如何在弹性搜索中将文档中的字数统计为随时间推移的总和?

How to get word count in docs as a aggregate over time in elastic search?

我正在尝试将文档中的字数统计趋势作为汇总结果。尽管使用以下方法我能够获得文档计数聚合结果,但我无法找到任何资源来获取 jan 、 feb 和 mar

月份的字数统计
PUT test/_doc/1
{
  "description" : "one two three four",
  "month" : "jan"

}
PUT test/_doc/2
{
  "description" : "one one test test test",
  "month" : "feb"

}

PUT test/_doc/3
{
  "description" : "one one one test",
  "month" : "mar"

}

GET test/_search
{
  "size": 0,
  "query": {
    "match": {
      "description": {
        "query": "one"
      }
    }
  },
  "aggs": {
    "monthly_count": {
      "terms": {
        "field": "month.keyword"
      }
    }
  }
}

输出

{
  "took" : 706,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 3,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : [ ]
  },
  "aggregations" : {
    "monthly_count" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "feb",
          "doc_count" : 1
        },
        {
          "key" : "jan",
          "doc_count" : 1
        },
        {
          "key" : "mar",
          "doc_count" : 1
        }
      ]
    }
  }
}

一个月的预期字数

"aggregations" : {
    "monthly_count" : {
      "buckets" : [
        {
          "key" : "feb",
          "word_count" : 2
        },
        {
          "key" : "jan",
          "word_count" : 1
        },
        {
          "key" : "mar",
          "word_count" : 3
        }
      ]
    }
  }

也许这个查询可以帮助您:

GET test/_search
{
  "size": 0,
  "aggs": {
    "monthly_count": {
      "terms": {
        "field": "month.keyword"
      },
      "aggs": {
        "count_word_one": {
          "terms": {
            "script": {
              "source": """
              def str = doc['description.keyword'].value;
              def array = str.splitOnToken(' ');
              int i = 0;
              for (item in array) {
                if(item == 'one'){
                  i++
                }
              }
              return i;
              """
            }, 
            "size": 10
          }
        }
      }
    }
  }
}

回复:

"aggregations" : {
    "monthly_count" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "feb",
          "doc_count" : 1,
          "count_word_one" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : "2",
                "doc_count" : 1
              }
            ]
          }
        },
        {
          "key" : "jan",
          "doc_count" : 1,
          "count_word_one" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : "1",
                "doc_count" : 1
              }
            ]
          }
        },
        {
          "key" : "mar",
          "doc_count" : 1,
          "count_word_one" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : "3",
                "doc_count" : 1
              }
            ]
          }
        }
      ]
    }
  }