全部笔记All notes

Elasticsearch 搜索引擎完整指南

阅读 11m 36s11m 36s read

概述

Elasticsearch 是一个基于 Apache Lucene 构建的分布式、RESTful 搜索和分析引擎。作为 ELK Stack(Elasticsearch, Logstash, Kibana)的核心组件,Elasticsearch 广泛应用于日志分析、全文搜索、业务分析等领域。

核心特性

  • 分布式架构: 水平扩展,高可用性
  • 近实时搜索: 数据入库后秒级可搜
  • RESTful API: 简单易用的 HTTP 接口
  • 全文搜索: 强大的文本分析能力
  • 聚合分析: 实时数据统计和分析
  • 多种数据类型: 支持结构化和非结构化数据

版本选择

版本发布时间主要特性推荐度
8.x2022+新架构、性能提升⭐⭐⭐⭐⭐
7.x2019+稳定版本、功能完善⭐⭐⭐⭐
6.x2017+传统版本、兼容性好⭐⭐⭐

应用场景

场景描述适用性
日志分析系统日志、应用日志分析⭐⭐⭐⭐⭐
全文搜索网站搜索、文档搜索⭐⭐⭐⭐⭐
业务分析实时数据分析、BI 报表⭐⭐⭐⭐
监控告警APM、系统监控⭐⭐⭐⭐
地理信息位置搜索、地图应用⭐⭐⭐

💡 推荐: 新项目建议使用 Elasticsearch 7.17+ 或 8.x 最新版本。

环境准备

系统要求

组件最低要求推荐配置
CPU2 核心4 核心以上
内存4GB8GB 以上
存储20GB100GB SSD
JVMOpenJDK 11+OpenJDK 17+

系统配置

# 设置虚拟内存映射数量
sudo sysctl -w vm.max_map_count=262144
echo 'vm.max_map_count=262144' | sudo tee -a /etc/sysctl.conf

# 设置文件描述符限制
echo '* soft nofile 65536' | sudo tee -a /etc/security/limits.conf
echo '* hard nofile 65536' | sudo tee -a /etc/security/limits.conf

# 设置进程数限制
echo '* soft nproc 4096' | sudo tee -a /etc/security/limits.conf
echo '* hard nproc 4096' | sudo tee -a /etc/security/limits.conf

Docker 快速部署

单节点部署

1. 部署 Elasticsearch

# 创建 Docker 网络
docker network create elastic

# 部署 Elasticsearch 7.17.7
docker run -d \
  --name elasticsearch \
  --network elastic \
  -p 9200:9200 \
  -p 9300:9300 \
  -e "discovery.type=single-node" \
  -e "ES_JAVA_OPTS=-Xms512m -Xmx512m" \
  -e "xpack.security.enabled=false" \
  elasticsearch:7.17.7

# 验证安装
curl -X GET "localhost:9200/"

2. 安装 IK 中文分词器

# 进入容器
docker exec -it elasticsearch /bin/bash

# 在线安装 IK 分词器
./bin/elasticsearch-plugin install https://github.com/medcl/elasticsearch-analysis-ik/releases/download/v7.17.7/elasticsearch-analysis-ik-7.17.7.zip

# 或者本地安装(网络问题时)
# 1. 下载 ik 分词器到服务器
# 2. 复制到容器
docker cp /path/to/elasticsearch-analysis-ik-7.17.7.zip elasticsearch:/tmp/

# 3. 在容器内安装
docker exec -it elasticsearch /bin/bash
./bin/elasticsearch-plugin install file:///tmp/elasticsearch-analysis-ik-7.17.7.zip

# 重启 Elasticsearch
docker restart elasticsearch

3. 部署 Kibana

# 部署 Kibana
docker run -d \
  --name kibana \
  --network elastic \
  -p 5601:5601 \
  -e "ELASTICSEARCH_HOSTS=http://elasticsearch:9200" \
  kibana:7.17.7

访问 Kibana

访问 http://localhost:5601 即可打开 Kibana 界面

基础操作

集群健康检查

# 检查集群健康状态
curl -X GET "localhost:9200/_cluster/health?pretty"

# 查看节点信息
curl -X GET "localhost:9200/_nodes?pretty"

# 查看集群统计信息
curl -X GET "localhost:9200/_cluster/stats?pretty"

索引管理

创建索引

# 创建简单索引
curl -X PUT "localhost:9200/my_index"

# 创建带设置的索引
curl -X PUT "localhost:9200/my_index" -H 'Content-Type: application/json' -d'
{
  "settings": {
    "number_of_shards": 1,
    "number_of_replicas": 1,
    "analysis": {
      "analyzer": {
        "ik_max_word_analyzer": {
          "type": "ik_max_word"
        },
        "ik_smart_analyzer": {
          "type": "ik_smart"
        }
      }
    }
  },
  "mappings": {
    "properties": {
      "title": {
        "type": "text",
        "analyzer": "ik_max_word",
        "search_analyzer": "ik_smart"
      },
      "content": {
        "type": "text",
        "analyzer": "ik_max_word"
      },
      "author": {
        "type": "keyword"
      },
      "publish_date": {
        "type": "date",
        "format": "yyyy-MM-dd HH:mm:ss||yyyy-MM-dd||epoch_millis"
      },
      "tags": {
        "type": "keyword"
      }
    }
  }
}'

查看和删除索引

# 查看所有索引
curl -X GET "localhost:9200/_cat/indices?v"

# 查看索引详细信息
curl -X GET "localhost:9200/my_index?pretty"

# 查看索引映射
curl -X GET "localhost:9200/my_index/_mapping?pretty"

# 删除索引
curl -X DELETE "localhost:9200/my_index"

数据操作

文档增删改查

新增文档

# 指定 ID 创建文档
curl -X PUT "localhost:9200/my_index/_doc/1" -H 'Content-Type: application/json' -d'
{
  "title": "Elasticsearch 入门教程",
  "content": "Elasticsearch 是一个分布式、RESTful 搜索和分析引擎",
  "author": "张三",
  "publish_date": "2023-07-01 10:00:00",
  "tags": ["elasticsearch", "搜索引擎", "教程"]
}
'

# 自动生成 ID
curl -X POST "localhost:9200/my_index/_doc" -H 'Content-Type: application/json' -d'
{
  "title": "Kibana 可视化分析",
  "content": "Kibana 是 Elasticsearch 的数据可视化和管理工具",
  "author": "李四",
  "publish_date": "2023-07-02 14:30:00",
  "tags": ["kibana", "可视化", "数据分析"]
}
'

# 批量操作(注意:每个JSON对象必须单独一行)
curl -X POST "localhost:9200/_bulk" -H 'Content-Type: application/json' -d'
{"index":{"_index":"my_index","_id":"3"}}
{"title":"Logstash 数据处理","content":"Logstash 是一个开源的数据收集引擎","author":"王五","publish_date":"2023-07-03 09:15:00","tags":["logstash","数据处理","ETL"]}
{"index":{"_index":"my_index","_id":"4"}}
{"title":"ELK Stack 完整方案","content":"ELK Stack 是完整的日志分析解决方案","author":"赵六","publish_date":"2023-07-04 16:45:00","tags":["elk","日志分析","监控"]}
'

查询文档

# 根据 ID 查询
curl -X GET "localhost:9200/my_index/_doc/1?pretty"

# 检查文档是否存在
curl -I "localhost:9200/my_index/_doc/1"

# 查询所有文档
curl -X GET "localhost:9200/my_index/_search?pretty"

更新文档

# 全量更新
curl -X PUT "localhost:9200/my_index/_doc/1" -H 'Content-Type: application/json' -d'
{
  "title": "Elasticsearch 高级教程",
  "content": "深入学习 Elasticsearch 的高级特性和优化技巧",
  "author": "张三",
  "publish_date": "2023-07-01 10:00:00",
  "tags": ["elasticsearch", "高级", "优化"]
}
'

# 部分更新
curl -X POST "localhost:9200/my_index/_update/1" -H 'Content-Type: application/json' -d'
{
  "doc": {
    "title": "Elasticsearch 完整指南"
  }
}
'

# 脚本更新
curl -X POST "localhost:9200/my_index/_update/1" -H 'Content-Type: application/json' -d'
{
  "script": {
    "source": "if (!ctx._source.tags.contains(params.tag)) { ctx._source.tags.add(params.tag) }",
    "params": {
      "tag": "完整指南"
    }
  }
}
'

删除文档

# 根据 ID 删除
curl -X DELETE "localhost:9200/my_index/_doc/1"

# 根据查询删除
curl -X POST "localhost:9200/my_index/_delete_by_query" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match": {
      "author": "张三"
    }
  }
}
'

搜索查询

基础查询

全文搜索

# match 查询(分词匹配)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match": {
      "content": "搜索引擎"
    }
  }
}
'

# match_phrase 查询(短语匹配)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match_phrase": {
      "content": "分布式搜索"
    }
  }
}
'

# multi_match 查询(多字段搜索)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "multi_match": {
      "query": "elasticsearch",
      "fields": ["title^2", "content"]
    }
  }
}
'

精确匹配

# term 查询(精确匹配)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "term": {
      "author": "张三"
    }
  }
}
'

# terms 查询(多值匹配)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "terms": {
      "tags": ["elasticsearch", "kibana"]
    }
  }
}
'

# range 查询(范围查询)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "range": {
      "publish_date": {
        "gte": "2023-07-01",
        "lte": "2023-07-03"
      }
    }
  }
}
'

复合查询

# bool 查询(布尔组合)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "bool": {
      "must": [
        {
          "match": {
            "content": "elasticsearch"
          }
        }
      ],
      "filter": [
        {
          "term": {
            "author.keyword": "张三"
          }
        },
        {
          "range": {
            "publish_date": {
              "gte": "2023-07-01"
            }
          }
        }
      ],
      "should": [
        {
          "match": {
            "title": "教程"
          }
        }
      ],
      "must_not": [
        {
          "term": {
            "tags": "已删除"
          }
        }
      ]
    }
  }
}
'

排序和分页

# 排序查询
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match_all": {}
  },
  "sort": [
    {
      "publish_date": {
        "order": "desc"
      }
    },
    {
      "_score": {
        "order": "desc"
      }
    }
  ]
}
'

# 分页查询
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match_all": {}
  },
  "from": 0,
  "size": 10
}
'

# 字段过滤
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "query": {
    "match_all": {}
  },
  "_source": ["title", "author", "publish_date"]
}
'

聚合分析

指标聚合

# 统计聚合
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "size": 0,
  "aggs": {
    "doc_count": {
      "value_count": {
        "field": "title.keyword"
      }
    },
    "avg_content_length": {
      "avg": {
        "script": {
          "source": "params._source.content.length()"
        }
      }
    }
  }
}
'

桶聚合

# terms 聚合(分组统计)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "size": 0,
  "aggs": {
    "authors": {
      "terms": {
        "field": "author.keyword",
        "size": 10
      }
    },
    "tags": {
      "terms": {
        "field": "tags",
        "size": 20
      }
    }
  }
}
'

# date_histogram 聚合(时间分布)
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "size": 0,
  "aggs": {
    "publish_dates": {
      "date_histogram": {
        "field": "publish_date",
        "calendar_interval": "day",
        "format": "yyyy-MM-dd"
      }
    }
  }
}
'

嵌套聚合

# 嵌套聚合分析
curl -X GET "localhost:9200/my_index/_search" -H 'Content-Type: application/json' -d'
{
  "size": 0,
  "aggs": {
    "authors": {
      "terms": {
        "field": "author.keyword"
      },
      "aggs": {
        "avg_content_length": {
          "avg": {
            "script": {
              "source": "doc[\"content.keyword\"].value.length()"
            }
          }
        },
        "tags": {
          "terms": {
            "field": "tags",
            "size": 5
          }
        }
      }
    }
  }
}
'

Kibana 可视化

Dev Tools 使用

  1. 访问 Dev Tools:

    • 打开 Kibana: http://localhost:5601
    • 左侧菜单选择 “Dev Tools”
  2. 执行查询:

    GET /my_index/_search
    {
      "query": {
        "match": {
          "content": "elasticsearch"
        }
      }
    }

创建索引模式

  1. 管理 → 索引模式
  2. 创建索引模式: my_index*
  3. 选择时间字段: publish_date

数据可视化

1. 创建柱状图

  • Visualize Library → Create visualization → Vertical bar
  • Y轴: Count
  • X轴: Terms aggregation on author.keyword

2. 创建饼图

  • Visualize Library → Create visualization → Pie
  • Slice: Terms aggregation on tags

3. 创建时间序列图

  • Visualize Library → Create visualization → Line
  • Y轴: Count
  • X轴: Date histogram on publish_date

创建仪表板

  1. Dashboard → Create dashboard
  2. Add existing 添加已创建的可视化
  3. 保存仪表板

集群规划与架构设计

节点角色规划

Elasticsearch 7.x 引入了更细粒度的节点角色:

# master 节点 - 管理集群状态
node.roles: [master]

# data 节点 - 存储数据和执行查询
node.roles: [data]

# ingest 节点 - 预处理数据
node.roles: [ingest]

# coordinating 节点 - 协调查询请求
node.roles: []  # 空角色即为协调节点

# 混合节点(默认)
node.roles: [master, data, ingest]

集群规模设计

小型集群(< 100GB)

3 个节点(master + data)
├── 节点1:master, data
├── 节点2:master, data
└── 节点3:master, data

中型集群(100GB - 1TB)

专用 master 节点(3个)
├── master-1:仅 master 角色
├── master-2:仅 master 角色
└── master-3:仅 master 角色

数据节点(3-10个)
├── data-1:data, ingest
├── data-2:data, ingest
└── data-n:data, ingest

协调节点(2个)
├── coord-1:无角色
└── coord-2:无角色

大型集群(> 1TB)

专用 master 节点(3-5个)
专用数据节点(10+个)
├── 热数据节点:SSD 存储
├── 温数据节点:HDD 存储
└── 冷数据节点:归档存储

专用 ingest 节点(2-4个)
专用协调节点(4+个)
机器学习节点(可选)

硬件配置建议

节点类型CPU内存存储网络
Master4核8GB100GB SSD千兆
Data (热)16核64GB2TB NVMe万兆
Data (温)8核32GB8TB HDD千兆
Coordinating8核16GB100GB SSD万兆
Ingest8核16GB200GB SSD千兆

索引设计最佳实践

分片策略

分片数量计算

分片数 = 数据量 / 分片大小

推荐分片大小:
- 日志数据:30-50GB
- 搜索数据:10-30GB
- 时序数据:20-40GB

分片配置示例

PUT /my_index
{
  "settings": {
    "number_of_shards": 3,
    "number_of_replicas": 1,
    "refresh_interval": "30s",
    "index.translog.durability": "async",
    "index.translog.sync_interval": "30s"
  }
}

索引生命周期管理(ILM)

PUT _ilm/policy/logs_policy
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_age": "7d",
            "max_size": "50GB"
          },
          "set_priority": {
            "priority": 100
          }
        }
      },
      "warm": {
        "min_age": "7d",
        "actions": {
          "set_priority": {
            "priority": 50
          },
          "allocate": {
            "number_of_replicas": 1,
            "include": {
              "_tier_preference": "data_warm,data_hot"
            }
          },
          "forcemerge": {
            "max_num_segments": 1
          }
        }
      },
      "cold": {
        "min_age": "30d",
        "actions": {
          "set_priority": {
            "priority": 0
          },
          "allocate": {
            "number_of_replicas": 0,
            "include": {
              "_tier_preference": "data_cold,data_warm,data_hot"
            }
          }
        }
      },
      "delete": {
        "min_age": "90d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

索引模板设计

PUT _index_template/logs_template
{
  "index_patterns": ["logs-*"],
  "template": {
    "settings": {
      "number_of_shards": 3,
      "number_of_replicas": 1,
      "index.lifecycle.name": "logs_policy",
      "index.lifecycle.rollover_alias": "logs"
    },
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "message": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "level": {
          "type": "keyword"
        },
        "host": {
          "type": "keyword"
        }
      }
    }
  },
  "priority": 100
}

性能优化指南

查询性能优化

1. 使用 Filter 代替 Query

// 优化前 - 使用 query(计算相关性分数)
GET /products/_search
{
  "query": {
    "term": {
      "status": "active"
    }
  }
}

// 优化后 - 使用 filter(不计算分数,可缓存)
GET /products/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "term": {
            "status": "active"
          }
        }
      ]
    }
  }
}

2. 合理使用聚合缓存

PUT /sales
{
  "settings": {
    "index.requests.cache.enable": true
  }
}

// 使用 size: 0 避免返回文档
GET /sales/_search
{
  "size": 0,
  "aggs": {
    "sales_per_month": {
      "date_histogram": {
        "field": "date",
        "calendar_interval": "month"
      }
    }
  }
}

3. 查询优化技巧

// 避免深度分页
// 不推荐
GET /_search
{
  "from": 10000,
  "size": 10
}

// 推荐:使用 search_after
GET /_search
{
  "size": 10,
  "sort": [
    {"_id": "asc"}
  ],
  "search_after": ["last_doc_id"]
}

// 或使用 scroll(大量导出时)
POST /my_index/_search?scroll=1m
{
  "size": 1000
}

索引性能优化

1. 批量索引优化

# Python 示例:优化的批量索引
from elasticsearch import Elasticsearch, helpers

es = Elasticsearch()

def generate_actions():
    for i in range(1000000):
        yield {
            "_index": "my_index",
            "_source": {
                "id": i,
                "data": f"data_{i}"
            }
        }

# 使用 parallel_bulk 提高性能
for success, info in helpers.parallel_bulk(
    es,
    generate_actions(),
    chunk_size=1000,
    thread_count=4
):
    if not success:
        print(f"Failed: {info}")

2. 索引设置优化

// 批量导入前的设置
PUT /my_index/_settings
{
  "index": {
    "refresh_interval": "-1",
    "number_of_replicas": 0,
    "translog.durability": "async",
    "translog.flush_threshold_size": "1gb"
  }
}

// 导入完成后恢复设置
PUT /my_index/_settings
{
  "index": {
    "refresh_interval": "1s",
    "number_of_replicas": 1,
    "translog.durability": "request"
  }
}

// 强制合并段
POST /my_index/_forcemerge?max_num_segments=1

JVM 调优

堆内存设置

# jvm.options
-Xms32g  # 最小堆内存
-Xmx32g  # 最大堆内存(建议相同)

# 经验法则:
# 1. 不超过物理内存的 50%
# 2. 不超过 32GB(避免指针压缩失效)
# 3. 留一半内存给文件系统缓存

GC 优化

# 使用 G1GC(默认)
-XX:+UseG1GC
-XX:G1ReservePercent=25
-XX:InitiatingHeapOccupancyPercent=30

# GC 日志
-XX:+PrintGCDetails
-XX:+PrintGCDateStamps
-XX:+PrintTenuringDistribution
-XX:+PrintGCApplicationStoppedTime
-Xloggc:/var/log/elasticsearch/gc.log
-XX:+UseGCLogFileRotation
-XX:NumberOfGCLogFiles=32
-XX:GCLogFileSize=64m

系统级优化

1. 操作系统配置

# /etc/sysctl.conf
vm.max_map_count=262144
vm.swappiness=1
net.core.somaxconn=65535
net.ipv4.tcp_max_syn_backlog=65535

2. 文件系统优化

# 禁用 atime
mount -o remount,noatime,nodiratime /data

# I/O 调度器设置
echo noop > /sys/block/sda/queue/scheduler

监控与诊断

关键监控指标

集群健康

# 集群健康状态
GET /_cluster/health?pretty

# 节点统计
GET /_nodes/stats?pretty

# 索引统计
GET /_stats?pretty

性能监控

// 慢查询日志配置
PUT /my_index/_settings
{
  "index.search.slowlog.threshold.query.warn": "10s",
  "index.search.slowlog.threshold.query.info": "5s",
  "index.search.slowlog.threshold.query.debug": "2s",
  "index.search.slowlog.threshold.query.trace": "500ms",
  "index.indexing.slowlog.threshold.index.warn": "10s",
  "index.indexing.slowlog.threshold.index.info": "5s"
}

诊断工具

1. 热点线程分析

GET /_nodes/hot_threads

2. 任务管理

# 查看运行中的任务
GET /_tasks?detailed=true&group_by=parents

# 取消任务
POST /_tasks/task_id/_cancel

3. Profile API

GET /my_index/_search
{
  "profile": true,
  "query": {
    "match": {
      "content": "elasticsearch"
    }
  }
}

安全配置

基础安全设置

# elasticsearch.yml
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12

用户权限管理

# 创建用户
POST /_security/user/app_user
{
  "password": "password123",
  "roles": ["app_read", "app_write"],
  "full_name": "Application User"
}

# 创建角色
POST /_security/role/app_read
{
  "indices": [
    {
      "names": ["app-*"],
      "privileges": ["read"]
    }
  ]
}

故障恢复

常见故障处理

1. 集群状态红色

# 检查未分配的分片
GET /_cluster/allocation/explain

# 重新分配分片
POST /_cluster/reroute
{
  "commands": [
    {
      "allocate_replica": {
        "index": "my_index",
        "shard": 0,
        "node": "node-2"
      }
    }
  ]
}

2. 节点脱离集群

# 检查节点状态
GET /_nodes/stats

# 调整发现设置(ES 7.x)
PUT /_cluster/settings
{
  "persistent": {
    "discovery.seed_hosts": ["host1:9300", "host2:9300"],
    "cluster.initial_master_nodes": ["node-1", "node-2", "node-3"]
  }
}

相关文章

ELK Stack 完整部署

数据库技术对比

容器化部署

监控运维

大数据技术


总结

Elasticsearch 作为现代搜索和分析引擎的佼佼者,为海量数据的存储、搜索和分析提供了强大的解决方案:

🎯 核心优势

  • 分布式架构: 支持水平扩展,处理 PB 级数据
  • 近实时搜索: 数据写入后秒级即可搜索
  • 全文检索: 强大的文本分析和搜索能力
  • 聚合分析: 实时数据统计和多维分析
  • 生态完整: ELK Stack 提供完整解决方案

🛠️ 技术要点

  1. 部署方式: Docker 快速部署 + 集群扩展
  2. 索引设计: 合理的映射配置和分片策略
  3. 查询优化: 选择合适的查询类型和过滤策略
  4. 聚合分析: 灵活的指标统计和桶聚合
  5. 可视化: Kibana 丰富的图表和仪表板

🚀 应用场景

  • 日志分析: 系统日志、应用日志集中分析
  • 全文搜索: 网站搜索、文档检索系统
  • 监控告警: 实时监控和异常检测
  • 商业智能: 数据报表和业务分析

💡 最佳实践建议:

  • 根据数据量合理设置分片数量
  • 使用合适的分词器提高搜索精度
  • 监控集群健康状态和性能指标
  • 定期备份重要索引数据
  • 结合 Logstash 和 Beats 构建完整数据管道