Exclude index name using mserch query in elasticsearch










1















I am using elasticsearch to fetch logs using msearch API for multiple indices.
But I need to exclude some indexes. Suppose I have a,b,c,d,e indexes but I don't want to include indexes b,c.



I wrote elasticsearch query to fetch records:



GET _msearch?
"index":"*","size":100000,"exclude":["b","c"] //used kibana to check indexes
"query": //required to successfully run the query


But I am getting records including indexes b,c. I checked the documentation but I didn't get any proper resource for this.
How can I resolve this??










share|improve this question




























    1















    I am using elasticsearch to fetch logs using msearch API for multiple indices.
    But I need to exclude some indexes. Suppose I have a,b,c,d,e indexes but I don't want to include indexes b,c.



    I wrote elasticsearch query to fetch records:



    GET _msearch?
    "index":"*","size":100000,"exclude":["b","c"] //used kibana to check indexes
    "query": //required to successfully run the query


    But I am getting records including indexes b,c. I checked the documentation but I didn't get any proper resource for this.
    How can I resolve this??










    share|improve this question


























      1












      1








      1








      I am using elasticsearch to fetch logs using msearch API for multiple indices.
      But I need to exclude some indexes. Suppose I have a,b,c,d,e indexes but I don't want to include indexes b,c.



      I wrote elasticsearch query to fetch records:



      GET _msearch?
      "index":"*","size":100000,"exclude":["b","c"] //used kibana to check indexes
      "query": //required to successfully run the query


      But I am getting records including indexes b,c. I checked the documentation but I didn't get any proper resource for this.
      How can I resolve this??










      share|improve this question
















      I am using elasticsearch to fetch logs using msearch API for multiple indices.
      But I need to exclude some indexes. Suppose I have a,b,c,d,e indexes but I don't want to include indexes b,c.



      I wrote elasticsearch query to fetch records:



      GET _msearch?
      "index":"*","size":100000,"exclude":["b","c"] //used kibana to check indexes
      "query": //required to successfully run the query


      But I am getting records including indexes b,c. I checked the documentation but I didn't get any proper resource for this.
      How can I resolve this??







      elasticsearch kibana






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited Nov 16 '18 at 23:11









      Nikolay Vasiliev

      2,299718




      2,299718










      asked Nov 15 '18 at 11:29









      Bhavya DhimanBhavya Dhiman

      677




      677






















          1 Answer
          1






          active

          oldest

          votes


















          2














          This code should do the trick:



          GET _msearch?
          "index":"*,-b,-c","size":100000
          "query":


          Note the minus (-) in the "index" value.



          Although there isn't an explicit mention in the _msearch docs page, it looks like most of the APIs supporting multi index execution work in the same way:




          Most APIs that refer to an index parameter support execution across
          multiple indices, using simple test1,test2,test3 notation (or _all for
          all indices).
          It also support wildcards, for example: test* or test or tet or
          test, and the ability to "exclude" (-), for example: test*,-test3.




          There's a similar question on search over multiple indexes in general.






          share|improve this answer























          • thanks!! i got it!

            – Bhavya Dhiman
            Nov 16 '18 at 20:23










          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53318472%2fexclude-index-name-using-mserch-query-in-elasticsearch%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          2














          This code should do the trick:



          GET _msearch?
          "index":"*,-b,-c","size":100000
          "query":


          Note the minus (-) in the "index" value.



          Although there isn't an explicit mention in the _msearch docs page, it looks like most of the APIs supporting multi index execution work in the same way:




          Most APIs that refer to an index parameter support execution across
          multiple indices, using simple test1,test2,test3 notation (or _all for
          all indices).
          It also support wildcards, for example: test* or test or tet or
          test, and the ability to "exclude" (-), for example: test*,-test3.




          There's a similar question on search over multiple indexes in general.






          share|improve this answer























          • thanks!! i got it!

            – Bhavya Dhiman
            Nov 16 '18 at 20:23















          2














          This code should do the trick:



          GET _msearch?
          "index":"*,-b,-c","size":100000
          "query":


          Note the minus (-) in the "index" value.



          Although there isn't an explicit mention in the _msearch docs page, it looks like most of the APIs supporting multi index execution work in the same way:




          Most APIs that refer to an index parameter support execution across
          multiple indices, using simple test1,test2,test3 notation (or _all for
          all indices).
          It also support wildcards, for example: test* or test or tet or
          test, and the ability to "exclude" (-), for example: test*,-test3.




          There's a similar question on search over multiple indexes in general.






          share|improve this answer























          • thanks!! i got it!

            – Bhavya Dhiman
            Nov 16 '18 at 20:23













          2












          2








          2







          This code should do the trick:



          GET _msearch?
          "index":"*,-b,-c","size":100000
          "query":


          Note the minus (-) in the "index" value.



          Although there isn't an explicit mention in the _msearch docs page, it looks like most of the APIs supporting multi index execution work in the same way:




          Most APIs that refer to an index parameter support execution across
          multiple indices, using simple test1,test2,test3 notation (or _all for
          all indices).
          It also support wildcards, for example: test* or test or tet or
          test, and the ability to "exclude" (-), for example: test*,-test3.




          There's a similar question on search over multiple indexes in general.






          share|improve this answer













          This code should do the trick:



          GET _msearch?
          "index":"*,-b,-c","size":100000
          "query":


          Note the minus (-) in the "index" value.



          Although there isn't an explicit mention in the _msearch docs page, it looks like most of the APIs supporting multi index execution work in the same way:




          Most APIs that refer to an index parameter support execution across
          multiple indices, using simple test1,test2,test3 notation (or _all for
          all indices).
          It also support wildcards, for example: test* or test or tet or
          test, and the ability to "exclude" (-), for example: test*,-test3.




          There's a similar question on search over multiple indexes in general.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Nov 16 '18 at 18:31









          Nikolay VasilievNikolay Vasiliev

          2,299718




          2,299718












          • thanks!! i got it!

            – Bhavya Dhiman
            Nov 16 '18 at 20:23

















          • thanks!! i got it!

            – Bhavya Dhiman
            Nov 16 '18 at 20:23
















          thanks!! i got it!

          – Bhavya Dhiman
          Nov 16 '18 at 20:23





          thanks!! i got it!

          – Bhavya Dhiman
          Nov 16 '18 at 20:23



















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53318472%2fexclude-index-name-using-mserch-query-in-elasticsearch%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          這個網誌中的熱門文章

          How to read a connectionString WITH PROVIDER in .NET Core?

          In R, how to develop a multiplot heatmap.2 figure showing key labels successfully

          Museum of Modern and Contemporary Art of Trento and Rovereto