Elasticsearch:业务索引、映射与查询参数
服务端版本:7.17.6;本页列出开放索引的 mapping 与 alias。
业务索引按完整 mapping 内容分组,相同结构只列一次;月份仍逐一保留以便核对类型漂移。其他系统、监控和归属未明索引仅登记名称,不展开非业务的字段。字段索引、物理索引名、分片数含义不同,业务条件见查询与分区指南。
索引用途与数据来源
| 索引族 | 存什么、怎么来 | 查询时注意 |
|---|---|---|
| base_device | 设备档案的检索副本,由设备登记、激活及档案更新同步;支持按设备、渠道、型号等筛选大批设备 | 精确标识使用实际 keyword 字段;MySQL 档案与 ES 可能有同步延迟 |
| app_install_deviceYYYYMM | 设备上报的当月安装应用快照,经同步形成月索引;回答“该月最近上报装了什么” | 先选月份;apps 为整份 JSON 字符串,不能按 nested 应用对象查询;不能还原任意历史时点 |
| apk_push_history | 设备应用推送历史及卸载反馈的检索副本,来自历史写入后的同步或补同步 | 设备、包名和时间共同限定;多次推送保留多条;不承担 MySQL 唯一约束 |
APP 运行时长和打开次数的当前明细位于 TDengine flow_app_runtime,不能将安装快照当成运行记录。物理字段和参数见下表; 中文释义为业务解释,不是 ES 原生字段注释。
| 业务索引 | 字段路径数 | 别名 | mapping 分组 |
|---|---|---|---|
| apk_push_history | 9 | apk_push_history_alias | 结构 |
| app_install_device | 9 | 无 | 结构 |
| app_install_device202503 | 9 | ee_default_alias | 结构 |
| app_install_device202504 | 9 | ee_default_alias | 结构 |
| app_install_device202505 | 9 | ee_default_alias | 结构 |
| app_install_device202506 | 9 | ee_default_alias | 结构 |
| app_install_device202507 | 9 | ee_default_alias | 结构 |
| app_install_device202508 | 9 | ee_default_alias | 结构 |
| app_install_device202509 | 9 | ee_default_alias | 结构 |
| app_install_device202510 | 9 | ee_default_alias | 结构 |
| app_install_device202511 | 9 | ee_default_alias | 结构 |
| app_install_device202512 | 9 | ee_default_alias | 结构 |
| app_install_device202601 | 18 | ee_default_alias | 结构 |
| app_install_device202602 | 13 | 无 | 结构 |
| app_install_device202603 | 13 | 无 | 结构 |
| app_install_device202604 | 13 | 无 | 结构 |
| app_install_device202605 | 13 | 无 | 结构 |
| app_install_device202606 | 13 | 无 | 结构 |
| app_install_device202607 | 13 | 无 | 结构 |
| app_install_device202608 | 13 | 无 | 结构 |
| app_install_device202609 | 13 | 无 | 结构 |
| app_install_device_s0 | 9 | ee_default_alias | 结构 |
| base_device | 48 | ee_default_alias | 结构 |
APK 推送历史字段(mapping-1)
适用索引:apk_push_history。
映射顶层选项:{}。
| 字段路径(含 multi-field) | 类型 | 实际 mapping 参数 业务释义 | | --- | --- | --- --- | | cpuid | keyword | {"type": "keyword"} 设备CPU标识 | | id | long | {"type": "long"} 对应业务记录编号 | | mac | text | {"analyzer": "mac_analyzer", "type": "text"} 设备MAC | | mac.keyword | keyword | {"ignore_above": 255, "type": "keyword"} 设备MAC;完整值检索子字段 | | package_name | text | {"analyzer": "standard", "type": "text"} 应用包名 | | package_name.keyword | keyword | {"ignore_above": 255, "type": "keyword"} 应用包名;完整值检索子字段 | | push_task_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 推送时间 | | uninstall_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 卸载反馈时间 | | version_code | long | {"type": "long"} 应用版本号 |
安装快照字段(mapping-2)
适用索引:app_install_device、app_install_device202503、app_install_device202504、app_install_device202505、app_install_device202506、app_install_device202508、app_install_device202509、app_install_device202510、app_install_device202511、app_install_device202512、app_install_device_s0。
映射顶层选项:{}。
| 字段路径(含 multi-field) | 类型 | 实际 mapping 参数 业务释义 | | --- | --- | --- --- | | app_count | long | {"type": "long"} 安装应用数量 | | apps | text | {"analyzer": "ik_max_word", "type": "text"} 安装应用集合的JSON字符串 | | apps.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 安装应用集合的JSON字符串;完整值检索子字段 | | cpu_id | keyword | {"type": "keyword"} 设备CPU标识 | | create_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录创建时间 | | last_undate_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 设备采集安装列表的时间 | | mac | text | {"analyzer": "standard", "type": "text"} 设备MAC | | mac.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备MAC;完整值检索子字段 | | update_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录更新时间 |
安装快照字段(mapping-3)
适用索引:app_install_device202507。
映射顶层选项:{}。
| 字段路径(含 multi-field) | 类型 | 实际 mapping 参数 业务释义 | | --- | --- | --- --- | | app_count | long | {"type": "long"} 安装应用数量 | | apps | text | {"analyzer": "ik_max_word", "type": "text"} 安装应用集合的JSON字符串 | | apps.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 安装应用集合的JSON字符串;完整值检索子字段 | | cpu_id | keyword | {"type": "keyword"} 设备CPU标识 | | create_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录创建时间 | | last_undate_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 设备采集安装列表的时间 | | mac | text | {"analyzer": "mac_analyzer", "type": "text"} 设备MAC | | mac.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备MAC;完整值检索子字段 | | update_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录更新时间 |
安装快照字段(mapping-4)
适用索引:app_install_device202601。
映射顶层选项:{}。
| 字段路径(含 multi-field) | 类型 | 实际 mapping 参数 业务释义 | | --- | --- | --- --- | | appCount | long | {"type": "long"} 中文含义待核验 | | app_count | long | {"type": "long"} 安装应用数量 | | apps | text | {"analyzer": "ik_max_word", "type": "text"} 安装应用集合的JSON字符串 | | apps.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 安装应用集合的JSON字符串;完整值检索子字段 | | cpuId | text | {"type": "text"} 中文含义待核验 | | cpuId.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | cpu_id | keyword | {"type": "keyword"} 设备CPU标识 | | createTime | text | {"type": "text"} 中文含义待核验 | | createTime.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | create_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录创建时间 | | lastUndateTime | text | {"type": "text"} 中文含义待核验 | | lastUndateTime.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | last_undate_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 设备采集安装列表的时间 | | mac | text | {"analyzer": "standard", "type": "text"} 设备MAC | | mac.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备MAC;完整值检索子字段 | | updateTime | text | {"type": "text"} 中文含义待核验 | | updateTime.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | update_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录更新时间 |
安装快照字段(mapping-5)
适用索引:app_install_device202602、app_install_device202603、app_install_device202604、app_install_device202605、app_install_device202606、app_install_device202607、app_install_device202608、app_install_device202609。
映射顶层选项:{}。
| 字段路径(含 multi-field) | 类型 | 实际 mapping 参数 业务释义 | | --- | --- | --- --- | | app_count | long | {"type": "long"} 安装应用数量 | | apps | text | {"type": "text"} 安装应用集合的JSON字符串 | | apps.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 安装应用集合的JSON字符串;完整值检索子字段 | | cpu_id | text | {"type": "text"} 设备CPU标识 | | cpu_id.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备CPU标识;完整值检索子字段 | | create_time | text | {"type": "text"} 记录创建时间 | | create_time.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 记录创建时间;完整值检索子字段 | | last_undate_time | text | {"type": "text"} 设备采集安装列表的时间 | | last_undate_time.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备采集安装列表的时间;完整值检索子字段 | | mac | text | {"type": "text"} 设备MAC | | mac.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备MAC;完整值检索子字段 | | update_time | text | {"type": "text"} 记录更新时间 | | update_time.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 记录更新时间;完整值检索子字段 |
设备档案字段(mapping-6)
适用索引:base_device。
映射顶层选项:{}。
| 字段路径(含 multi-field) | 类型 | 实际 mapping 参数 业务释义 | | --- | --- | --- --- | | activation_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 首次激活时间 | | brand | keyword | {"type": "keyword"} 中文含义待核验 | | build | text | {"analyzer": "standard", "type": "text"} 中文含义待核验 | | build.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | certification | keyword | {"type": "keyword"} 中文含义待核验 | | channel_id | long | {"type": "long"} 渠道编号 | | channel_name | text | {"analyzer": "ik_max_word", "type": "text"} 中文含义待核验 | | channel_name.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | company_id | integer | {"type": "integer"} 中文含义待核验 | | cpu | keyword | {"type": "keyword"} 设备CPU标识 | | create_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录创建时间 | | ddr | keyword | {"type": "keyword"} 中文含义待核验 | | deleted | boolean | {"type": "boolean"} 中文含义待核验 | | device_ip | text | {"analyzer": "standard", "type": "text"} 中文含义待核验 | | device_ip.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | device_model | text | {"analyzer": "ik_max_word", "type": "text"} 中文含义待核验 | | device_model.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | excel_file_ids | keyword | {"type": "keyword"} 中文含义待核验 | | ip_address | text | {"analyzer": "ik_max_word", "type": "text"} 中文含义待核验 | | ip_address.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | mac | text | {"analyzer": "mac_analyzer", "type": "text"} 设备MAC | | mac.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 设备MAC;完整值检索子字段 | | master_model | text | {"type": "text"} 中文含义待核验 | | master_model.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | model_id | integer | {"type": "integer"} 设备型号编号 | | name | text | {"analyzer": "standard", "type": "text"} 中文含义待核验 | | name.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 中文含义待核验;完整值检索子字段 | | order_number | keyword | {"type": "keyword"} 订单号 | | pcb_model | text | {"type": "text"} PCB型号 | | pcb_model.keyword | keyword | {"ignore_above": 256, "type": "keyword"} PCB型号;完整值检索子字段 | | production_order | text | {"type": "text"} 生产订单 | | production_order.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 生产订单;完整值检索子字段 | | real_ddr | text | {"type": "text"} 实际内存规格 | | real_ddr.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 实际内存规格;完整值检索子字段 | | real_flash | text | {"type": "text"} 实际存储规格 | | real_flash.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 实际存储规格;完整值检索子字段 | | region_id | long | {"type": "long"} 地区编号 | | remarks | keyword | {"type": "keyword"} 备注 | | sdk_version_name | text | {"analyzer": "standard", "type": "text"} SDK版本名称 | | sdk_version_name.keyword | keyword | {"ignore_above": 256, "type": "keyword"} SDK版本名称;完整值检索子字段 | | serial_number | keyword | {"type": "keyword"} 设备序列号 | | status | integer | {"type": "integer"} 设备状态,取值以业务字典为准 | | system_version | text | {"analyzer": "standard", "type": "text"} 系统版本 | | system_version.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 系统版本;完整值检索子字段 | | ui | text | {"analyzer": "ik_max_word", "type": "text"} 界面版本或标识 | | ui.keyword | keyword | {"ignore_above": 256, "type": "keyword"} 界面版本或标识;完整值检索子字段 | | update_time | date | {"format": "yyyy-MM-dd HH:mm:ss", "type": "date"} 记录更新时间 | | user_id | long | {"type": "long"} 关联用户编号 |
分片、分析器与排序设置
| 索引 | 主分片 | 副本 | mac_analyzer | 显式 index.sort |
|---|---|---|---|---|
| apk_push_history | 1 | 0 | pattern,分隔符冒号 | {} |
| app_install_device | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202503 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202504 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202505 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202506 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202507 | 1 | 0 | pattern,分隔符冒号 | {} |
| app_install_device202508 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202509 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202510 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202511 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202512 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202601 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202602 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202603 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202604 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202605 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202606 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202607 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202608 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device202609 | 1 | 1 | pattern,分隔符冒号 | {} |
| app_install_device_s0 | 1 | 1 | 未返回 | {} |
| base_device | 1 | 0 | pattern,分隔符冒号 | {} |
节点分配策略为 index.routing.allocation.include._tier_preference=data_content。大批量检索应设置稳定排序并分批读取;跨月份查询先限定目标索引和日期范围。
其他开放索引:仅登记范围
| 索引 | 别名 |
|---|---|
| .apm-agent-configuration | 无 |
| .apm-custom-link | 无 |
| .async-search | 无 |
| .fleet-policies-7 | .fleet-policies |
| .items-default-000001 | .items-default |
| .kibana_7.17.6_001 | .kibana, .kibana_7.17.6 |
| .kibana_task_manager_7.17.6_001 | .kibana_task_manager, .kibana_task_manager_7.17.6 |
| .lists-default-000001 | .lists-default |
| .metrics-endpoint.metadata_united_default | 无 |
| .security-7 | .security |
| .tasks | 无 |
| .transform-internal-007 | .data-frame-internal-3 |
| document_s1 | ee_default_alias |
| ee-distribute-lock | 无 |
| metrics-endpoint.metadata_current_default | 无 |
| sw_browser_error_log-20250701 | sw_browser_error_log |
| sw_browser_error_log-20250702 | sw_browser_error_log |
| sw_log-20250701 | sw_log |
| sw_log-20250702 | sw_log |
| sw_management | 无 |
| sw_metrics-all-20250701 | sw_metrics-all |
| sw_metrics-all-20250702 | sw_metrics-all |
| sw_records-all-20250701 | sw_records-all |
| sw_records-all-20250702 | sw_records-all |
| sw_segment-20250701 | sw_segment |
| sw_segment-20250702 | sw_segment |
| sw_zipkin_span-20250701 | sw_zipkin_span |
| sw_zipkin_span-20250702 | sw_zipkin_span |
ee_default_alias 成员既包含业务月份索引,也包含 document_s1,且未覆盖全部已存在月份。历史查询应按目标月份明确选择索引,避免遗漏月份或混入其他对象。上方两张清单列出开放索引的别名成员关系。