
|
|
449177c07e | ||
|
|
f464d01041 | ||
|
|
36694537f6 | ||
|
|
26d3dfe351 | ||
|
|
7faade1bdf | ||
|
|
5ddabb88bd | ||
|
|
edd9d2e313 | ||
|
|
d941cb6ad7 | ||
|
|
17f91f09a3 | ||
|
|
36853b6484 | ||
|
|
eaeeb97630 | ||
|
|
dd2d93793a | ||
|
|
6c5432db1f | ||
|
|
78621f98e3 | ||
|
|
bdffb128d8 | ||
|
|
0376c4b6d9 | ||
|
|
ff8cd66090 | ||
|
|
df42f777f9 | ||
|
|
f3a9bad35c | ||
|
|
17ae32cb9a | ||
|
|
861644393d | ||
|
|
b863e18503 | ||
|
|
8e3451358b | ||
|
|
5789bb4c28 | ||
|
|
3901ea23c1 | ||
|
|
00d2db4917 | ||
|
|
60da8fa182 | ||
|
|
b9023ab6ec | ||
|
|
90e28e6f23 | ||
|
|
d60acc5fd2 | ||
|
|
747c4d7730 | ||
|
|
10ec3ef95e | ||
|
|
b695c750ad | ||
|
|
f9baa125c3 | ||
|
|
fd1ea4c9ac | ||
|
|
1dcdee97f8 | ||
|
|
2452e60305 | ||
|
|
7d070e1ac2 | ||
|
|
83a7bbffc0 | ||
|
|
8d548ca475 | ||
|
|
c8761d3bd6 | ||
|
|
b5812bebbf | ||
|
|
d90d9859a2 | ||
|
|
294da5c0df | ||
|
|
6ebe39307e | ||
|
|
b6f61a753c | ||
|
|
d6b02c0e17 | ||
|
|
f7093ffd8f | ||
|
|
0a497238c7 | ||
|
|
0c9fe0271a | ||
|
|
d1a065587c | ||
|
|
2561bc262f | ||
|
|
be92ce0783 | ||
|
|
95b5157c19 | ||
|
|
1d99315e8b | ||
|
|
6f32dce469 | ||
|
|
fac01d293e | ||
|
|
634db90e9b | ||
|
|
42095bd2d7 | ||
|
|
0d58bcf854 | ||
|
|
a75fbf62dc | ||
|
|
5b1f7fdaca | ||
|
|
dbb3d893ac | ||
|
|
187bccec6b | ||
|
|
3f7f651619 | ||
|
|
bd944e8448 | ||
|
|
fa7943b905 | ||
|
|
47a1573202 | ||
|
|
45fea0e20e | ||
|
|
4a4c43482a | ||
|
|
bdf53c9117 | ||
|
|
ee1400ff2b | ||
|
|
eb51f06694 | ||
|
|
1f60c9c307 | ||
|
|
bf78a468c3 | ||
|
|
8c703b9cff | ||
|
|
a3808e858a | ||
|
|
59f7ffeb99 | ||
|
|
eac60ec797 | ||
|
|
b8b7fb13e3 | ||
|
|
b4461e130f | ||
|
|
ba5bfa429f | ||
|
|
266df8e006 | ||
|
|
c18cced55a | ||
|
|
31613067dd | ||
|
|
8d178c3d83 | ||
|
|
cfb582dd26 | ||
|
|
96e0c4dbcd | ||
|
|
880a635b90 | ||
|
|
9ab749a7df | ||
|
|
2ff209d0b8 | ||
|
|
28e0409da3 | ||
|
|
7c33c8d5a4 | ||
|
|
f315193267 | ||
|
|
84e9440f18 | ||
|
|
96a70a820a | ||
|
|
3d509b3976 | ||
|
|
dc2f349d7e | ||
|
|
db86114248 | ||
|
|
30df98e078 | ||
|
|
0ac341523a | ||
|
|
15f9c6bc5c | ||
|
|
a9bde64480 | ||
|
|
a4cca7c71b | ||
|
|
4705da9726 | ||
|
|
5f678cd814 | ||
|
|
01df7f0b53 | ||
|
|
d06c1bc978 | ||
|
|
e378928a5d | ||
|
|
31bf69767a | ||
|
|
a77c678c98 | ||
|
|
76e3b2710e | ||
|
|
793ce77490 | ||
|
|
2b31c5392c | ||
|
|
37cab900a5 | ||
|
|
6c9a46c130 | ||
|
|
15a5f18fb7 | ||
|
|
4453173942 | ||
|
|
23981ecc33 | ||
|
|
a99458c41b | ||
|
|
b93af9a94b | ||
|
|
25421e60e0 | ||
|
|
c961ca45d0 | ||
|
|
fb9ecbbc15 | ||
|
|
63f391a3ef | ||
|
|
537eaa7743 | ||
|
|
c098a80fdb | ||
|
|
9574bd2c30 | ||
|
|
951a2e01f1 | ||
|
|
546ce5293b | ||
|
|
9e4618111c | ||
|
|
40f2e462c1 | ||
|
|
0257a9de5d | ||
|
|
cff7b8fea3 | ||
|
|
9ae5a6bfc8 | ||
|
|
3bbdae031e | ||
|
|
540595fcea | ||
|
|
13eb8e50ff | ||
|
|
c6aaa74993 | ||
|
|
96f2dbafdf | ||
|
|
45c8214c2b | ||
|
|
4841a9985c | ||
|
|
49a765d0a5 | ||
|
|
67423ff9c2 | ||
|
|
5a4d4dabba | ||
|
|
05d6b6cb5d | ||
|
|
432005eaa0 | ||
|
|
3d3bc88422 | ||
|
|
d00637b05e | ||
|
|
be8d244d8c | ||
|
|
1e031e8362 | ||
|
|
c0871cfe0d | ||
|
|
18e74399fa | ||
|
|
21b4c3ab87 | ||
|
|
3170c44a4f | ||
|
|
24acbc3d56 | ||
|
|
faa347c20f | ||
|
|
31ebf2634d | ||
|
|
610c958b2d | ||
|
|
5c3572bed1 | ||
|
|
96f08a51d7 | ||
|
|
70c9b6d9c8 | ||
|
|
9648a850ad | ||
|
|
e0004a2f52 | ||
|
|
a1a5ed068b |
@@ -8,22 +8,22 @@ source "https://rubygems.org"
|
|||||||
#
|
#
|
||||||
# This will help ensure the proper Jekyll version is running.
|
# This will help ensure the proper Jekyll version is running.
|
||||||
# Happy Jekylling!
|
# Happy Jekylling!
|
||||||
# gem "jekyll", "~> 3.9.0"
|
gem "jekyll", "~> 4.2.0"
|
||||||
|
|
||||||
# This is the default theme for new Jekyll sites. You may change this to anything you like.
|
# This is the default theme for new Jekyll sites. You may change this to anything you like.
|
||||||
gem "just-the-docs", "~> 0.3.3"
|
gem "just-the-docs", "~> 0.3.3"
|
||||||
|
gem "jekyll-remote-theme", "~> 0.4"
|
||||||
|
gem "jekyll-redirect-from", "~> 0.16"
|
||||||
|
|
||||||
# If you want to use GitHub Pages, remove the "gem "jekyll"" above and
|
# If you want to use GitHub Pages, remove the "gem "jekyll"" above and
|
||||||
# uncomment the line below. To upgrade, run `bundle update github-pages`.
|
# uncomment the line below. To upgrade, run `bundle update github-pages`.
|
||||||
|
|
||||||
gem 'github-pages', group: :jekyll_plugins
|
# gem 'github-pages', group: :jekyll_plugins
|
||||||
|
|
||||||
# If you have any plugins, put them here!
|
# If you have any plugins, put them here!
|
||||||
# group :jekyll_plugins do
|
group :jekyll_plugins do
|
||||||
# # gem "jekyll-feed", "~> 0.6"
|
gem "jekyll-sitemap"
|
||||||
# gem "jekyll-remote-theme"
|
end
|
||||||
# gem "jekyll-redirect-from"
|
|
||||||
# end
|
|
||||||
|
|
||||||
# Windows does not include zoneinfo files, so bundle the tzinfo-data gem
|
# Windows does not include zoneinfo files, so bundle the tzinfo-data gem
|
||||||
gem "tzinfo-data", platforms: [:mingw, :mswin, :x64_mingw, :jruby]
|
gem "tzinfo-data", platforms: [:mingw, :mswin, :x64_mingw, :jruby]
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
Copyright 2021 OpenSearch contributors.
|
Copyright OpenSearch contributors.
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
|
<img src="https://opensearch.org/assets/img/opensearch-logo-themed.svg" height="64px">
|
||||||
|
|
||||||
# OpenSearch documentation
|
# OpenSearch documentation
|
||||||
|
|
||||||
This repository contains the documentation for OpenSearch, the search, analytics, and visualization suite with advanced security, alerting, SQL support, automated index management, deep performance analysis, and more. You can find the rendered documentation at [docs-beta.opensearch.org](https://docs-beta.opensearch.org).
|
This repository contains the documentation for OpenSearch, the search, analytics, and visualization suite with advanced security, alerting, SQL support, automated index management, deep performance analysis, and more. You can find the rendered documentation at [opensearch.org/docs](https://opensearch.org/docs).
|
||||||
|
|
||||||
Community contributions remain essential in keeping this documentation comprehensive, useful, well-organized, and up-to-date.
|
Community contributions remain essential in keeping this documentation comprehensive, useful, well-organized, and up-to-date.
|
||||||
|
|
||||||
@@ -11,9 +13,9 @@ Community contributions remain essential in keeping this documentation comprehen
|
|||||||
|
|
||||||
Often, engineering teams can keep existing documentation up-to-date with minimal effort, thus freeing up the documentation team to focus on larger projects.
|
Often, engineering teams can keep existing documentation up-to-date with minimal effort, thus freeing up the documentation team to focus on larger projects.
|
||||||
|
|
||||||
- Do you have expertise in a particular area of OpenSearch? Cluster sizing? The query DSL? Painless scripting? Aggregations? JVM settings? Take a look at the [current content](https://docs-beta.opensearch.org/docs/opensearch/) and see where you can add value. The [documentation team](#points-of-contact) is happy to help you polish and organize your drafts.
|
- Do you have expertise in a particular area of OpenSearch? Cluster sizing? The query DSL? Painless scripting? Aggregations? JVM settings? Take a look at the [current content](https://opensearch.org/docs/opensearch/) and see where you can add value. The [documentation team](#points-of-contact) is happy to help you polish and organize your drafts.
|
||||||
|
|
||||||
- Are you an OpenSearch Dashboards expert? How did you set up your visualizations? Why is a particular dashboard so valuable to your organization? We have [very little](https://docs-beta.opensearch.org/docs/opensearch-dashboards/) on how to use OpenSearch Dashboards, only how to install it.
|
- Are you an OpenSearch Dashboards expert? How did you set up your visualizations? Why is a particular dashboard so valuable to your organization? We have [very little](https://opensearch.org/docs/opensearch-dashboards/) on how to use OpenSearch Dashboards, only how to install it.
|
||||||
|
|
||||||
- Are you a web developer? Do you want to add an optional dark mode to the documentation? A "copy to clipboard" button for our code samples? Other improvements to the design or usability? See [major changes](#major-changes) for information on building the website locally.
|
- Are you a web developer? Do you want to add an optional dark mode to the documentation? A "copy to clipboard" button for our code samples? Other improvements to the design or usability? See [major changes](#major-changes) for information on building the website locally.
|
||||||
|
|
||||||
@@ -30,11 +32,9 @@ If you encounter problems or have questions when contributing to the documentati
|
|||||||
- [snyder114](https://github.com/snyder114)
|
- [snyder114](https://github.com/snyder114)
|
||||||
|
|
||||||
|
|
||||||
## How we build the website
|
## How the website works
|
||||||
|
|
||||||
After each commit to this repository, GitHub Pages automatically uses [Jekyll](https://jekyllrb.com) to rebuild the [website](https://docs-beta.opensearch.org). The whole process takes around 30 seconds.
|
This repository contains many [Markdown](https://guides.github.com/features/mastering-markdown/) files organized into Jekyll "collections" (e.g. `_search-plugins`, `_opensearch`, etc.). Each Markdown file correlates with one page on the website.
|
||||||
|
|
||||||
This repository contains many [Markdown](https://guides.github.com/features/mastering-markdown/) files in the `/docs` directory. Each Markdown file correlates with one page on the website.
|
|
||||||
|
|
||||||
Using plain text on GitHub has many advantages:
|
Using plain text on GitHub has many advantages:
|
||||||
|
|
||||||
@@ -133,15 +133,15 @@ If you're making major changes to the documentation and need to see the rendered
|
|||||||
sh build.sh
|
sh build.sh
|
||||||
```
|
```
|
||||||
|
|
||||||
1. If the build script doesn't automatically open your web browser (it should), open [http://localhost:4000/](http://localhost:4000/).
|
1. If the build script doesn't automatically open your web browser (it should), open [http://localhost:4000/docs/](http://localhost:4000/docs/).
|
||||||
|
|
||||||
1. Create a new branch.
|
1. Create a new branch.
|
||||||
|
|
||||||
1. Edit the Markdown files in `/docs`.
|
1. Edit the Markdown files in each collection (e.g. `_security-plugin/`).
|
||||||
|
|
||||||
If you're a web developer, you can customize `_layouts/default.html` and `_sass/custom/custom.scss`.
|
If you're a web developer, you can customize `_layouts/default.html` and `_sass/custom/custom.scss`.
|
||||||
|
|
||||||
1. When you save a file, marvel as Jekyll automatically rebuilds the site and refreshes your web browser. This process takes roughly 30 seconds.
|
1. When you save a file, marvel as Jekyll automatically rebuilds the site and refreshes your web browser. This process can take anywhere from 10-30 seconds.
|
||||||
|
|
||||||
1. When you're happy with how everything looks, commit, push your changes to your fork, and submit a pull request.
|
1. When you're happy with how everything looks, commit, push your changes to your fork, and submit a pull request.
|
||||||
|
|
||||||
@@ -196,7 +196,7 @@ If you're making major changes to the documentation and need to see the rendered
|
|||||||
## New releases
|
## New releases
|
||||||
|
|
||||||
1. Branch.
|
1. Branch.
|
||||||
1. Change the `opensearch_version` and `opensearch_major_version` variables in `_config.yml`.
|
1. Change the `opensearch_version` and `opensearch_major_minor_version` variables in `_config.yml`.
|
||||||
1. Start up a new cluster using the updated Docker Compose file in `docs/install/docker.md`.
|
1. Start up a new cluster using the updated Docker Compose file in `docs/install/docker.md`.
|
||||||
1. Update the version table in `version-history.md`.
|
1. Update the version table in `version-history.md`.
|
||||||
|
|
||||||
@@ -225,7 +225,7 @@ This documentation uses a modified version of the [just-the-docs](https://github
|
|||||||
|
|
||||||
## Get started
|
## Get started
|
||||||
New
|
New
|
||||||
{: .label .label-green :}
|
{: .label .label-green }
|
||||||
```
|
```
|
||||||
|
|
||||||
* Labels come in default (blue), green, purple, yellow, and red.
|
* Labels come in default (blue), green, purple, yellow, and red.
|
||||||
@@ -238,6 +238,27 @@ These classes can help with readability, but should be used *sparingly*. Each ad
|
|||||||
Besides, standard Markdown elements suffice for most documentation.
|
Besides, standard Markdown elements suffice for most documentation.
|
||||||
|
|
||||||
|
|
||||||
|
## Labels for APIs
|
||||||
|
|
||||||
|
Each API operation has a label indicating when it was introduced. For most operations, this label is 1.0:
|
||||||
|
|
||||||
|
```
|
||||||
|
## Get roles
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
```
|
||||||
|
|
||||||
|
If we introduce a breaking change to an operation, add an additional label with a link to the release note for that breaking change:
|
||||||
|
|
||||||
|
```
|
||||||
|
## Get roles
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
[Last breaking change 2.0](https://example.com)
|
||||||
|
{: .label .label-red }
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
## Math
|
## Math
|
||||||
|
|
||||||
If you want to use the sorts of pretty formulas that [MathJax](https://www.mathjax.org) allows, add `has_math: true` to the Jekyll page metadata. Then insert LaTeX math into HTML tags with the rest of your Markdown content:
|
If you want to use the sorts of pretty formulas that [MathJax](https://www.mathjax.org) allows, add `has_math: true` to the Jekyll page metadata. Then insert LaTeX math into HTML tags with the rest of your Markdown content:
|
||||||
@@ -273,4 +294,4 @@ This project is licensed under the Apache-2.0 License.
|
|||||||
|
|
||||||
## Copyright
|
## Copyright
|
||||||
|
|
||||||
Copyright 2021 OpenSearch contributors.
|
Copyright OpenSearch contributors.
|
||||||
|
|||||||
@@ -4,22 +4,42 @@ title: Agents and ingestion tools
|
|||||||
nav_order: 100
|
nav_order: 100
|
||||||
has_children: false
|
has_children: false
|
||||||
has_toc: false
|
has_toc: false
|
||||||
|
redirect_from:
|
||||||
|
- /clients/agents-and-ingestion-tools/
|
||||||
---
|
---
|
||||||
|
|
||||||
# Agents and ingestion tools
|
# Agents and ingestion tools
|
||||||
|
|
||||||
Historically, many multiple popular agents and ingestion tools have worked with Elasticsearch OSS, such as Beats, Logstash, Fluentd, FluentBit, and OpenTelemetry. OpenSearch aims to continue to support a broad set of agents and ingestion tools, but not all have been tested or have explicitly added OpenSearch compatibility.
|
Historically, many multiple popular agents and ingestion tools have worked with Elasticsearch OSS, such as Beats, Logstash, Fluentd, FluentBit, and OpenTelemetry. OpenSearch aims to continue to support a broad set of agents and ingestion tools, but not all have been tested or have explicitly added OpenSearch compatibility.
|
||||||
|
|
||||||
As an intermediate solution, we are adding a [version value](https://github.com/opensearch-project/OpenSearch/issues/693) to `opensearch.yml`. This change will let you set OpenSearch 1.x clusters to report version 7.10.2 (or any other arbitrary value). By reporting 7.10.2, the cluster will be able to connect with tools that check for a particular version number.
|
As an intermediate compatibility solution, OpenSearch has a setting that instructs the cluster to return version 7.10.2 rather than its actual version.
|
||||||
|
|
||||||
For a longer term solution, we plan to create an OpenSearch output plugin for Logstash. This plugin *does not exist yet*, but we've included it in the compatibility matrices below based on its expected behavior.
|
If you use clients that include a version check, such as recent versions of Logstash OSS or Filebeat OSS, enable the setting:
|
||||||
|
|
||||||
|
```json
|
||||||
|
PUT _cluster/settings
|
||||||
|
{
|
||||||
|
"persistent": {
|
||||||
|
"compatibility": {
|
||||||
|
"override_main_response_version": true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
[Just like any other setting]({{site.url}}{{site.baseurl}}/opensearch/configuration/), the alternative is to add the following line to `opensearch.yml` on each node and then restart the node:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
compatibility.override_main_response_version: true
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
## Downloads
|
## Downloads
|
||||||
|
|
||||||
These versions of Logstash and Beats offer the best compatibility with OpenSearch. For more information, see the [compatibility matrices](#compatibility-matrices).
|
You can download the OpenSearch output plugin for Logstash from [OpenSearch downloads](https://opensearch.org/downloads.html). The Logstash output plugin is compatible with OpenSearch and Elasticsearch OSS (7.10.2 or lower).
|
||||||
|
|
||||||
|
These are the latest versions of Beats OSS with OpenSearch compatibility. For more information, see the [compatibility matrices](#compatibility-matrices).
|
||||||
|
|
||||||
- [Logstash OSS 7.12.1](https://www.elastic.co/downloads/past-releases/logstash-oss-7-12-1)
|
|
||||||
- [Filebeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/filebeat-oss-7-12-1)
|
- [Filebeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/filebeat-oss-7-12-1)
|
||||||
- [Metricbeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/metricbeat-oss-7-12-1)
|
- [Metricbeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/metricbeat-oss-7-12-1)
|
||||||
- [Packetbeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/packetbeat-oss-7-12-1)
|
- [Packetbeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/packetbeat-oss-7-12-1)
|
||||||
@@ -27,6 +47,9 @@ These versions of Logstash and Beats offer the best compatibility with OpenSearc
|
|||||||
- [Winlogbeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/winlogbeat-oss-7-12-1)
|
- [Winlogbeat OSS 7.12.1](https://www.elastic.co/downloads/past-releases/winlogbeat-oss-7-12-1)
|
||||||
- [Auditbeat OSS 7.12.1](https://elastic.co/downloads/past-releases/auditbeat-oss-7-12-1)
|
- [Auditbeat OSS 7.12.1](https://elastic.co/downloads/past-releases/auditbeat-oss-7-12-1)
|
||||||
|
|
||||||
|
Some users report compatibility issues with ingest pipelines on these versions of Beats. If you use ingest pipelines with OpenSearch, consider using the 7.10.2 versions of Beats instead.
|
||||||
|
{: .note }
|
||||||
|
|
||||||
|
|
||||||
## Compatibility Matrices
|
## Compatibility Matrices
|
||||||
|
|
||||||
@@ -35,28 +58,26 @@ These versions of Logstash and Beats offer the best compatibility with OpenSearc
|
|||||||
|
|
||||||
### Compatibility Matrix for Logstash
|
### Compatibility Matrix for Logstash
|
||||||
|
|
||||||
| | Logstash OSS 7.x to 7.11.x | Logstash OSS 7.12.x\* | Logstash 7.13.x without OpenSearch output plugin | Logstash 7.13.x with OpenSearch output plugin\*\* |
|
| | Logstash OSS 7.x to 7.11.x | Logstash OSS 7.12.x\* | Logstash 7.13.x without OpenSearch output plugin | Logstash 7.13.x with OpenSearch output plugin |
|
||||||
| :---| :--- | :--- | :--- | :--- |
|
| :---| :--- | :--- | :--- | :--- |
|
||||||
| Elasticsearch OSS v7.x to v7.9.x | *Yes* | *Yes* | *No* | *Yes* |
|
| Elasticsearch OSS 7.x to 7.9.x | *Yes* | *Yes* | *No* | *Yes* |
|
||||||
| Elasticsearch OSS v7.10.2 | *Yes* | *Yes* | *No* | *Yes* |
|
| Elasticsearch OSS 7.10.2 | *Yes* | *Yes* | *No* | *Yes* |
|
||||||
| ODFE OSS v1.x to 1.12 | *Yes* | *Yes* | *No* | *Yes* |
|
| ODFE 1.x to 1.12 | *Yes* | *Yes* | *No* | *Yes* |
|
||||||
| ODFE 1.13 | *Yes* | *Yes* | *No* | *Yes* |
|
| ODFE 1.13 | *Yes* | *Yes* | *No* | *Yes* |
|
||||||
| OpenSearch 1.0 | [Yes via version setting](https://github.com/opensearch-project/OpenSearch/issues/693) | [Yes via version setting](https://github.com/opensearch-project/OpenSearch/issues/693) | *No* | *Yes* |
|
| OpenSearch 1.0 | Yes via version setting | Yes via version setting | *No* | *Yes* |
|
||||||
|
|
||||||
\* Most current compatible version with Elasticsearch OSS.
|
\* Most current compatible version with Elasticsearch OSS.
|
||||||
|
|
||||||
\*\* Planning to build.
|
|
||||||
|
|
||||||
|
|
||||||
### Compatibility Matrix for Beats
|
### Compatibility Matrix for Beats
|
||||||
|
|
||||||
| | Beats OSS 7.x to 7.11.x\*\* | Beats OSS 7.12.x\* | Beats 7.13.x |
|
| | Beats OSS 7.x to 7.11.x\*\* | Beats OSS 7.12.x\* | Beats 7.13.x |
|
||||||
| :--- | :--- | :--- | :--- |
|
| :--- | :--- | :--- | :--- |
|
||||||
| Elasticsearch OSS v7.x to v7.9.x | *Yes* | *Yes* | No |
|
| Elasticsearch OSS 7.x to 7.9.x | *Yes* | *Yes* | No |
|
||||||
| Elasticsearch OSS v7.10.2 | *Yes* | *Yes* | No |
|
| Elasticsearch OSS 7.10.2 | *Yes* | *Yes* | No |
|
||||||
| ODFE OSS v1.x to 1.12 | *Yes* | *Yes* | No |
|
| ODFE 1.x to 1.12 | *Yes* | *Yes* | No |
|
||||||
| ODFE 1.13 | *Yes* | *Yes* | No |
|
| ODFE 1.13 | *Yes* | *Yes* | No |
|
||||||
| OpenSearch 1.0 | [Yes via version setting](https://github.com/opensearch-project/OpenSearch/issues/693) | [Yes via version setting](https://github.com/opensearch-project/OpenSearch/issues/693) | No |
|
| OpenSearch 1.0 | Yes via version setting | Yes via version setting | No |
|
||||||
| Logstash OSS 7.x to 7.11.x | *Yes* | *Yes* | *Yes* |
|
| Logstash OSS 7.x to 7.11.x | *Yes* | *Yes* | *Yes* |
|
||||||
| Logstash OSS 7.12.x\* | *Yes* | *Yes* | *Yes* |
|
| Logstash OSS 7.12.x\* | *Yes* | *Yes* | *Yes* |
|
||||||
| Logstash 7.13.x with OpenSearch output plugin | *Yes* | *Yes* | *Yes* |
|
| Logstash 7.13.x with OpenSearch output plugin | *Yes* | *Yes* | *Yes* |
|
||||||
|
|||||||
@@ -3,9 +3,6 @@ layout: default
|
|||||||
title: OpenSearch CLI
|
title: OpenSearch CLI
|
||||||
nav_order: 52
|
nav_order: 52
|
||||||
has_children: false
|
has_children: false
|
||||||
redirect_from:
|
|
||||||
- /docs/odfe-cli/
|
|
||||||
- /docs/cli/
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# OpenSearch CLI
|
# OpenSearch CLI
|
||||||
|
|||||||
@@ -0,0 +1,82 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Compatibility
|
||||||
|
nav_order: 1
|
||||||
|
has_children: false
|
||||||
|
redirect_from:
|
||||||
|
- /clients/
|
||||||
|
---
|
||||||
|
|
||||||
|
# OpenSearch client compatibility
|
||||||
|
|
||||||
|
Most clients that work with Elasticsearch OSS 7.10.2 *should* work with OpenSearch, but the latest versions of those clients might include license or version checks that artificially break compatibility. This page includes recommendations around which versions of those clients to use for best compatibility with OpenSearch.
|
||||||
|
|
||||||
|
Client | Recommended version
|
||||||
|
:--- | :---
|
||||||
|
[Java low-level REST client](https://search.maven.org/artifact/org.elasticsearch.client/elasticsearch-rest-client/7.13.4/jar) | 7.13.4
|
||||||
|
[Java high-level REST client](https://search.maven.org/artifact/org.elasticsearch.client/elasticsearch-rest-high-level-client/7.13.4/jar) | 7.13.4
|
||||||
|
[Python Elasticsearch client](https://pypi.org/project/elasticsearch/7.13.4/) | 7.13.4
|
||||||
|
[Elasticsearch Node.js client](https://www.npmjs.com/package/@elastic/elasticsearch/v/7.13.0) | 7.13.0
|
||||||
|
|
||||||
|
Clients exist for a wide variety of languages, so if you test a client and verify that it works, please [submit a PR](https://github.com/opensearch-project/documentation-website/pulls) and add it to this table.
|
||||||
|
|
||||||
|
|
||||||
|
{% comment %}
|
||||||
|
## Python 3 test code
|
||||||
|
|
||||||
|
This code indexes a single document and is equivalent to `PUT /python-test-index1/_doc/1`.
|
||||||
|
|
||||||
|
```python
|
||||||
|
from elasticsearch import Elasticsearch
|
||||||
|
|
||||||
|
host = 'localhost'
|
||||||
|
port = 9200
|
||||||
|
# For testing only. Do not store credentials in code.
|
||||||
|
auth = ('admin', 'admin')
|
||||||
|
|
||||||
|
es = Elasticsearch(
|
||||||
|
hosts = [{'host': host, 'port': port}],
|
||||||
|
http_auth = auth,
|
||||||
|
use_ssl = True,
|
||||||
|
verify_certs = False
|
||||||
|
)
|
||||||
|
|
||||||
|
document = {
|
||||||
|
"title": "Moneyball",
|
||||||
|
"director": "Bennett Miller",
|
||||||
|
"year": "2011"
|
||||||
|
}
|
||||||
|
|
||||||
|
response = es.index(index='python-test-index1', id='1', body=document, refresh=True)
|
||||||
|
|
||||||
|
print(response)
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
## Node.js test code
|
||||||
|
|
||||||
|
This code is equivalent to `GET /`.
|
||||||
|
|
||||||
|
```js
|
||||||
|
const { Client } = require('@elastic/elasticsearch')
|
||||||
|
const client = new Client({
|
||||||
|
node: 'https://localhost:9200',
|
||||||
|
auth: {
|
||||||
|
// For testing only. Don't store credentials in code.
|
||||||
|
username: 'admin',
|
||||||
|
password: 'admin'
|
||||||
|
},
|
||||||
|
ssl: {
|
||||||
|
// ca: fs.readFileSync('./cacert.pem'),
|
||||||
|
rejectUnauthorized: false
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
async function run () {
|
||||||
|
const { body } = await client.info();
|
||||||
|
console.log(body);
|
||||||
|
}
|
||||||
|
|
||||||
|
run().catch(console.log)
|
||||||
|
```
|
||||||
|
{% endcomment %}
|
||||||
@@ -0,0 +1,124 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Java high-level REST client
|
||||||
|
nav_order: 97
|
||||||
|
---
|
||||||
|
|
||||||
|
# Java high-level REST client
|
||||||
|
|
||||||
|
The Elasticsearch OSS Java high-level REST client allows you to interact with your OpenSearch clusters and indices through Java methods and data structures rather than HTTP methods and JSON.
|
||||||
|
|
||||||
|
You submit requests to your cluster using request objects, which allows you to create indices, add data to documents, or complete other operations with your cluster. In return, you get back response objects that have all of the available information, such as the associated index or ID, from your cluster.
|
||||||
|
|
||||||
|
## Setup
|
||||||
|
|
||||||
|
To start using the Elasticsearch OSS Java high-level REST client, ensure that you have the following dependency in your project's `pom.xml` file:
|
||||||
|
|
||||||
|
```
|
||||||
|
<dependency>
|
||||||
|
<groupId>org.elasticsearch.client</groupId>
|
||||||
|
<artifactId>elasticsearch-rest-high-level-client</artifactId>
|
||||||
|
<version>7.10.2</version>
|
||||||
|
</dependency>
|
||||||
|
```
|
||||||
|
|
||||||
|
You can now start your OpenSearch cluster. The 7.10.2 high-level REST client works with the 1.x versions of OpenSearch.
|
||||||
|
|
||||||
|
## Sample code
|
||||||
|
|
||||||
|
```java
|
||||||
|
import org.apache.http.HttpHost;
|
||||||
|
import org.apache.http.auth.AuthScope;
|
||||||
|
import org.apache.http.auth.UsernamePasswordCredentials;
|
||||||
|
import org.apache.http.client.CredentialsProvider;
|
||||||
|
import org.apache.http.impl.client.BasicCredentialsProvider;
|
||||||
|
import org.apache.http.impl.nio.client.HttpAsyncClientBuilder;
|
||||||
|
import org.elasticsearch.action.admin.indices.delete.DeleteIndexRequest;
|
||||||
|
import org.elasticsearch.action.delete.DeleteRequest;
|
||||||
|
import org.elasticsearch.action.delete.DeleteResponse;
|
||||||
|
import org.elasticsearch.action.get.GetRequest;
|
||||||
|
import org.elasticsearch.action.get.GetResponse;
|
||||||
|
import org.elasticsearch.action.index.IndexRequest;
|
||||||
|
import org.elasticsearch.action.index.IndexResponse;
|
||||||
|
import org.elasticsearch.action.support.master.AcknowledgedResponse;
|
||||||
|
import org.elasticsearch.client.RequestOptions;
|
||||||
|
import org.elasticsearch.client.RestClient;
|
||||||
|
import org.elasticsearch.client.RestClientBuilder;
|
||||||
|
import org.elasticsearch.client.RestHighLevelClient;
|
||||||
|
import org.elasticsearch.client.indices.CreateIndexRequest;
|
||||||
|
import org.elasticsearch.client.indices.CreateIndexResponse;
|
||||||
|
import org.elasticsearch.common.settings.Settings;
|
||||||
|
import org.elasticsearch.common.xcontent.XContentType;
|
||||||
|
|
||||||
|
import java.io.IOException;
|
||||||
|
import java.util.HashMap;
|
||||||
|
|
||||||
|
public class RESTClientSample {
|
||||||
|
|
||||||
|
public static void main(String[] args) throws IOException {
|
||||||
|
|
||||||
|
//Point to keystore with appropriate certificates for security.
|
||||||
|
System.setProperty("javax.net.ssl.trustStore", "/full/path/to/keystore");
|
||||||
|
System.setProperty("javax.net.ssl.trustStorePassword", password-to-keystore);
|
||||||
|
|
||||||
|
//Establish credentials to use basic authentication.
|
||||||
|
//Only for demo purposes. Do not specify your credentials in code.
|
||||||
|
final CredentialsProvider credentialsProvider = new BasicCredentialsProvider();
|
||||||
|
|
||||||
|
credentialsProvider.setCredentials(AuthScope.ANY,
|
||||||
|
new UsernamePasswordCredentials("admin", "admin"));
|
||||||
|
|
||||||
|
//Create a client.
|
||||||
|
RestClientBuilder builder = RestClient.builder(new HttpHost("localhost", 9200, "https"))
|
||||||
|
.setHttpClientConfigCallback(new RestClientBuilder.HttpClientConfigCallback() {
|
||||||
|
@Override
|
||||||
|
public HttpAsyncClientBuilder customizeHttpClient(HttpAsyncClientBuilder httpClientBuilder) {
|
||||||
|
return httpClientBuilder.setDefaultCredentialsProvider(credentialsProvider);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
RestHighLevelClient client = new RestHighLevelClient(builder);
|
||||||
|
|
||||||
|
//Create a non-default index with custom settings and mappings.
|
||||||
|
CreateIndexRequest createIndexRequest = new CreateIndexRequest("custom-index");
|
||||||
|
|
||||||
|
createIndexRequest.settings(Settings.builder() //Specify in the settings how many shards you want in the index.
|
||||||
|
.put("index.number_of_shards", 4)
|
||||||
|
.put("index.number_of_replicas", 3)
|
||||||
|
);
|
||||||
|
//Create a set of maps for the index's mappings.
|
||||||
|
HashMap<String, String> typeMapping = new HashMap<String,String>();
|
||||||
|
typeMapping.put("type", "integer");
|
||||||
|
HashMap<String, Object> ageMapping = new HashMap<String, Object>();
|
||||||
|
ageMapping.put("age", typeMapping);
|
||||||
|
HashMap<String, Object> mapping = new HashMap<String, Object>();
|
||||||
|
mapping.put("properties", ageMapping);
|
||||||
|
createIndexRequest.mapping(mapping);
|
||||||
|
CreateIndexResponse createIndexResponse = client.indices().create(createIndexRequest, RequestOptions.DEFAULT
|
||||||
|
|
||||||
|
//Adding data to the index.
|
||||||
|
IndexRequest request = new IndexRequest("custom-index"); //Add a document to the custom-index we created.
|
||||||
|
request.id("1"); //Assign an ID to the document.
|
||||||
|
|
||||||
|
HashMap<String, String> stringMapping = new HashMap<String, String>();
|
||||||
|
stringMapping.put("message:", "Testing Java REST client");
|
||||||
|
request.source(stringMapping); //Place your content into the index's source.
|
||||||
|
IndexResponse indexResponse = client.index(request, RequestOptions.DEFAULT);
|
||||||
|
|
||||||
|
//Getting back the document
|
||||||
|
GetRequest getRequest = new GetRequest("custom-index", "1");
|
||||||
|
GetResponse response = client.get(getRequest, RequestOptions.DEFAULT);
|
||||||
|
|
||||||
|
System.out.println(response.getSourceAsString());
|
||||||
|
|
||||||
|
//Delete the document
|
||||||
|
DeleteRequest deleteDocumentRequest = new DeleteRequest("custom-index", "1"); //Index name followed by the ID.
|
||||||
|
DeleteResponse deleteResponse = client.delete(deleteDocumentRequest, RequestOptions.DEFAULT);
|
||||||
|
|
||||||
|
//Delete the index
|
||||||
|
DeleteIndexRequest deleteIndexRequest = new DeleteIndexRequest("custom-index"); //Index name.
|
||||||
|
AcknowledgedResponse deleteIndexResponse = client.indices().delete(deleteIndexRequest, RequestOptions.DEFAULT);
|
||||||
|
|
||||||
|
client.close();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
@@ -0,0 +1,246 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Advanced configurations
|
||||||
|
parent: Logstash
|
||||||
|
nav_order: 230
|
||||||
|
---
|
||||||
|
|
||||||
|
# Advanced configurations
|
||||||
|
|
||||||
|
This section describes how to set up advanced configuration options, like referencing field values and conditional statements, for Logstash.
|
||||||
|
|
||||||
|
## Referencing field values
|
||||||
|
|
||||||
|
To get access to a field, use the `- field` syntax.
|
||||||
|
You can also surround the field name by square brackets `- [field]` which makes it more explicit that you're referring to a field.
|
||||||
|
|
||||||
|
|
||||||
|
For example, if you have the following event:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
{
|
||||||
|
"request": "/products/view/123",
|
||||||
|
"verb": "GET",
|
||||||
|
"response": 200,
|
||||||
|
"headers": {
|
||||||
|
"request_path" => "/"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
To access the `request` field, use `- request` or `- [request]`.
|
||||||
|
|
||||||
|
If you want to reference nested fields, use the square brackets syntax and specify the path to the field. With each level being enclosed within square brackets: `- [headers][request_path]`.
|
||||||
|
|
||||||
|
You can reference fields using the `sprintf` format. This is also called string expansion. You need to add a % sign and then wrap the field reference within curly brackets.
|
||||||
|
|
||||||
|
You need to reference field values when using conditional statements.
|
||||||
|
|
||||||
|
For example, you can make the file name dynamic and contain the type of the processed events - either `access` or `error`. The `type` option is mainly used for conditionally applying filter plugins based on the type of events being processed.
|
||||||
|
|
||||||
|
Let's add a `type` option and specify a value of `access`.
|
||||||
|
|
||||||
|
|
||||||
|
```yml
|
||||||
|
input {
|
||||||
|
file {
|
||||||
|
path => ""
|
||||||
|
start_position => "beginning"
|
||||||
|
type => "access"
|
||||||
|
}
|
||||||
|
http {
|
||||||
|
type => "access"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
filter {
|
||||||
|
mutate {
|
||||||
|
remove_field => {"host"}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output {
|
||||||
|
stdout {
|
||||||
|
codec => rubydebug
|
||||||
|
}
|
||||||
|
file {
|
||||||
|
path => "%{[type]}.log"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Start Logstash and send an HTTP request. The processed event is output in the terminal. The event now includes a field named `type`.
|
||||||
|
|
||||||
|
You'll see the `access.log` file created within the Logstash directory.
|
||||||
|
|
||||||
|
## Conditional statements
|
||||||
|
|
||||||
|
You can use conditional statements to control the flow of code execution based on some conditions.
|
||||||
|
|
||||||
|
Syntax:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
if EXPR {
|
||||||
|
...
|
||||||
|
} else if EXPR {
|
||||||
|
...
|
||||||
|
} else {
|
||||||
|
...
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`EXPR` is any valid Logstash syntax that evaluates to a boolean value.
|
||||||
|
For example, you can check if an event type is set to `access` or `error` and perform some action based on that:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
if [type] == "access" {
|
||||||
|
...
|
||||||
|
} else if [type] == "error" {
|
||||||
|
file { .. }
|
||||||
|
} else {
|
||||||
|
...
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
You can compare a field value to some arbitrary value:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
if [headers][content_length] >= 1000 {
|
||||||
|
...
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
You can regex:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
if [some_field =~ /[0-9]+/ {
|
||||||
|
//some field only contains digits
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
You can use arrays:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
if [some_field] in ["one", "two", "three"] {
|
||||||
|
some field is either "one", "two", or "three"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
You can use boolean operators:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
if [type] == "access" or [type] == "error" {
|
||||||
|
...
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
## Formatting dates
|
||||||
|
|
||||||
|
You can use the `sprintf` format or string expansion to format dates.
|
||||||
|
For example, you might want the current date to be part of the filename.
|
||||||
|
|
||||||
|
To format the date, add a plus sign in curly brackets followed by the date format - `%{+yyyy-MM-dd}`.
|
||||||
|
|
||||||
|
```yml
|
||||||
|
file {
|
||||||
|
path => "%{[type]}_%{+yyyy_MM_dd}.log"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
This is the date stored within the @timestamp fields, which is the time and date of the event.
|
||||||
|
Send a request to the pipeline and verify that a filename is outputted that contains the events date.
|
||||||
|
|
||||||
|
You can embed the date in other outputs as well, for example into the index name in OpenSearch.
|
||||||
|
|
||||||
|
## Sending time information
|
||||||
|
|
||||||
|
You can set the time of events.
|
||||||
|
|
||||||
|
Logstash already sets the time when the event is received by the input plugin within the @timestamp field.
|
||||||
|
In some scenarios, you might need to use a different timestamp.
|
||||||
|
For example, if you have an eCommerce store and you process the orders daily at midnight. When Logstash receives the events at midnight, it sets the timestamp to the current time.
|
||||||
|
But you want it to be the time when the order is placed and not when Logstash received the event.
|
||||||
|
|
||||||
|
Let's change the event timestamp to the date the request is received by the web server. You can do this using a filter plugin named `dates`.
|
||||||
|
The `dates` filter passes a `date` or `datetime` value from a field and uses the results as the event timestamp.
|
||||||
|
|
||||||
|
Add the `date` plugin at the bottom of the `filter` block:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
date {
|
||||||
|
match => [ "timestamp", "dd/MMM/yyyy:HH:mm:ss Z" ]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
timestamp is the field that the `grok` pattern creates.
|
||||||
|
`Z` is the timezone. i.e., UTC offsets.
|
||||||
|
|
||||||
|
Start Logstash and send an HTTP request.
|
||||||
|
|
||||||
|
You can see that the filename contains the date of the request instead of the present date.
|
||||||
|
|
||||||
|
If the passing of the date fails, the `filter` plugin adds a tag named `_datepassfailure` to the text field.
|
||||||
|
|
||||||
|
After you have set the @timestamp field to a new value, you don't really need the other `timestamp` field anymore. You can remove it with the `remove_field` option.
|
||||||
|
|
||||||
|
```yml
|
||||||
|
date {
|
||||||
|
match => [ "timestamp", "dd/MMM/yyyy:HH:mm:ss Z" ]
|
||||||
|
remove_field => [ "timestamp" ]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## Parsing user agents
|
||||||
|
|
||||||
|
The user agent is the last part of a log entry that consists of the name of the browser, the browser version, and the OS of the device.
|
||||||
|
|
||||||
|
Users might be using a wide range of browsers, devices, and OS's. Doing this manually is hard.
|
||||||
|
|
||||||
|
You can't use `grok` patterns because the `grok` pattern only matches the usage in the string as whole and doesn't figure out which browser the visitor used for instance.
|
||||||
|
|
||||||
|
Logstash ships with a file containing regular expressions for this purpose. This makes it really easy to extract user agent information, which you could send to OpenSearch and run aggregations on.
|
||||||
|
|
||||||
|
To do this, add a `source` option that contains the name of the field. In this case, that's the `agent` field.
|
||||||
|
By default the user agent plugin, adds a number of fields at the top-level of the event.
|
||||||
|
Since that can get pretty confusing, we can add an option named `target` with a value of `ua`, short for user agent. What this does is that it nests the fields within an object named `ua`, making things more organized.
|
||||||
|
|
||||||
|
```yml
|
||||||
|
useragent {
|
||||||
|
source => "agent"
|
||||||
|
target => "ua"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Start Logstah and send an HTTP request.
|
||||||
|
|
||||||
|
You can see a field named `ua` with a number of keys including the browser name and version, the OS, and the device.
|
||||||
|
|
||||||
|
You could OpenSearch Dashboards to create a pie chart that shows how many visitors are from mobile devices and how many are desktop users. Or, you could get statistics on which browser versions are popular.
|
||||||
|
|
||||||
|
## Enriching geographical data
|
||||||
|
|
||||||
|
You can take an IP address and perform geographical lookup to resolve the geographical location of the user using the `geoip` filter.
|
||||||
|
|
||||||
|
The `geoip` filter plugin ships with a database called `geolite 2`, which is provided by a company named MaxMind. `geolite 2` is a popular source of geographical data and it's available for free.
|
||||||
|
Add the `geoip` plugin at the bottom of the `else` block.
|
||||||
|
|
||||||
|
The value of the `source` option is the name of the field containing the IP address, in this case that's `clientip`. You can make this field available using the `grok` pattern.
|
||||||
|
|
||||||
|
```yml
|
||||||
|
geoip {
|
||||||
|
source => "clientip"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Start Logstash and send an HTTP request.
|
||||||
|
|
||||||
|
Within the terminal, you see a new field named `geoip` that contains information such as the timezone, country, continent, city, postal code, and the latitude / longitude pair.
|
||||||
|
|
||||||
|
If you only need the country name for instance, include an option named `fields` with an array of the field names that you want the `geoip` plugin to return.
|
||||||
|
|
||||||
|
Some of the fields are not always available such as city name and region because translating IP addresses into geographical locations is generally not that accurate. If the `geoip` plugin fails to look up the geographical location, it adds a tag named `geoip_lookup_failure`.
|
||||||
|
|
||||||
|
You can use the `geoip` plugin with the OpenSearch output because `location` object within the `geoip` object, is a standard format for representing geospatial data in JSON. This is the same format as OpenSearch uses for its `geo_point` data type.
|
||||||
|
|
||||||
|
You can use the powerful geospatial queries of OpenSearch for working with geographical data.
|
||||||
@@ -0,0 +1,157 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Common filter plugins
|
||||||
|
parent: Logstash
|
||||||
|
nav_order: 220
|
||||||
|
---
|
||||||
|
|
||||||
|
# Common filter plugins
|
||||||
|
|
||||||
|
This page contains a list of common filter plugins.
|
||||||
|
|
||||||
|
## mutate
|
||||||
|
|
||||||
|
You can use the `mutate` filter to change the data type of a field. For example, you can use the `mutate` filter if you're sending events to OpenSearch and you need to change the data type of a field to match any existing mappings.
|
||||||
|
|
||||||
|
To convert the `quantity` field from a `string` type to an `integer` type:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
input {
|
||||||
|
http {
|
||||||
|
host => "127.0.0.1"
|
||||||
|
port => 8080
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
filter {
|
||||||
|
mutate {
|
||||||
|
convert => {"quantity" => "integer"}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output {
|
||||||
|
file {
|
||||||
|
path => "output.txt"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Sample output
|
||||||
|
|
||||||
|
You can see that the type of the `quantity` field is changed from a `string` to an `integer`.
|
||||||
|
|
||||||
|
```yml
|
||||||
|
{
|
||||||
|
"quantity" => 3,
|
||||||
|
"host" => "127.0.0.1",
|
||||||
|
"@timestamp" => 2021-05-23T19:02:08.026Z,
|
||||||
|
"amount" => 10,
|
||||||
|
"@version" => "1",
|
||||||
|
"headers" => {
|
||||||
|
"request_path" => "/",
|
||||||
|
"connection" => "keep-alive",
|
||||||
|
"content_length" => "41",
|
||||||
|
"http_user_agent" => "PostmanRuntime/7.26.8",
|
||||||
|
"request_method" => "PUT",
|
||||||
|
"cache_control" => "no-cache",
|
||||||
|
"http_accept" => "*/*",
|
||||||
|
"content_type" => "application/json",
|
||||||
|
"http_version" => "HTTP/1.1",
|
||||||
|
"http_host" => "127.0.0.1:8080",
|
||||||
|
"accept_encoding" => "gzip, deflate, br",
|
||||||
|
"postman_token" => "ffd1cdcb-7a1d-4d63-90f8-0f2773069205"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Other data types you can convert to are `float`, `string`, and `boolean` values. If you pass in an array, the `mutate` filter converts all the elements in the array. If you pass a `string` like "world" to cast to an `integer` type, the result is 0 and Logstash continues processing events.
|
||||||
|
|
||||||
|
Logstash supports a few common options for all filter plugins:
|
||||||
|
|
||||||
|
Option | Description
|
||||||
|
:--- | :---
|
||||||
|
`add_field` | Adds one or more fields to the event.
|
||||||
|
`remove_field` | Removes one or more events from the field.
|
||||||
|
`add_tag` | Adds one or more tags to the event. You can use tags to perform conditional processing on events depending on which tags they contain.
|
||||||
|
`remove_tag` | Removes one or more tags from the event.
|
||||||
|
|
||||||
|
For example, you can remove the `host` field from the event:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
input {
|
||||||
|
http {
|
||||||
|
host => "127.0.0.1"
|
||||||
|
port => 8080
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
filter {
|
||||||
|
mutate {
|
||||||
|
remove_field => {"host"}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output {
|
||||||
|
file {
|
||||||
|
path => "output.txt"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## grok
|
||||||
|
|
||||||
|
With the `grok` filter, you can parse unstructured data and and structure it into fields. The `grok` filter uses text patterns to match text in your logs. You can think of text patterns as variables containing regular expressions.
|
||||||
|
|
||||||
|
The format of a text pattern is as follows:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
%{SYNTAX:SEMANTIC}
|
||||||
|
```
|
||||||
|
|
||||||
|
`SYNTAX` is the format a piece of text should be in for the pattern to match. You can enter any of `grok`'s predefined patterns. For example, you can use the email identifier to match an email address from a given piece of text.
|
||||||
|
|
||||||
|
`SEMANTIC` is an arbitrary name for the matched text. For example, if you're using the email identifier syntax, you can name it “email.”
|
||||||
|
|
||||||
|
The following request consists of the IP address of the visitor, name of the visitor, the timestamp of the request, the HTTP verb and URL, the HTTP status code, and the number of bytes:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
184.252.108.229 - joe [20/Sep/2017:13:22:22 +0200] GET /products/view/123 200 12798
|
||||||
|
```
|
||||||
|
|
||||||
|
To split this request into different fields:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
filter {
|
||||||
|
grok {
|
||||||
|
match => { "message" => " %{IP: ip_address} %{USER:identity}
|
||||||
|
%{USER:auth} \[%{HTTPDATE:reg_ts}\]
|
||||||
|
\"%{WORD:http_verb}
|
||||||
|
%{URIPATHPARAM: req_path}
|
||||||
|
\" %{INT:http_status:int}
|
||||||
|
%{INT:num_bytes:int}"}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
where:
|
||||||
|
|
||||||
|
- `IP`: matches the IP address field.
|
||||||
|
- `USER`: matches the user name.
|
||||||
|
- `WORD`: matches the HTTP verb.
|
||||||
|
- `URIPATHPARAM`: matches the URI path.
|
||||||
|
- `INT`: matches the HTTP status field.
|
||||||
|
- `INT`: matches the number of bytes.
|
||||||
|
|
||||||
|
This is what the event looks like after the `grok` filter breaks it down into individual fields:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
ip_address: 184.252.108.229
|
||||||
|
identity: joe
|
||||||
|
reg_ts: 20/Sep/2017:13:22:22 +0200
|
||||||
|
http_verb:GET
|
||||||
|
req_path: /products/view/123
|
||||||
|
http_status: 200
|
||||||
|
num_bytes: 12798
|
||||||
|
```
|
||||||
|
|
||||||
|
For common log formats, you use the predefined patterns defined here---[Logstash patterns](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/ecs-v1). You can make any adjustments to the results with the `mutate` filter.
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Logstash execution model
|
||||||
|
parent: Logstash
|
||||||
|
nav_order: 210
|
||||||
|
---
|
||||||
|
|
||||||
|
# Logstash execution model
|
||||||
|
|
||||||
|
Here's a brief introduction to how Logstash processes events internally.
|
||||||
|
|
||||||
|
## Handling events concurrently
|
||||||
|
|
||||||
|
You can configure Logstash to have a number of inputs listening for events. Each input runs in its own thread to avoid inputs blocking each other. If you have two incoming events at the same time, Logstash handles both events concurrently.
|
||||||
|
|
||||||
|
After receiving an event and possibly applying an input codec, Logstash sends the event to a work queue. Pipeline workers or batchers perform the rest of the work involving filters and outputs along with any codec used at the output. Each pipeline worker also runs within its own thread meaning that Logstash processes multiple events simultaneously.
|
||||||
|
|
||||||
|
## Processing events in batches
|
||||||
|
|
||||||
|
A pipeline worker consumes events from the work queue in batches to optimize the throughput of the pipeline as a whole.
|
||||||
|
|
||||||
|
One reason why Logstash works in batches is that some code needs to be executed regardless of how many events are processed at a time within the pipeline worker. Instead of executing that code 100 times for 100 events, it’s more efficient to execute it once for a batch of 100 events.
|
||||||
|
|
||||||
|
Another reason is that a few output plugins group together events as batches. For example, if you send 100 requests to OpenSearch, the OpenSearch output plugin uses the bulk API to send a single request that groups together the 100 requests.
|
||||||
|
|
||||||
|
Logstash determines the batch size by two configuration options---a number representing the maximum batch size and the batch delay. The batch delay is how long Logstash waits before processing the unprocessed batch of events.
|
||||||
|
If you set the maximum batch size to 50 and the batch delay to 100 ms, Logstash processes a batch if they're either 50 unprocessed events in the work queue or if one hundred milliseconds have elapsed.
|
||||||
|
|
||||||
|
The reason that a batch is processed, even if the maximum batch size isn’t reached, is to reduce the delay in processing and to continue to process events in a timely manner. This works well for pipelines that process a low volume of events.
|
||||||
|
|
||||||
|
Imagine that you’ve a pipeline that processes error logs from web servers and pushes them to OpenSearch. You’re using OpenSearch Dashboards to analyze the error logs. Because you’re possibly dealing with a fairly low number of events, it might take a long time to reach 50 events. Logstash processes the events before reaching this threshold because otherwise there would be a long delay before we see the errors appear in OpenSearch Dashboards.
|
||||||
|
|
||||||
|
The default batch size and batch delay work for most cases. You don’t need to change the default values unless you need to minutely optimize the performance.
|
||||||
|
|
||||||
|
## Optimizing based on CPU cores
|
||||||
|
|
||||||
|
The number of pipeline workers are proportional to the number of CPU cores on the nodes.
|
||||||
|
If you have 5 workers running on a server with 2 CPU cores, the 5 workers won't be able to process events concurrently. On the other hand, running 5 workers on a server running 10 CPU cores limits the throughput of a Logstash instance.
|
||||||
|
|
||||||
|
Instead of running a fixed number of workers, which results in poor performance in some cases, Logstash examines the number of CPU cores of the instance and selects the number of pipeline workers to optimize its performance for the platform on which its running. For instance, your local development machine might not have the same processing power as a production server. So you don't need to manually configure Logstash for different machines.
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,77 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Ship events to OpenSearch
|
||||||
|
parent: Logstash
|
||||||
|
nav_order: 220
|
||||||
|
---
|
||||||
|
|
||||||
|
# Ship events to OpenSearch
|
||||||
|
|
||||||
|
You can Ship Logstash events to an OpenSearch cluster and then visualize your events with OpenSearch Dashboards.
|
||||||
|
|
||||||
|
Make sure you have [Logstash]({{site.url}}{{site.baseurl}}/clients/logstash/index/#install-logstash), [OpenSearch]({{site.url}}{{site.baseurl}}/opensearch/install/index/), and [OpenSearch Dashboards]({{site.url}}{{site.baseurl}}/dashboards/install/index/).
|
||||||
|
{: .note }
|
||||||
|
|
||||||
|
## OpenSearch output plugin
|
||||||
|
|
||||||
|
To run the OpenSearch output plugin, add the following configuration in your `pipeline.conf` file:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
output {
|
||||||
|
opensearch {
|
||||||
|
hosts => "https://localhost:9200"
|
||||||
|
user => "admin"
|
||||||
|
password => "admin"
|
||||||
|
index => "logstash-logs-%{+YYYY.MM.dd}"
|
||||||
|
ssl_certificate_verification => false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
## Sample walkthrough
|
||||||
|
|
||||||
|
1. Open the `config/pipeline.conf` file and add in the following configuration:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
input {
|
||||||
|
stdin {
|
||||||
|
codec => json
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output {
|
||||||
|
opensearch {
|
||||||
|
hosts => "https://localhost:9200"
|
||||||
|
user => "admin"
|
||||||
|
password => "admin"
|
||||||
|
index => "logstash-logs-%{+YYYY.MM.dd}"
|
||||||
|
ssl_certificate_verification => false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
This Logstash pipeline accepts JSON input through the terminal and ships the events to an OpenSearch cluster running locally. Logstash writes the events to an index with the `logstash-logs-%{+YYYY.MM.dd}` naming convention.
|
||||||
|
|
||||||
|
2. Start Logstash:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
$ bin/logstash -f config/pipeline.conf --config.reload.automatic
|
||||||
|
```
|
||||||
|
|
||||||
|
`config/pipeline.conf` is a relative path to the `pipeline.conf` file. You can use an absolute path as well.
|
||||||
|
|
||||||
|
3. Add a JSON object in the terminal:
|
||||||
|
|
||||||
|
```json
|
||||||
|
{ "amount": 10, "quantity": 2}
|
||||||
|
```
|
||||||
|
|
||||||
|
4. Start OpenSearch Dashboards and choose **Dev Tools**:
|
||||||
|
|
||||||
|
```json
|
||||||
|
GET _cat/indices?v
|
||||||
|
|
||||||
|
health | status | index | uuid | pri | rep | docs.count | docs.deleted | store.size | pri.store.size
|
||||||
|
green | open | logstash-logs-2021.07.01 | iuh648LYSnmQrkGf70pplA | 1 | 1 | 1 | 0 | 10.3kb | 5.1kb
|
||||||
|
```
|
||||||
+6
-5
@@ -1,12 +1,13 @@
|
|||||||
title: OpenSearch documentation
|
title: OpenSearch documentation
|
||||||
description: >- # this means to ignore newlines until "baseurl:"
|
description: >- # this means to ignore newlines until "baseurl:"
|
||||||
Documentation for OpenSearch, the Apache 2.0 search, analytics, and visualization suite with advanced security, alerting, SQL support, automated index management, deep performance analysis, and more.
|
Documentation for OpenSearch, the Apache 2.0 search, analytics, and visualization suite with advanced security, alerting, SQL support, automated index management, deep performance analysis, and more.
|
||||||
baseurl: "" # the subpath of your site, e.g. /blog
|
baseurl: "/docs" # the subpath of your site, e.g. /blog
|
||||||
url: "https://docs-beta.opensearch.org" # the base hostname & protocol for your site, e.g. http://example.com
|
url: "https://opensearch.org" # the base hostname & protocol for your site, e.g. http://example.com
|
||||||
permalink: /:path/
|
permalink: /:path/
|
||||||
|
|
||||||
opensearch_version: 1.0.0-rc1
|
opensearch_version: 1.0.1
|
||||||
opensearch_major_minor_version: 1.0
|
opensearch_major_minor_version: 1.0
|
||||||
|
lucene_version: 8_8_2
|
||||||
|
|
||||||
# Build settings
|
# Build settings
|
||||||
markdown: kramdown
|
markdown: kramdown
|
||||||
@@ -20,8 +21,7 @@ logo: "/assets/images/logo.svg"
|
|||||||
|
|
||||||
# Aux links for the upper right navigation
|
# Aux links for the upper right navigation
|
||||||
aux_links:
|
aux_links:
|
||||||
"Back to OpenSearch.org":
|
|
||||||
- "https://opensearch.org"
|
|
||||||
color_scheme: opensearch
|
color_scheme: opensearch
|
||||||
|
|
||||||
# Define Jekyll collections
|
# Define Jekyll collections
|
||||||
@@ -138,6 +138,7 @@ footer_content:
|
|||||||
plugins:
|
plugins:
|
||||||
- jekyll-remote-theme
|
- jekyll-remote-theme
|
||||||
- jekyll-redirect-from
|
- jekyll-redirect-from
|
||||||
|
- jekyll-sitemap
|
||||||
|
|
||||||
# Exclude from processing.
|
# Exclude from processing.
|
||||||
# The following items will not be processed, by default. Create a custom list
|
# The following items will not be processed, by default. Create a custom list
|
||||||
|
|||||||
@@ -6,10 +6,11 @@ has_children: false
|
|||||||
has_toc: false
|
has_toc: false
|
||||||
redirect_from:
|
redirect_from:
|
||||||
- /docs/opensearch-dashboards/
|
- /docs/opensearch-dashboards/
|
||||||
- /opensearch-dashboards/
|
|
||||||
- /dashboards/
|
- /dashboards/
|
||||||
---
|
---
|
||||||
|
|
||||||
|
{%- comment -%}The `/docs/opensearch-dashboards/` redirect is specifically to support the UI links in OpenSearch Dashboards 1.0.0.{%- endcomment -%}
|
||||||
|
|
||||||
# OpenSearch Dashboards
|
# OpenSearch Dashboards
|
||||||
|
|
||||||
OpenSearch Dashboards is the default visualization tool for data in OpenSearch. It also serves as a user interface for many of the OpenSearch plugins, including security, alerting, Index State Management, SQL, and more.
|
OpenSearch Dashboards is the default visualization tool for data in OpenSearch. It also serves as a user interface for many of the OpenSearch plugins, including security, alerting, Index State Management, SQL, and more.
|
||||||
|
|||||||
@@ -0,0 +1,135 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Helm
|
||||||
|
parent: Install OpenSearch Dashboards
|
||||||
|
nav_order: 35
|
||||||
|
---
|
||||||
|
|
||||||
|
# Run OpenSearch Dashboards using Helm
|
||||||
|
|
||||||
|
Helm is a package manager that allows you to easily install and manage OpenSearch Dashboards in a Kubernetes cluster. You can define your OpenSearch configurations in a YAML file and use Helm to deploy your applications in a version-controlled and reproducible way.
|
||||||
|
|
||||||
|
The Helm chart contains the resources described in the following table.
|
||||||
|
|
||||||
|
Resource | Description
|
||||||
|
:--- | :---
|
||||||
|
`Chart.yaml` | Information about the chart.
|
||||||
|
`values.yaml` | Default configuration values for the chart.
|
||||||
|
`templates` | Templates that combine with values to generate the Kubernetes manifest files.
|
||||||
|
|
||||||
|
The specification in the default Helm chart supports many standard use cases and setups. You can modify the default chart to configure your desired specifications and set Transport Layer Security (TLS) and role-based access control (RBAC).
|
||||||
|
|
||||||
|
For information about the default configuration, steps to configure security, and configurable parameters, see the
|
||||||
|
[README](https://github.com/opensearch-project/opensearch-devops/blob/main/Helm/README.md).
|
||||||
|
|
||||||
|
The instructions here assume you have a Kubernetes cluster with Helm preinstalled. See the [Kubernetes documentation](https://kubernetes.io/docs/setup/) for steps to configure a Kubernetes cluster and the [Helm documentation](https://helm.sh/docs/intro/install/) to install Helm.
|
||||||
|
{: .note }
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
Before you get started, you must first use [Helm to install OpenSearch]({{site.url}}{{site.baseurl}}/opensearch/install/helm/).
|
||||||
|
|
||||||
|
Make sure that you can send requests to your OpenSearch pod:
|
||||||
|
|
||||||
|
```json
|
||||||
|
$ curl -XGET https://localhost:9200 -u 'admin:admin' --insecure
|
||||||
|
{
|
||||||
|
"name" : "opensearch-cluster-master-1",
|
||||||
|
"cluster_name" : "opensearch-cluster",
|
||||||
|
"cluster_uuid" : "hP2gq5bPS3SLp8Z7wXm8YQ",
|
||||||
|
"version" : {
|
||||||
|
"distribution" : "opensearch",
|
||||||
|
"number" : "1.0.0",
|
||||||
|
"build_type" : "tar",
|
||||||
|
"build_hash" : "34550c5b17124ddc59458ef774f6b43a086522e3",
|
||||||
|
"build_date" : "2021-07-02T23:22:21.383695Z",
|
||||||
|
"build_snapshot" : false,
|
||||||
|
"lucene_version" : "8.8.2",
|
||||||
|
"minimum_wire_compatibility_version" : "6.8.0",
|
||||||
|
"minimum_index_compatibility_version" : "6.0.0-beta1"
|
||||||
|
},
|
||||||
|
"tagline" : "The OpenSearch Project: https://opensearch.org/"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## Install OpenSearch Dashboards using Helm
|
||||||
|
|
||||||
|
1. Change to the `opensearch-dashboards` directory:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd opensearch-dashboards
|
||||||
|
```
|
||||||
|
|
||||||
|
1. Package the Helm chart:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm package .
|
||||||
|
```
|
||||||
|
|
||||||
|
1. Deploy OpenSearch Dashboards:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm install --generate-name opensearch-dashboards-1.0.0.tgz
|
||||||
|
```
|
||||||
|
The output shows you the specifications instantiated from the install.
|
||||||
|
To customize the deployment, pass in the values that you want to override with a custom YAML file:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm install --values=customvalues.yaml opensearch-dashboards-1.0.0.tgz
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Sample output
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
NAME: opensearch-dashboards-1-1629223356
|
||||||
|
LAST DEPLOYED: Tue Aug 17 18:02:37 2021
|
||||||
|
NAMESPACE: default
|
||||||
|
STATUS: deployed
|
||||||
|
REVISION: 1
|
||||||
|
TEST SUITE: None
|
||||||
|
NOTES:
|
||||||
|
1. Get the application URL by running these commands:
|
||||||
|
export POD_NAME=$(kubectl get pods --namespace default -l "app.kubernetes.io/name=opensearch-dashboards,app.kubernetes.io/instance=op
|
||||||
|
ensearch-dashboards-1-1629223356" -o jsonpath="{.items[0].metadata.name}")
|
||||||
|
export CONTAINER_PORT=$(kubectl get pod --namespace default $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
||||||
|
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||||
|
kubectl --namespace default port-forward $POD_NAME 8080:$CONTAINER_PORT
|
||||||
|
```
|
||||||
|
|
||||||
|
To make sure your OpenSearch Dashboards pod is up and running, run the following command:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
$ kubectl get pods
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
opensearch-cluster-master-0 1/1 Running 0 4m35s
|
||||||
|
opensearch-cluster-master-1 1/1 Running 0 4m35s
|
||||||
|
opensearch-cluster-master-2 1/1 Running 0 4m35s
|
||||||
|
opensearch-dashboards-1-1629223356-758bd8747f-8www5 1/1 Running 0 66s
|
||||||
|
```
|
||||||
|
|
||||||
|
To set up port forwarding to access OpenSearch Dashboards, exit the OpenSearch shell and run the following command:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
$ kubectl port-forward deployment/opensearch-dashboards-1-1629223356 5601
|
||||||
|
```
|
||||||
|
|
||||||
|
You can now access OpenSearch Dashboards from your browser at: http://localhost:5601.
|
||||||
|
|
||||||
|
|
||||||
|
## Uninstall using Helm
|
||||||
|
|
||||||
|
To identify the OpenSearch Dashboards deployment that you want to delete:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
$ helm list
|
||||||
|
NAME NAMESPACE REVISION UPDATED STATUS CHART APP VERSION
|
||||||
|
opensearch-1-1629223146 default 1 2021-08-17 17:59:07.664498239 +0000 UTCdeployedopensearch-1.0.0 1.0.0
|
||||||
|
opensearch-dashboards-1-1629223356 default 1 2021-08-17 18:02:37.600796946 +0000 UTCdepl
|
||||||
|
oyedopensearch-dashboards-1.0.0 1.0.0
|
||||||
|
```
|
||||||
|
|
||||||
|
To delete or uninstall a deployment, run the following command:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm delete opensearch-dashboards-1-1629223356
|
||||||
|
```
|
||||||
@@ -9,4 +9,4 @@ redirect_from:
|
|||||||
|
|
||||||
# Install and configure OpenSearch Dashboards
|
# Install and configure OpenSearch Dashboards
|
||||||
|
|
||||||
OpenSearch Dashboards has two installation options at this time: Docker images and tarballs.
|
OpenSearch Dashboards has three installation options at this time: Docker images, tarballs, and Helm charts.
|
||||||
|
|||||||
@@ -29,32 +29,32 @@ If you don't want to use the all-in-one installation options, you can install th
|
|||||||
</thead>
|
</thead>
|
||||||
<tbody>
|
<tbody>
|
||||||
<tr>
|
<tr>
|
||||||
<td>1.0.0-rc1</td>
|
<td>1.0.1</td>
|
||||||
<td>
|
<td>
|
||||||
<pre>alertingDashboards 1.0.0.0-rc1
|
<pre>alertingDashboards 1.0.0.0
|
||||||
anomalyDetectionDashboards 1.0.0.0-rc1
|
anomalyDetectionDashboards 1.0.0.0
|
||||||
ganttChartDashboards 1.0.0.0-rc1
|
ganttChartDashboards 1.0.0.0
|
||||||
indexManagementDashboards 1.0.0.0-rc1
|
indexManagementDashboards 1.0.1.0
|
||||||
notebooksDashboards 1.0.0.0-rc1
|
notebooksDashboards 1.0.0.0
|
||||||
queryWorkbenchDashboards 1.0.0.0-rc1
|
queryWorkbenchDashboards 1.0.0.0
|
||||||
reportsDashboards 1.0.0.0-rc1
|
reportsDashboards 1.0.1.0
|
||||||
securityDashboards 1.0.0.0-rc1
|
securityDashboards 1.0.1.0
|
||||||
traceAnalyticsDashboards 1.0.0.0-rc1
|
traceAnalyticsDashboards 1.0.0.0
|
||||||
</pre>
|
</pre>
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
<tr>
|
<tr>
|
||||||
<td>1.0.0-beta1</td>
|
<td>1.0.0</td>
|
||||||
<td>
|
<td>
|
||||||
<pre>alertingDashboards 1.0.0.0-beta1
|
<pre>alertingDashboards 1.0.0.0
|
||||||
anomalyDetectionDashboards 1.0.0.0-beta1
|
anomalyDetectionDashboards 1.0.0.0
|
||||||
ganttChartDashboards 1.0.0.0-beta1
|
ganttChartDashboards 1.0.0.0
|
||||||
indexManagementDashboards 1.0.0.0-beta1
|
indexManagementDashboards 1.0.0.0
|
||||||
notebooksDashboards 1.0.0.0-beta1
|
notebooksDashboards 1.0.0.0
|
||||||
queryWorkbenchDashboards 1.0.0.0-beta1
|
queryWorkbenchDashboards 1.0.0.0
|
||||||
reportsDashboards 1.0.0.0-beta1
|
reportsDashboards 1.0.0.0
|
||||||
securityDashboards 1.0.0.0-beta1
|
securityDashboards 1.0.0.0
|
||||||
traceAnalyticsDashboards 1.0.0.0-beta1
|
traceAnalyticsDashboards 1.0.0.0
|
||||||
</pre>
|
</pre>
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
|||||||
@@ -27,4 +27,4 @@ nav_order: 30
|
|||||||
./bin/opensearch-dashboards
|
./bin/opensearch-dashboards
|
||||||
```
|
```
|
||||||
|
|
||||||
1. See the [OpenSearch Dashboards documentation]({{site.url}}{{site.baseurl}}/opensearch-dashboards/).
|
1. See the [OpenSearch Dashboards documentation]({{site.url}}{{site.baseurl}}/dashboards/index/).
|
||||||
|
|||||||
@@ -12,9 +12,9 @@ By default, for ease of testing and getting started, OpenSearch Dashboards runs
|
|||||||
Setting | Description
|
Setting | Description
|
||||||
:--- | :---
|
:--- | :---
|
||||||
opensearch.ssl.verificationMode | This setting is for communications between OpenSearch and OpenSearch Dashboards. Valid values are `full`, `certificate`, or `none`. We recommend `full` if you enable TLS, which enables hostname verification. `certificate` just checks the certificate, not the hostname, and `none` performs no checks (suitable for HTTP). Default is `full`.
|
opensearch.ssl.verificationMode | This setting is for communications between OpenSearch and OpenSearch Dashboards. Valid values are `full`, `certificate`, or `none`. We recommend `full` if you enable TLS, which enables hostname verification. `certificate` just checks the certificate, not the hostname, and `none` performs no checks (suitable for HTTP). Default is `full`.
|
||||||
opensearch.ssl.certificateAuthorities | If `opensearch.ssl.verificationMode` is `full` or `certificate`, specify the full path (e.g. `[ "/usr/share/opensearch-dashboards-1.0.0/config/root-ca.pem" ]` to the certificate authority for your OpenSearch cluster.
|
opensearch.ssl.certificateAuthorities | If `opensearch.ssl.verificationMode` is `full` or `certificate`, specify the full path to one or more CA certificates that comprise a trusted chain for your OpenSearch cluster. For example, you might need to include a root CA _and_ an intermediate CA if you used the intermediate CA to issue your admin, client, and node certificates.
|
||||||
server.ssl.enabled | This setting is for communications between OpenSearch Dashboards and the web browser. Set to true for HTTPS, false for HTTP.
|
server.ssl.enabled | This setting is for communications between OpenSearch Dashboards and the web browser. Set to true for HTTPS, false for HTTP.
|
||||||
server.ssl.certificate | If `server.ssl.enabled` is true, specify the full path (e.g. `/usr/share/opensearch-dashboards-1.0.0/config/my-client-cert.pem` to a valid client certificate for your OpenSearch cluster. You can [generate your own]({{site.url}}{{site.baseurl}}/security-plugin/configuration/generate-certificates/) or get one from a certificate authority.
|
server.ssl.certificate | If `server.ssl.enabled` is true, specify the full path to a valid client certificate for your OpenSearch cluster. You can [generate your own]({{site.url}}{{site.baseurl}}/security-plugin/configuration/generate-certificates/) or get one from a certificate authority.
|
||||||
server.ssl.key | If `server.ssl.enabled` is true, specify the full path (e.g. `/usr/share/opensearch-dashboards-1.0.0/config/my-client-cert-key.pem` to the key for your client certificate. You can [generate your own]({{site.url}}{{site.baseurl}}/security-plugin/configuration/generate-certificates/) or get one from a certificate authority.
|
server.ssl.key | If `server.ssl.enabled` is true, specify the full path (e.g. `/usr/share/opensearch-dashboards-1.0.0/config/my-client-cert-key.pem` to the key for your client certificate. You can [generate your own]({{site.url}}{{site.baseurl}}/security-plugin/configuration/generate-certificates/) or get one from a certificate authority.
|
||||||
opensearch_security.cookie.secure | If you enable TLS for OpenSearch Dashboards, change this setting to `true`. For HTTP, set it to `false`.
|
opensearch_security.cookie.secure | If you enable TLS for OpenSearch Dashboards, change this setting to `true`. For HTTP, set it to `false`.
|
||||||
|
|
||||||
@@ -27,9 +27,9 @@ opensearch.username: "kibanaserver"
|
|||||||
opensearch.password: "kibanaserver"
|
opensearch.password: "kibanaserver"
|
||||||
opensearch.requestHeadersWhitelist: [ authorization,securitytenant ]
|
opensearch.requestHeadersWhitelist: [ authorization,securitytenant ]
|
||||||
server.ssl.enabled: true
|
server.ssl.enabled: true
|
||||||
server.ssl.certificate: /usr/share/opensearch-1.0.0/config/client-cert.pem
|
server.ssl.certificate: /usr/share/opensearch-dashboards/config/client-cert.pem
|
||||||
server.ssl.key: /usr/share/opensearch-1.0.0/config/client-cert-key.pem
|
server.ssl.key: /usr/share/opensearch-dashboards/config/client-cert-key.pem
|
||||||
opensearch.ssl.certificateAuthorities: [ "/usr/share/opensearch-1.0.0/config/root-ca.pem" ]
|
opensearch.ssl.certificateAuthorities: [ "/usr/share/opensearch-dashboards/config/root-ca.pem", "/usr/share/opensearch-dashboards/config/intermediate-ca.pem" ]
|
||||||
opensearch_security.multitenancy.enabled: true
|
opensearch_security.multitenancy.enabled: true
|
||||||
opensearch_security.multitenancy.tenants.preferred: ["Private", "Global"]
|
opensearch_security.multitenancy.tenants.preferred: ["Private", "Global"]
|
||||||
opensearch_security.readonly_mode.roles: ["kibana_read_only"]
|
opensearch_security.readonly_mode.roles: ["kibana_read_only"]
|
||||||
|
|||||||
@@ -2,8 +2,12 @@
|
|||||||
layout: default
|
layout: default
|
||||||
title: WMS map server
|
title: WMS map server
|
||||||
nav_order: 5
|
nav_order: 5
|
||||||
|
redirect_from:
|
||||||
|
- /docs/opensearch-dashboards/maptiles/
|
||||||
---
|
---
|
||||||
|
|
||||||
|
{%- comment -%}The `/docs/opensearch-dashboards/maptiles/` redirect is specifically to support the UI links in OpenSearch Dashboards 1.0.0.{%- endcomment -%}
|
||||||
|
|
||||||
# Configure WMS map server
|
# Configure WMS map server
|
||||||
|
|
||||||
OpenSearch Dashboards includes default map tiles, but if you need more specialized maps, you can configure OpenSearch Dashboards to use a WMS map server:
|
OpenSearch Dashboards includes default map tiles, but if you need more specialized maps, you can configure OpenSearch Dashboards to use a WMS map server:
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
layout: default
|
layout: default
|
||||||
title: Notebooks
|
title: Notebooks
|
||||||
nav_order: 50
|
nav_order: 50
|
||||||
redirect_from: /docs/notebooks/
|
redirect_from: /notebooks/
|
||||||
has_children: false
|
has_children: false
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -36,6 +36,7 @@ A notebook is an interface for creating reports.
|
|||||||
|
|
||||||
Choose **Actions** to rename, duplicate, or delete a notebook.
|
Choose **Actions** to rename, duplicate, or delete a notebook.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### Step 2: Add a paragraph
|
### Step 2: Add a paragraph
|
||||||
|
|
||||||
@@ -55,7 +56,7 @@ For example, type `%md` for markdown, `%sql` for SQL, and `%ppl` for PPL.
|
|||||||
Add in text formatted in markdown.
|
Add in text formatted in markdown.
|
||||||
```
|
```
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
##### Sample SQL block
|
##### Sample SQL block
|
||||||
|
|
||||||
@@ -64,7 +65,7 @@ Add in text formatted in markdown.
|
|||||||
Select * from opensearch_dashboards_sample_data_flights limit 20;
|
Select * from opensearch_dashboards_sample_data_flights limit 20;
|
||||||
```
|
```
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
##### Sample PPL block
|
##### Sample PPL block
|
||||||
|
|
||||||
@@ -73,7 +74,7 @@ Select * from opensearch_dashboards_sample_data_flights limit 20;
|
|||||||
source=opensearch_dashboards_sample_data_logs | head 20
|
source=opensearch_dashboards_sample_data_logs | head 20
|
||||||
```
|
```
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|
||||||
#### Add a visualization
|
#### Add a visualization
|
||||||
@@ -82,7 +83,7 @@ source=opensearch_dashboards_sample_data_logs | head 20
|
|||||||
1. In **Title**, select your visualization and choose a date range. You can choose multiple timelines to compare and contrast visualizations.
|
1. In **Title**, select your visualization and choose a date range. You can choose multiple timelines to compare and contrast visualizations.
|
||||||
1. To run and save a paragraph, choose **Run**.
|
1. To run and save a paragraph, choose **Run**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
## Paragraph actions
|
## Paragraph actions
|
||||||
|
|
||||||
@@ -93,7 +94,8 @@ You can perform the following actions on paragraphs:
|
|||||||
- Run all the paragraphs at the same time.
|
- Run all the paragraphs at the same time.
|
||||||
- Clear the outputs of all paragraphs.
|
- Clear the outputs of all paragraphs.
|
||||||
- Delete all the paragraphs.
|
- Delete all the paragraphs.
|
||||||
- Move paragraphs up and down.
|
|
||||||
|

|
||||||
|
|
||||||
## Sample notebooks
|
## Sample notebooks
|
||||||
|
|
||||||
@@ -105,6 +107,8 @@ We prepared the following sample notebooks that showcase a variety of use cases:
|
|||||||
|
|
||||||
To add a sample notebook, choose **Actions** and select **Add sample notebooks**.
|
To add a sample notebook, choose **Actions** and select **Add sample notebooks**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
## Create a report
|
## Create a report
|
||||||
|
|
||||||
You can use notebooks to create PNG and PDF reports:
|
You can use notebooks to create PNG and PDF reports:
|
||||||
@@ -116,3 +120,5 @@ You can use notebooks to create PNG and PDF reports:
|
|||||||
|
|
||||||
1. To create a schedule-based report, choose **Create report definition**. For steps to create a report definition, see [Create reports using a definition]({{site.url}}{{site.baseurl}}/dashboards/reporting#create-reports-using-a-definition).
|
1. To create a schedule-based report, choose **Create report definition**. For steps to create a report definition, see [Create reports using a definition]({{site.url}}{{site.baseurl}}/dashboards/reporting#create-reports-using-a-definition).
|
||||||
1. To see all your reports, choose **View all reports**.
|
1. To see all your reports, choose **View all reports**.
|
||||||
|
|
||||||
|

|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
message: "🔥 [OpenSearch 1.0 released on July 12th! Get it now!](/downloads.html)"
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
columns:
|
||||||
|
-
|
||||||
|
title: 'Get Involved'
|
||||||
|
links:
|
||||||
|
-
|
||||||
|
title: Code of Conduct
|
||||||
|
url: '/codeofconduct.html'
|
||||||
|
-
|
||||||
|
title: 'Forums'
|
||||||
|
url: 'https://discuss.opendistrocommunity.dev/'
|
||||||
|
-
|
||||||
|
title: 'Github'
|
||||||
|
url: 'https://github.com/opensearch-project'
|
||||||
|
-
|
||||||
|
title: 'Partners'
|
||||||
|
url: '/partners/'
|
||||||
|
-
|
||||||
|
title: 'Community Projects'
|
||||||
|
url: '/community_projects'
|
||||||
|
-
|
||||||
|
title: 'Resources'
|
||||||
|
links:
|
||||||
|
#-
|
||||||
|
# title: 'Documentation'
|
||||||
|
# url: 'https://github.com/opensearch/documentation'
|
||||||
|
-
|
||||||
|
title: FAQ
|
||||||
|
url: '/faq/'
|
||||||
|
-
|
||||||
|
title: 'Brand Guidelines'
|
||||||
|
url: '/brand.html'
|
||||||
|
-
|
||||||
|
title: 'Trademark Usage Policy'
|
||||||
|
url: '/trademark-usage.html'
|
||||||
|
-
|
||||||
|
title: OpenSearch Disambiguation
|
||||||
|
url: '/disambiguation.html'
|
||||||
|
-
|
||||||
|
title: 'Connect'
|
||||||
|
links:
|
||||||
|
# -
|
||||||
|
# title: 'Twitter'
|
||||||
|
# url: 'https://twitter.com/opensearch_project'
|
||||||
|
#-
|
||||||
|
# title: 'Facebook'
|
||||||
|
# url: 'http://www.facebook.com/opensearch'
|
||||||
|
-
|
||||||
|
title: 'E-mail'
|
||||||
|
url: 'mailto:[email protected]'
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Dashboards developer guide
|
||||||
|
nav_order: 2
|
||||||
|
permalink: /dashboards-developer-guide/
|
||||||
|
redirect_to: https://github.com/opensearch-project/OpenSearch-Dashboards/blob/main/DEVELOPER_GUIDE.md
|
||||||
|
---
|
||||||
@@ -3,5 +3,5 @@ layout: default
|
|||||||
title: Javadoc
|
title: Javadoc
|
||||||
nav_order: 1
|
nav_order: 1
|
||||||
permalink: /javadoc/
|
permalink: /javadoc/
|
||||||
redirect_to: https://opensearch.org/docs/javadocs/
|
redirect_to: https://opensearch.org/javadocs/
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
nav_exclude: true
|
||||||
|
permalink: /javadocs/
|
||||||
|
redirect_to: https://opensearch.org/javadocs/
|
||||||
|
---
|
||||||
@@ -3,7 +3,7 @@ layout: default
|
|||||||
title: Index rollups
|
title: Index rollups
|
||||||
nav_order: 35
|
nav_order: 35
|
||||||
has_children: true
|
has_children: true
|
||||||
redirect_from: /docs/ism/index-rollups/
|
redirect_from: /im-plugin/index-rollups/
|
||||||
has_toc: false
|
has_toc: false
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
@@ -2,7 +2,6 @@
|
|||||||
layout: default
|
layout: default
|
||||||
title: Index rollups API
|
title: Index rollups API
|
||||||
parent: Index rollups
|
parent: Index rollups
|
||||||
redirect_from: /docs/ism/rollup-api/
|
|
||||||
nav_order: 9
|
nav_order: 9
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -20,6 +19,8 @@ Use the index rollup operations to programmatically work with index rollup jobs.
|
|||||||
---
|
---
|
||||||
|
|
||||||
## Create or update an index rollup job
|
## Create or update an index rollup job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Creates or updates an index rollup job.
|
Creates or updates an index rollup job.
|
||||||
You must provide the `seq_no` and `primary_term` parameters.
|
You must provide the `seq_no` and `primary_term` parameters.
|
||||||
@@ -89,36 +90,36 @@ You can specify the following options.
|
|||||||
|
|
||||||
Options | Description | Type | Required
|
Options | Description | Type | Required
|
||||||
:--- | :--- |:--- |:--- |
|
:--- | :--- |:--- |:--- |
|
||||||
`source_index` | The name of the detector. | `string` | Yes
|
`source_index` | The name of the detector. | String | Yes
|
||||||
`target_index` | Specify the target index that the rolled up data is ingested into. You could either create a new target index or use an existing index. The target index cannot be a combination of raw and rolled up data. | `string` | Yes
|
`target_index` | Specify the target index that the rolled up data is ingested into. You could either create a new target index or use an existing index. The target index cannot be a combination of raw and rolled up data. | String | Yes
|
||||||
`schedule` | Schedule of the index rollup job which can be an interval or a cron expression. | `object` | Yes
|
`schedule` | Schedule of the index rollup job which can be an interval or a cron expression. | Object | Yes
|
||||||
`schedule.interval` | Specify the frequency of execution of the rollup job. | `object` | No
|
`schedule.interval` | Specify the frequency of execution of the rollup job. | Object | No
|
||||||
`schedule.interval.start_time` | Start time of the interval. | `timestamp` | Yes
|
`schedule.interval.start_time` | Start time of the interval. | Timestamp | Yes
|
||||||
`schedule.interval.period` | Define the interval period. | `string` | Yes
|
`schedule.interval.period` | Define the interval period. | String | Yes
|
||||||
`schedule.interval.unit` | Specify the time unit of the interval. | `string` | Yes
|
`schedule.interval.unit` | Specify the time unit of the interval. | String | Yes
|
||||||
`schedule.interval.cron` | Optionally, specify a cron expression to define therollup frequency. | `list` | No
|
`schedule.interval.cron` | Optionally, specify a cron expression to define therollup frequency. | List | No
|
||||||
`schedule.interval.cron.expression` | Specify a Unix cron expression. | `string` | Yes
|
`schedule.interval.cron.expression` | Specify a Unix cron expression. | String | Yes
|
||||||
`schedule.interval.cron.timezone` | Specify timezones as defined by the IANA Time Zone Database. Defaults to UTC. | `string` | No
|
`schedule.interval.cron.timezone` | Specify timezones as defined by the IANA Time Zone Database. Defaults to UTC. | String | No
|
||||||
`description` | Optionally, describe the rollup job. | `string` | No
|
`description` | Optionally, describe the rollup job. | String | No
|
||||||
`enabled` | When true, the index rollup job is scheduled. Default is true. | `boolean` | Yes
|
`enabled` | When true, the index rollup job is scheduled. Default is true. | Boolean | Yes
|
||||||
`continuous` | Specify whether or not the index rollup job continuously rolls up data forever or just executes over the current data set once and stops. Default is false. | `boolean` | Yes
|
`continuous` | Specify whether or not the index rollup job continuously rolls up data forever or just executes over the current data set once and stops. Default is false. | Boolean | Yes
|
||||||
`error_notification` | Set up a Mustache message template sent for error notifications. For example, if an index rollup job fails, the system sends a message to a Slack channel. | `object` | No
|
`error_notification` | Set up a Mustache message template sent for error notifications. For example, if an index rollup job fails, the system sends a message to a Slack channel. | Object | No
|
||||||
`page_size` | Specify the number of buckets to paginate through at a time while rolling up. | `number` | Yes
|
`page_size` | Specify the number of buckets to paginate through at a time while rolling up. | Number | Yes
|
||||||
`delay` | Specify time value to delay execution of the index rollup job. | `time_unit` | No
|
`delay` | The number of milliseconds to delay execution of the index rollup job. | Long | No
|
||||||
`dimensions` | Specify aggregations to create dimensions for the roll up time window. | `object` | Yes
|
`dimensions` | Specify aggregations to create dimensions for the roll up time window. | Object | Yes
|
||||||
`dimensions.date_histogram` | Specify either fixed_interval or calendar_interval, but not both. Either one limits what you can query in the target index. | `object` | No
|
`dimensions.date_histogram` | Specify either fixed_interval or calendar_interval, but not both. Either one limits what you can query in the target index. | Object | No
|
||||||
`dimensions.date_histogram.fixed_interval` | Specify the fixed interval for aggregations in milliseconds, seconds, minutes, hours, or days. | `string` | No
|
`dimensions.date_histogram.fixed_interval` | Specify the fixed interval for aggregations in milliseconds, seconds, minutes, hours, or days. | String | No
|
||||||
`dimensions.date_histogram.calendar_interval` | Specify the calendar interval for aggregations in minutes, hours, days, weeks, months, quarters, or years. | `string` | No
|
`dimensions.date_histogram.calendar_interval` | Specify the calendar interval for aggregations in minutes, hours, days, weeks, months, quarters, or years. | String | No
|
||||||
`dimensions.date_histogram.field` | Specify the date field used in date histogram aggregation. | `string` | No
|
`dimensions.date_histogram.field` | Specify the date field used in date histogram aggregation. | String | No
|
||||||
`dimensions.date_histogram.timezone` | Specify the timezones as defined by the IANA Time Zone Database. The default is UTC. | `string` | No
|
`dimensions.date_histogram.timezone` | Specify the timezones as defined by the IANA Time Zone Database. The default is UTC. | String | No
|
||||||
`dimensions.terms` | Specify the term aggregations that you want to roll up. | `object` | No
|
`dimensions.terms` | Specify the term aggregations that you want to roll up. | Object | No
|
||||||
`dimensions.terms.fields` | Specify terms aggregation for compatible fields. | `object` | No
|
`dimensions.terms.fields` | Specify terms aggregation for compatible fields. | Object | No
|
||||||
`dimensions.histogram` | Specify the histogram aggregations that you want to roll up. | `object` | No
|
`dimensions.histogram` | Specify the histogram aggregations that you want to roll up. | Object | No
|
||||||
`dimensions.histogram.field` | Add a field for histogram aggregations. | `string` | Yes
|
`dimensions.histogram.field` | Add a field for histogram aggregations. | String | Yes
|
||||||
`dimensions.histogram.interval` | Specify the histogram aggregation interval for the field. | `long` | Yes
|
`dimensions.histogram.interval` | Specify the histogram aggregation interval for the field. | Long | Yes
|
||||||
`dimensions.metrics` | Specify a list of objects that represent the fields and metrics that you want to calculate. | `nested object` | No
|
`dimensions.metrics` | Specify a list of objects that represent the fields and metrics that you want to calculate. | Nested object | No
|
||||||
`dimensions.metrics.field` | Specify the field that you want to perform metric aggregations on. | `string` | No
|
`dimensions.metrics.field` | Specify the field that you want to perform metric aggregations on. | String | No
|
||||||
`dimensions.metrics.field.metrics` | Specify the metric aggregations you want to calculate for the field. | `multiple strings` | No
|
`dimensions.metrics.field.metrics` | Specify the metric aggregations you want to calculate for the field. | Multiple strings | No
|
||||||
|
|
||||||
|
|
||||||
#### Sample response
|
#### Sample response
|
||||||
@@ -134,6 +135,8 @@ Options | Description | Type | Required
|
|||||||
|
|
||||||
|
|
||||||
## Get an index rollup job
|
## Get an index rollup job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Returns all information about an index rollup job based on the `rollup_id`.
|
Returns all information about an index rollup job based on the `rollup_id`.
|
||||||
|
|
||||||
@@ -159,6 +162,8 @@ GET _plugins/_rollup/jobs/<rollup_id>
|
|||||||
---
|
---
|
||||||
|
|
||||||
## Delete an index rollup job
|
## Delete an index rollup job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Deletes an index rollup job based on the `rollup_id`.
|
Deletes an index rollup job based on the `rollup_id`.
|
||||||
|
|
||||||
@@ -178,6 +183,8 @@ DELETE _plugins/_rollup/jobs/<rollup_id>
|
|||||||
|
|
||||||
|
|
||||||
## Start or stop an index rollup job
|
## Start or stop an index rollup job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Start or stop an index rollup job.
|
Start or stop an index rollup job.
|
||||||
|
|
||||||
@@ -199,6 +206,8 @@ POST _plugins/_rollup/jobs/<rollup_id>/_stop
|
|||||||
---
|
---
|
||||||
|
|
||||||
## Explain an index rollup job
|
## Explain an index rollup job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Returns detailed metadata information about the index rollup job and its current progress.
|
Returns detailed metadata information about the index rollup job and its current progress.
|
||||||
|
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ layout: default
|
|||||||
title: Index transforms
|
title: Index transforms
|
||||||
nav_order: 20
|
nav_order: 20
|
||||||
has_children: true
|
has_children: true
|
||||||
redirect_from: /docs/im/index-transforms/
|
redirect_from: /im-plugin/index-transforms/
|
||||||
has_toc: false
|
has_toc: false
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
@@ -15,6 +15,8 @@ Aside from using OpenSearch Dashboards, you can also use the REST API to create,
|
|||||||
{:toc}
|
{:toc}
|
||||||
|
|
||||||
## Create a transform job
|
## Create a transform job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Creates a transform job.
|
Creates a transform job.
|
||||||
|
|
||||||
@@ -139,6 +141,8 @@ source_field | String | The field(s) to transform | Yes
|
|||||||
aggregations | JSON | The aggregations to use in the transform job. Supported aggregations are: `sum`, `max`, `min`, `value_count`, `avg`, `scripted_metric`, and `percentiles`. For more information, see [Metric Aggregations]({{site.url}}{{site.baseurl}}/opensearch/metric-agg). | Yes if not using groups
|
aggregations | JSON | The aggregations to use in the transform job. Supported aggregations are: `sum`, `max`, `min`, `value_count`, `avg`, `scripted_metric`, and `percentiles`. For more information, see [Metric Aggregations]({{site.url}}{{site.baseurl}}/opensearch/metric-agg). | Yes if not using groups
|
||||||
|
|
||||||
## Update a transform job
|
## Update a transform job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Updates a transform job if `transform_id` already exists.
|
Updates a transform job if `transform_id` already exists.
|
||||||
|
|
||||||
@@ -254,6 +258,8 @@ Parameter | Description | Required
|
|||||||
`if_primary_term` | Only perform the transform operation if the last operation that changed the transform job has the specified sequence term. | No
|
`if_primary_term` | Only perform the transform operation if the last operation that changed the transform job has the specified sequence term. | No
|
||||||
|
|
||||||
## Get a transform job's details
|
## Get a transform job's details
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Returns a transform job's details.
|
Returns a transform job's details.
|
||||||
|
|
||||||
@@ -520,6 +526,8 @@ GET _plugins/_transform?size=2&from=8
|
|||||||
```
|
```
|
||||||
|
|
||||||
## Start a transform job
|
## Start a transform job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Transform jobs created using the API are automatically enabled, but if you ever need to enable a job, you can use the `start` API operation.
|
Transform jobs created using the API are automatically enabled, but if you ever need to enable a job, you can use the `start` API operation.
|
||||||
|
|
||||||
@@ -538,6 +546,8 @@ POST _plugins/_transform/<transform_id>/_start
|
|||||||
```
|
```
|
||||||
|
|
||||||
## Stop a transform job
|
## Stop a transform job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Stops/disables a transform job.
|
Stops/disables a transform job.
|
||||||
|
|
||||||
@@ -556,6 +566,8 @@ POST _plugins/_transform/<transform_id>/_stop
|
|||||||
```
|
```
|
||||||
|
|
||||||
## Get the status of a transform job
|
## Get the status of a transform job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Returns the status and metadata of a transform job.
|
Returns the status and metadata of a transform job.
|
||||||
|
|
||||||
@@ -589,6 +601,8 @@ GET _plugins/_transform/<transform_id>/_explain
|
|||||||
```
|
```
|
||||||
|
|
||||||
## Preview a transform job's results
|
## Preview a transform job's results
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Returns a preview of what a transformed index would look like.
|
Returns a preview of what a transformed index would look like.
|
||||||
|
|
||||||
@@ -674,6 +688,8 @@ POST _plugins/_transform/_preview
|
|||||||
```
|
```
|
||||||
|
|
||||||
## Delete a transform job
|
## Delete a transform job
|
||||||
|
Introduced 1.0
|
||||||
|
{: .label .label-purple }
|
||||||
|
|
||||||
Deletes a transform job. This operation does not delete the source or target indices.
|
Deletes a transform job. This operation does not delete the source or target indices.
|
||||||
|
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user