-
Notifications
You must be signed in to change notification settings - Fork 692
[DOC] Create Dashboards quickstart #2409
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 10 commits
Commits
Show all changes
146 commits
Select commit
Hold shift + click to select a range
faf423e
Create Dashboards quickstart
vagimeli 70dacab
Create new pages
vagimeli 6d7adf2
Create pages
vagimeli dcb2a1f
Add new content and pages
vagimeli 477cb49
Move DQL page and copy edit
vagimeli 26cea8d
Add more content
vagimeli 37505f5
Add more content
vagimeli 8ac263c
Continue writing
vagimeli 31329c9
Send out first pass draft
vagimeli 6fec96d
Address tech review
vagimeli 06fc26c
Update _dashboards/get-started/dql.md
vagimeli bb7f3be
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli 8f15e8d
Update _dashboards/get-started/dql.md
vagimeli b668580
Update _dashboards/get-started/dql.md
vagimeli 39fa3b9
Add new Rules documentation that covers YAML Editor view (#2407)
cwillum 38eaa6b
Update opensearch-documentation-release-notes-2.4.0.md (#2406)
hdhalter b5e4383
Adds documentation for Admin UI index operations (#2403)
ariamarble 41217aa
Fixes allow_partial_pit_creation (#2411)
kolchfa-aws 6a69d19
Adds border to images (#2415)
kolchfa-aws c36ae65
Adds Jaeger trace data for analytics documentation (#2374)
alicejw1 21f0d00
Adds maps documentation (#2376)
kolchfa-aws 161fbd7
Updates to Security Analytics documentation (#2408)
cwillum c3f3fe7
Add GPU acceleration documentation (#2384)
Naarcha-AWS 1faeaf5
Adds cluster health by awareness attribute documentation (#2398)
kolchfa-aws 80e7599
Updates remote-backed storage documentation (#2363)
kolchfa-aws de36e45
Move pages (#2425)
vagimeli 056df67
Add Query String for rollups (#2428)
Naarcha-AWS 6603ab4
Adds query string query documentation (#2427)
kolchfa-aws 07cf3e4
Editorial for Admin UI index operations (#2421)
ariamarble 2cfbe3c
Admin UI further editorial updates (#2444)
ariamarble 8947b7e
Adds second image style with no border (#2445)
kolchfa-aws 7f84872
Adds installation guide for OpenSearch Dashboards debian distribution…
e58ad65
Update field mapping documentation for Security Analytics (#2422)
cwillum 9ca2980
Minor changes to Data Prepper index.md. (#2426)
carolxob 0f451f7
Editorial changes (#2454)
055f269
add two new settings for Anomaly Detection 2.5 (#2450)
amitgalitz b0d20fe
Add new ML cluster settings for 2.5 (#2442)
Naarcha-AWS c5cf556
Remove Install and Configure home page (#2449)
Naarcha-AWS 891be1f
Add cluster awareness and decommission docs (#2438)
Naarcha-AWS ef69c95
Adds generated documentation to clients (#2458)
kolchfa-aws 94a2f52
Fix links for 2.5 doc changes. (#2465)
Naarcha-AWS 20d4c55
Add k-NN filter to neural search (#2466)
Naarcha-AWS 30d65e2
Adds release notes 2.5 (#2441)
kolchfa-aws 8b93fd7
Fix typo in Neural Search (#2468)
Naarcha-AWS 96f127a
Adds version history 2.5 (#2437)
kolchfa-aws 7998786
Adds 2.5.0 version (#2436)
kolchfa-aws d7fb1ba
Rewords release notes header (#2470)
kolchfa-aws e427f8f
Updates table format for version history (#2480)
kolchfa-aws b4bb86a
Add Monitoring to doc website repo (#2018)
carolxob ba735f0
Update docker.md (#2375)
justinhyou 6f0a3c5
Add additional ML cluster settings (#2487)
Naarcha-AWS e402ebd
Adds UI text guidance to style guide (#2495)
natebower cc5f4a7
Adjusts spacing (#2496)
natebower 7693322
Address tech and doc reviewer feedback
vagimeli 7c47d0a
Address tech and doc review feedback
vagimeli ef4c78a
Address tech and doc review comments
vagimeli 57d75ed
Copy edits
vagimeli a601948
Copy edits
vagimeli 2f663bc
Copy edits
vagimeli e1efc70
Copy edits
vagimeli 674f779
Address tech review feedback
vagimeli 745a456
Continue updating for accuracy
vagimeli 350b046
address tech and doc review
vagimeli 47f149c
Finalize for editorial review
vagimeli 88c15c7
Revert "Adjusts spacing (#2496)"
vagimeli c6784ca
Revert "Adds UI text guidance to style guide (#2495)"
vagimeli cc24181
Revert "Add additional ML cluster settings (#2487)"
vagimeli 051c873
Copy edits
vagimeli d4b9898
Revert "Update docker.md (#2375)"
vagimeli 8127367
Revert "Add Monitoring to doc website repo (#2018)"
vagimeli 102fb59
Revert "Updates table format for version history (#2480)"
vagimeli 4bc2470
Revert "Rewords release notes header (#2470)"
vagimeli 50ac195
Revert "Adds 2.5.0 version (#2436)"
vagimeli 0e6594d
Revert "Adds version history 2.5 (#2437)"
vagimeli 459b702
Revert "Fix typo in Neural Search (#2468)"
vagimeli d4ea485
Revert "Adds release notes 2.5 (#2441)"
vagimeli b1f34ae
Revert "Add k-NN filter to neural search (#2466)"
vagimeli 7363e7b
Revert "Fix links for 2.5 doc changes. (#2465)"
vagimeli cc51c26
Revert "Adds generated documentation to clients (#2458)"
vagimeli 1ef8ff9
Revert "Add cluster awareness and decommission docs (#2438)"
vagimeli afe92d9
Revert "Remove Install and Configure home page (#2449)"
vagimeli 62b1332
Revert "Add new ML cluster settings for 2.5 (#2442)"
vagimeli c2a3f64
Revert "add two new settings for Anomaly Detection 2.5 (#2450)"
vagimeli 65a5d20
Revert "Editorial changes (#2454)"
vagimeli 97aaf3f
Revert "Minor changes to Data Prepper index.md. (#2426)"
vagimeli 574d924
Revert "Update field mapping documentation for Security Analytics (#2…
vagimeli 2f00e96
Revert "Adds installation guide for OpenSearch Dashboards debian dist…
vagimeli 97e0644
Revert "Adds second image style with no border (#2445)"
vagimeli ab12816
Revert "Admin UI further editorial updates (#2444)"
vagimeli cf48642
Revert "Editorial for Admin UI index operations (#2421)"
vagimeli e4d4db1
Revert "Adds query string query documentation (#2427)"
vagimeli 05d49e7
Revert "Add Query String for rollups (#2428)"
vagimeli be89411
Revert "Adds cluster health by awareness attribute documentation (#23…
vagimeli 52092ba
Revert "Updates remote-backed storage documentation (#2363)"
vagimeli b70cffd
Revert "Updates to Security Analytics documentation (#2408)"
vagimeli cf64b30
Revert "Adds maps documentation (#2376)"
vagimeli 300e4c7
Revert "Adds Jaeger trace data for analytics documentation (#2374)"
vagimeli f7b789b
Revert "Adds border to images (#2415)"
vagimeli 22e1f90
Revert "Fixes allow_partial_pit_creation (#2411)"
vagimeli 689a01f
Revert "Adds documentation for Admin UI index operations (#2403)"
vagimeli b79ef74
Revert "Update opensearch-documentation-release-notes-2.4.0.md (#2406)"
vagimeli 73ae37b
Revert "Add new Rules documentation that covers YAML Editor view (#24…
vagimeli c57a9b8
Final doc review feedback
vagimeli 94fe97b
Update _dashboards/get-started/dql.md
vagimeli fe010c1
Update _dashboards/get-started/dql.md
vagimeli 41f013e
Update _dashboards/get-started/dql.md
vagimeli a2d81f0
Update _dashboards/get-started/dql.md
vagimeli b70390f
Revert "Add GPU acceleration documentation (#2384)"
vagimeli 52d424f
Address final doc review feedback
vagimeli abcde81
Copy edits
vagimeli 0a55b3c
Scroll to top when last visit was more than 24 hours ago (#2457)
kolchfa-aws 057d418
Makes version selector sticky (#2492)
kolchfa-aws c7a03b2
Copy edits
vagimeli e707aac
Copy edits
vagimeli 94f7186
Finalize for editorial review
vagimeli b71c337
Revert "Scroll to top when last visit was more than 24 hours ago (#24…
vagimeli e64fe9f
Revert "Makes version selector sticky (#2492)"
vagimeli 25a1a72
Delete getting started page; replace with Quickstart page
vagimeli df36658
Update _dashboards/get-started/dql.md
vagimeli c47067d
Update _dashboards/get-started/dql.md
vagimeli 702e3a5
Update _dashboards/get-started/dql.md
vagimeli f801bb9
Update _dashboards/get-started/dql.md
vagimeli b04fff2
Update _dashboards/get-started/dql.md
vagimeli 529e7b0
Update _dashboards/get-started/dql.md
vagimeli 131d188
Update _dashboards/get-started/dql.md
vagimeli fa625f8
Update _dashboards/get-started/dql.md
vagimeli 7c2d6bb
Update _dashboards/get-started/dql.md
vagimeli ed04527
Update _dashboards/get-started/dql.md
vagimeli daaed6b
Update _dashboards/get-started/dql.md
vagimeli 76e6696
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli 71b04dc
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli c8f15c2
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli ffcee49
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli 4c0dece
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli 4c2486f
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli 405ff73
Update _dashboards/get-started/quickstart-dashboards.md
vagimeli 49d879e
Address editorial feedback
vagimeli 5416bbc
Delete gantt.md
vagimeli f27a038
Delete visbuilder.md
vagimeli a8cc4f5
Move images to dashboards images folder
vagimeli c82ebac
Address editorial feedback
vagimeli 3017b48
Re-review for editorial
vagimeli 2932dd6
Move page to Discover section
vagimeli 2ebe099
Remove core concepts page; gloassry to be created
vagimeli 08d6e5a
Remove core concepts page; gloassry to be created
vagimeli 821af03
Update sample data graphic
vagimeli File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| --- | ||
| layout: default | ||
| title: OpenSearch Dashboards core concepts | ||
| nav_order: 30 | ||
| has_children: true | ||
| --- | ||
|
|
||
| # OpenSearch Dashboards core concepts |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,134 @@ | ||
| --- | ||
| layout: default | ||
| title: Dashboards Query Language | ||
| parent: OpenSearch Dashboards core concepts | ||
| nav_order: 40 | ||
| redirect_from: | ||
| - /dashboards/dql/ | ||
| --- | ||
|
|
||
| # Dashboards Query Language | ||
|
|
||
| Dashboards Query Language (DQL) is a simple text-based query language for filtering data in OpenSearch Dashboards. Similar to [Query DSL]({{site.url}}{{site.baseurl}}/opensearch/query-dsl/index), DQL uses HTTP request body. For example, to display your site visitor data for a host in the United States, you would enter `geo.dest:US` into the search field. | ||
|
|
||
| This documentation uses the Dashboards web log sample data set. See [Quickstart for OpenSearch Dashboards]() to learn how to add sample data to Dashboards. | ||
| {: .note} | ||
|
|
||
| ## Terms query | ||
|
|
||
| The most basic query is to specify the search term. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| host:www.example.com | ||
| ``` | ||
|
|
||
| To access an object's nested field, list the complete path to the field separated by periods. For example, to retrieve the `lat` field in the `coordinates` object: | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| coordinates.lat:43.7102 | ||
| ``` | ||
|
|
||
| DQL supports leading and trailing wildcards, so you can search for any terms that match your pattern. | ||
|
|
||
| ``` | ||
| host.keyword:*.example.com/* | ||
| ``` | ||
|
|
||
| To check if a field exists or has any data, use a wildcard to see if Dashboards returns any results. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| host.keyword:* | ||
| ``` | ||
|
|
||
| ## Boolean query | ||
|
|
||
| To mix and match or combine multiple queries for more refined results, you can use the boolean operators `and`, `or`, and `not`. DQL is not case sensitive, so `AND` and `and` are the same. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| host.keyword:www.example.com and response.keyword:200 | ||
|
vagimeli marked this conversation as resolved.
|
||
| ``` | ||
|
|
||
| The following example shows how to use multiple operators in one query. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| geo.dest:US or response.keyword:200 and host.keyword:www.example.com | ||
| ``` | ||
|
|
||
| Remember that boolean operators follow the logical precedence order of `not`, `and`, and `or`, so if you have an expression like the previous example, `response.keyword:200 and host.keyword:www.example.com` gets evaluated first, and then Dashboards uses that result to compare with `geo.dest:US`. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| To avoid confusion, use parentheses to dictate the order in which you want to evaluate. If you want to evaluate `geo.dest:US or response.keyword:200` first, the expression is: | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| (geo.dest:US or response.keyword:200) and host.keyword:www.example.com | ||
| ``` | ||
|
|
||
| ## Date and range queries | ||
|
|
||
| DQL supports numeric inequalities. | ||
|
|
||
| ``` | ||
| bytes >= 15 and memory < 15 | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
| ``` | ||
|
|
||
| Similarly, you can use the same method to find a date before or after the query. `>` indicates a search for a date after the specified date, and `<` returns dates before. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| @timestamp > "2020-12-14T09:35:33" | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
| ``` | ||
|
|
||
| ## Nested field query | ||
|
|
||
| If you have a document with nested fields, you must specify which parts of the document to retrieve. | ||
|
|
||
| For example, if you have the following document: | ||
|
|
||
| ```json | ||
| { | ||
| "superheroes":[ | ||
| { | ||
| "hero-name": "Superman", | ||
| "real-identity": "Clark Kent", | ||
| "age": 28 | ||
| }, | ||
| { | ||
| "hero-name": "Batman", | ||
| "real-identity": "Bruce Wayne", | ||
| "age": 26 | ||
| }, | ||
| { | ||
| "hero-name": "Flash", | ||
| "real-identity": "Barry Allen", | ||
| "age": 28 | ||
| }, | ||
| { | ||
| "hero-name": "Robin", | ||
| "real-identity": "Dick Grayson", | ||
| "age": 15 | ||
| } | ||
| ] | ||
| } | ||
| ``` | ||
|
|
||
| The following example shows how to use DQL to retrieve a specific field. | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
|
|
||
| ``` | ||
| superheroes: {hero-name: Superman} | ||
| ``` | ||
|
|
||
| If you want to retrieve multiple objects from your document, specify all the fields you want to retrieve. | ||
|
|
||
| ``` | ||
| superheroes: {hero-name: Superman} and superheroes: {hero-name: Batman} | ||
| ``` | ||
|
|
||
| The previous boolean and range queries still work, so you can submit a more refined query. | ||
|
|
||
| ``` | ||
| superheroes: {hero-name: Superman and age < 50} | ||
| ``` | ||
|
|
||
| If your document has an object nested within another object, you can retrieve data by specifying all the levels. | ||
|
|
||
| ``` | ||
| justice-league.superheroes: {hero-name:Superman} | ||
|
vagimeli marked this conversation as resolved.
Outdated
|
||
| ``` | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.