Elasticsearch terms aggregation and querying
问题 I have two types of log messages: Jul 23 09:24:16 rrr mrr-core[222]: Aweg3AOMTs_1563866656871111.mt processMTMessage() #12798 realtime: 5.684 ms Jul 23 09:24:18 rrr mrr-core[2222]: Aweg3AOMTs_1563866656871111.0.dn processDN() #7750 realtime: 1.382 ms The first message is kind of sent message and second is message which confirm that message was delivered. The difference between them is the suffix which I have separated from "id" and can query it. These messages are parsed and stored in