query_builder.test.ts 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564
  1. import { ElasticQueryBuilder } from '../query_builder';
  2. describe('ElasticQueryBuilder', () => {
  3. let builder: any;
  4. beforeEach(() => {
  5. builder = new ElasticQueryBuilder({ timeField: '@timestamp' });
  6. });
  7. it('with defaults', () => {
  8. const query = builder.build({
  9. metrics: [{ type: 'Count', id: '0' }],
  10. timeField: '@timestamp',
  11. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '1' }],
  12. });
  13. expect(query.query.bool.filter[0].range['@timestamp'].gte).toBe('$timeFrom');
  14. expect(query.aggs['1'].date_histogram.extended_bounds.min).toBe('$timeFrom');
  15. });
  16. it('with defaults on es5.x', () => {
  17. const builder5x = new ElasticQueryBuilder({
  18. timeField: '@timestamp',
  19. esVersion: 5,
  20. });
  21. const query = builder5x.build({
  22. metrics: [{ type: 'Count', id: '0' }],
  23. timeField: '@timestamp',
  24. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '1' }],
  25. });
  26. expect(query.query.bool.filter[0].range['@timestamp'].gte).toBe('$timeFrom');
  27. expect(query.aggs['1'].date_histogram.extended_bounds.min).toBe('$timeFrom');
  28. });
  29. it('with multiple bucket aggs', () => {
  30. const query = builder.build({
  31. metrics: [{ type: 'count', id: '1' }],
  32. timeField: '@timestamp',
  33. bucketAggs: [
  34. { type: 'terms', field: '@host', id: '2' },
  35. { type: 'date_histogram', field: '@timestamp', id: '3' },
  36. ],
  37. });
  38. expect(query.aggs['2'].terms.field).toBe('@host');
  39. expect(query.aggs['2'].aggs['3'].date_histogram.field).toBe('@timestamp');
  40. });
  41. it('with select field', () => {
  42. const query = builder.build(
  43. {
  44. metrics: [{ type: 'avg', field: '@value', id: '1' }],
  45. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '2' }],
  46. },
  47. 100,
  48. 1000
  49. );
  50. const aggs = query.aggs['2'].aggs;
  51. expect(aggs['1'].avg.field).toBe('@value');
  52. });
  53. it('with term agg and order by term', () => {
  54. const query = builder.build(
  55. {
  56. metrics: [{ type: 'count', id: '1' }, { type: 'avg', field: '@value', id: '5' }],
  57. bucketAggs: [
  58. {
  59. type: 'terms',
  60. field: '@host',
  61. settings: { size: 5, order: 'asc', orderBy: '_term' },
  62. id: '2',
  63. },
  64. { type: 'date_histogram', field: '@timestamp', id: '3' },
  65. ],
  66. },
  67. 100,
  68. 1000
  69. );
  70. const firstLevel = query.aggs['2'];
  71. expect(firstLevel.terms.order._term).toBe('asc');
  72. });
  73. it('with term agg and order by term on es6.x', () => {
  74. const builder6x = new ElasticQueryBuilder({
  75. timeField: '@timestamp',
  76. esVersion: 60,
  77. });
  78. const query = builder6x.build(
  79. {
  80. metrics: [{ type: 'count', id: '1' }, { type: 'avg', field: '@value', id: '5' }],
  81. bucketAggs: [
  82. {
  83. type: 'terms',
  84. field: '@host',
  85. settings: { size: 5, order: 'asc', orderBy: '_term' },
  86. id: '2',
  87. },
  88. { type: 'date_histogram', field: '@timestamp', id: '3' },
  89. ],
  90. },
  91. 100,
  92. // @ts-ignore
  93. 1000
  94. );
  95. const firstLevel = query.aggs['2'];
  96. expect(firstLevel.terms.order._key).toBe('asc');
  97. });
  98. it('with term agg and order by metric agg', () => {
  99. const query = builder.build(
  100. {
  101. metrics: [{ type: 'count', id: '1' }, { type: 'avg', field: '@value', id: '5' }],
  102. bucketAggs: [
  103. {
  104. type: 'terms',
  105. field: '@host',
  106. settings: { size: 5, order: 'asc', orderBy: '5' },
  107. id: '2',
  108. },
  109. { type: 'date_histogram', field: '@timestamp', id: '3' },
  110. ],
  111. },
  112. 100,
  113. 1000
  114. );
  115. const firstLevel = query.aggs['2'];
  116. const secondLevel = firstLevel.aggs['3'];
  117. expect(firstLevel.aggs['5'].avg.field).toBe('@value');
  118. expect(secondLevel.aggs['5'].avg.field).toBe('@value');
  119. });
  120. it('with metric percentiles', () => {
  121. const query = builder.build(
  122. {
  123. metrics: [
  124. {
  125. id: '1',
  126. type: 'percentiles',
  127. field: '@load_time',
  128. settings: {
  129. percents: [1, 2, 3, 4],
  130. },
  131. },
  132. ],
  133. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '3' }],
  134. },
  135. 100,
  136. 1000
  137. );
  138. const firstLevel = query.aggs['3'];
  139. expect(firstLevel.aggs['1'].percentiles.field).toBe('@load_time');
  140. expect(firstLevel.aggs['1'].percentiles.percents).toEqual([1, 2, 3, 4]);
  141. });
  142. it('with filters aggs', () => {
  143. const query = builder.build({
  144. metrics: [{ type: 'count', id: '1' }],
  145. timeField: '@timestamp',
  146. bucketAggs: [
  147. {
  148. id: '2',
  149. type: 'filters',
  150. settings: {
  151. filters: [{ query: '@metric:cpu' }, { query: '@metric:logins.count' }],
  152. },
  153. },
  154. { type: 'date_histogram', field: '@timestamp', id: '4' },
  155. ],
  156. });
  157. expect(query.aggs['2'].filters.filters['@metric:cpu'].query_string.query).toBe('@metric:cpu');
  158. expect(query.aggs['2'].filters.filters['@metric:logins.count'].query_string.query).toBe('@metric:logins.count');
  159. expect(query.aggs['2'].aggs['4'].date_histogram.field).toBe('@timestamp');
  160. });
  161. it('with filters aggs on es5.x', () => {
  162. const builder5x = new ElasticQueryBuilder({
  163. timeField: '@timestamp',
  164. esVersion: 5,
  165. });
  166. const query = builder5x.build({
  167. metrics: [{ type: 'count', id: '1' }],
  168. timeField: '@timestamp',
  169. bucketAggs: [
  170. {
  171. id: '2',
  172. type: 'filters',
  173. settings: {
  174. filters: [{ query: '@metric:cpu' }, { query: '@metric:logins.count' }],
  175. },
  176. },
  177. { type: 'date_histogram', field: '@timestamp', id: '4' },
  178. ],
  179. });
  180. expect(query.aggs['2'].filters.filters['@metric:cpu'].query_string.query).toBe('@metric:cpu');
  181. expect(query.aggs['2'].filters.filters['@metric:logins.count'].query_string.query).toBe('@metric:logins.count');
  182. expect(query.aggs['2'].aggs['4'].date_histogram.field).toBe('@timestamp');
  183. });
  184. it('with raw_document metric', () => {
  185. const query = builder.build({
  186. metrics: [{ type: 'raw_document', id: '1', settings: {} }],
  187. timeField: '@timestamp',
  188. bucketAggs: [],
  189. });
  190. expect(query.size).toBe(500);
  191. });
  192. it('with raw_document metric size set', () => {
  193. const query = builder.build({
  194. metrics: [{ type: 'raw_document', id: '1', settings: { size: 1337 } }],
  195. timeField: '@timestamp',
  196. bucketAggs: [],
  197. });
  198. expect(query.size).toBe(1337);
  199. });
  200. it('with moving average', () => {
  201. const query = builder.build({
  202. metrics: [
  203. {
  204. id: '3',
  205. type: 'sum',
  206. field: '@value',
  207. },
  208. {
  209. id: '2',
  210. type: 'moving_avg',
  211. field: '3',
  212. pipelineAgg: '3',
  213. },
  214. ],
  215. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '3' }],
  216. });
  217. const firstLevel = query.aggs['3'];
  218. expect(firstLevel.aggs['2']).not.toBe(undefined);
  219. expect(firstLevel.aggs['2'].moving_avg).not.toBe(undefined);
  220. expect(firstLevel.aggs['2'].moving_avg.buckets_path).toBe('3');
  221. });
  222. it('with moving average doc count', () => {
  223. const query = builder.build({
  224. metrics: [
  225. {
  226. id: '3',
  227. type: 'count',
  228. field: 'select field',
  229. },
  230. {
  231. id: '2',
  232. type: 'moving_avg',
  233. field: '3',
  234. pipelineAgg: '3',
  235. },
  236. ],
  237. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '4' }],
  238. });
  239. const firstLevel = query.aggs['4'];
  240. expect(firstLevel.aggs['2']).not.toBe(undefined);
  241. expect(firstLevel.aggs['2'].moving_avg).not.toBe(undefined);
  242. expect(firstLevel.aggs['2'].moving_avg.buckets_path).toBe('_count');
  243. });
  244. it('with broken moving average', () => {
  245. const query = builder.build({
  246. metrics: [
  247. {
  248. id: '3',
  249. type: 'sum',
  250. field: '@value',
  251. },
  252. {
  253. id: '2',
  254. type: 'moving_avg',
  255. pipelineAgg: '3',
  256. },
  257. {
  258. id: '4',
  259. type: 'moving_avg',
  260. pipelineAgg: 'Metric to apply moving average',
  261. },
  262. ],
  263. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '3' }],
  264. });
  265. const firstLevel = query.aggs['3'];
  266. expect(firstLevel.aggs['2']).not.toBe(undefined);
  267. expect(firstLevel.aggs['2'].moving_avg).not.toBe(undefined);
  268. expect(firstLevel.aggs['2'].moving_avg.buckets_path).toBe('3');
  269. expect(firstLevel.aggs['4']).toBe(undefined);
  270. });
  271. it('with derivative', () => {
  272. const query = builder.build({
  273. metrics: [
  274. {
  275. id: '3',
  276. type: 'sum',
  277. field: '@value',
  278. },
  279. {
  280. id: '2',
  281. type: 'derivative',
  282. pipelineAgg: '3',
  283. },
  284. ],
  285. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '3' }],
  286. });
  287. const firstLevel = query.aggs['3'];
  288. expect(firstLevel.aggs['2']).not.toBe(undefined);
  289. expect(firstLevel.aggs['2'].derivative).not.toBe(undefined);
  290. expect(firstLevel.aggs['2'].derivative.buckets_path).toBe('3');
  291. });
  292. it('with derivative doc count', () => {
  293. const query = builder.build({
  294. metrics: [
  295. {
  296. id: '3',
  297. type: 'count',
  298. field: 'select field',
  299. },
  300. {
  301. id: '2',
  302. type: 'derivative',
  303. pipelineAgg: '3',
  304. },
  305. ],
  306. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '4' }],
  307. });
  308. const firstLevel = query.aggs['4'];
  309. expect(firstLevel.aggs['2']).not.toBe(undefined);
  310. expect(firstLevel.aggs['2'].derivative).not.toBe(undefined);
  311. expect(firstLevel.aggs['2'].derivative.buckets_path).toBe('_count');
  312. });
  313. it('with bucket_script', () => {
  314. const query = builder.build({
  315. metrics: [
  316. {
  317. id: '1',
  318. type: 'sum',
  319. field: '@value',
  320. },
  321. {
  322. id: '3',
  323. type: 'max',
  324. field: '@value',
  325. },
  326. {
  327. field: 'select field',
  328. id: '4',
  329. meta: {},
  330. pipelineVariables: [
  331. {
  332. name: 'var1',
  333. pipelineAgg: '1',
  334. },
  335. {
  336. name: 'var2',
  337. pipelineAgg: '3',
  338. },
  339. ],
  340. settings: {
  341. script: 'params.var1 * params.var2',
  342. },
  343. type: 'bucket_script',
  344. },
  345. ],
  346. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '2' }],
  347. });
  348. const firstLevel = query.aggs['2'];
  349. expect(firstLevel.aggs['4']).not.toBe(undefined);
  350. expect(firstLevel.aggs['4'].bucket_script).not.toBe(undefined);
  351. expect(firstLevel.aggs['4'].bucket_script.buckets_path).toMatchObject({ var1: '1', var2: '3' });
  352. });
  353. it('with bucket_script doc count', () => {
  354. const query = builder.build({
  355. metrics: [
  356. {
  357. id: '3',
  358. type: 'count',
  359. field: 'select field',
  360. },
  361. {
  362. field: 'select field',
  363. id: '4',
  364. meta: {},
  365. pipelineVariables: [
  366. {
  367. name: 'var1',
  368. pipelineAgg: '3',
  369. },
  370. ],
  371. settings: {
  372. script: 'params.var1 * 1000',
  373. },
  374. type: 'bucket_script',
  375. },
  376. ],
  377. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '2' }],
  378. });
  379. const firstLevel = query.aggs['2'];
  380. expect(firstLevel.aggs['4']).not.toBe(undefined);
  381. expect(firstLevel.aggs['4'].bucket_script).not.toBe(undefined);
  382. expect(firstLevel.aggs['4'].bucket_script.buckets_path).toMatchObject({ var1: '_count' });
  383. });
  384. it('with histogram', () => {
  385. const query = builder.build({
  386. metrics: [{ id: '1', type: 'count' }],
  387. bucketAggs: [
  388. {
  389. type: 'histogram',
  390. field: 'bytes',
  391. id: '3',
  392. settings: { interval: 10, min_doc_count: 2, missing: 5 },
  393. },
  394. ],
  395. });
  396. const firstLevel = query.aggs['3'];
  397. expect(firstLevel.histogram.field).toBe('bytes');
  398. expect(firstLevel.histogram.interval).toBe(10);
  399. expect(firstLevel.histogram.min_doc_count).toBe(2);
  400. expect(firstLevel.histogram.missing).toBe(5);
  401. });
  402. it('with adhoc filters', () => {
  403. const query = builder.build(
  404. {
  405. metrics: [{ type: 'Count', id: '0' }],
  406. timeField: '@timestamp',
  407. bucketAggs: [{ type: 'date_histogram', field: '@timestamp', id: '3' }],
  408. },
  409. [
  410. { key: 'key1', operator: '=', value: 'value1' },
  411. { key: 'key2', operator: '=', value: 'value2' },
  412. { key: 'key2', operator: '!=', value: 'value2' },
  413. { key: 'key3', operator: '<', value: 'value3' },
  414. { key: 'key4', operator: '>', value: 'value4' },
  415. { key: 'key5', operator: '=~', value: 'value5' },
  416. { key: 'key6', operator: '!~', value: 'value6' },
  417. ]
  418. );
  419. expect(query.query.bool.must[0].match_phrase['key1'].query).toBe('value1');
  420. expect(query.query.bool.must[1].match_phrase['key2'].query).toBe('value2');
  421. expect(query.query.bool.must_not[0].match_phrase['key2'].query).toBe('value2');
  422. expect(query.query.bool.filter[2].range['key3'].lt).toBe('value3');
  423. expect(query.query.bool.filter[3].range['key4'].gt).toBe('value4');
  424. expect(query.query.bool.filter[4].regexp['key5']).toBe('value5');
  425. expect(query.query.bool.filter[5].bool.must_not.regexp['key6']).toBe('value6');
  426. });
  427. // terms query ES<6.0 - check ordering for _term and doc_type
  428. it('getTermsQuery(default case) es<6.0 should set asc sorting on _term', () => {
  429. const query = builder.getTermsQuery({});
  430. expect(query.aggs['1'].terms.order._term).toBe('asc');
  431. expect(query.aggs['1'].terms.order._key).toBeUndefined();
  432. expect(query.aggs['1'].terms.order._count).toBeUndefined();
  433. });
  434. it('getTermsQuery(order:desc) es<6.0 should set desc sorting on _term', () => {
  435. const query = builder.getTermsQuery({ order: 'desc' });
  436. expect(query.aggs['1'].terms.order._term).toBe('desc');
  437. expect(query.aggs['1'].terms.order._key).toBeUndefined();
  438. expect(query.aggs['1'].terms.order._count).toBeUndefined();
  439. });
  440. it('getTermsQuery(orderBy:doc_count) es<6.0 should set desc sorting on _count', () => {
  441. const query = builder.getTermsQuery({ orderBy: 'doc_count' });
  442. expect(query.aggs['1'].terms.order._term).toBeUndefined();
  443. expect(query.aggs['1'].terms.order._key).toBeUndefined();
  444. expect(query.aggs['1'].terms.order._count).toBe('desc');
  445. });
  446. it('getTermsQuery(orderBy:doc_count, order:asc) es<6.0 should set asc sorting on _count', () => {
  447. const query = builder.getTermsQuery({ orderBy: 'doc_count', order: 'asc' });
  448. expect(query.aggs['1'].terms.order._term).toBeUndefined();
  449. expect(query.aggs['1'].terms.order._key).toBeUndefined();
  450. expect(query.aggs['1'].terms.order._count).toBe('asc');
  451. });
  452. // terms query ES>=6.0 - check ordering for _key and doc_type
  453. it('getTermsQuery(default case) es6.x should set asc sorting on _key', () => {
  454. const builder6x = new ElasticQueryBuilder({
  455. timeField: '@timestamp',
  456. esVersion: 60,
  457. });
  458. const query = builder6x.getTermsQuery({});
  459. expect(query.aggs['1'].terms.order._term).toBeUndefined();
  460. expect(query.aggs['1'].terms.order._key).toBe('asc');
  461. expect(query.aggs['1'].terms.order._count).toBeUndefined();
  462. });
  463. it('getTermsQuery(order:desc) es6.x should set desc sorting on _key', () => {
  464. const builder6x = new ElasticQueryBuilder({
  465. timeField: '@timestamp',
  466. esVersion: 60,
  467. });
  468. const query = builder6x.getTermsQuery({ order: 'desc' });
  469. expect(query.aggs['1'].terms.order._term).toBeUndefined();
  470. expect(query.aggs['1'].terms.order._key).toBe('desc');
  471. expect(query.aggs['1'].terms.order._count).toBeUndefined();
  472. });
  473. it('getTermsQuery(orderBy:doc_count) es6.x should set desc sorting on _count', () => {
  474. const builder6x = new ElasticQueryBuilder({
  475. timeField: '@timestamp',
  476. esVersion: 60,
  477. });
  478. const query = builder6x.getTermsQuery({ orderBy: 'doc_count' });
  479. expect(query.aggs['1'].terms.order._term).toBeUndefined();
  480. expect(query.aggs['1'].terms.order._key).toBeUndefined();
  481. expect(query.aggs['1'].terms.order._count).toBe('desc');
  482. });
  483. it('getTermsQuery(orderBy:doc_count, order:asc) es6.x should set asc sorting on _count', () => {
  484. const builder6x = new ElasticQueryBuilder({
  485. timeField: '@timestamp',
  486. esVersion: 60,
  487. });
  488. const query = builder6x.getTermsQuery({ orderBy: 'doc_count', order: 'asc' });
  489. expect(query.aggs['1'].terms.order._term).toBeUndefined();
  490. expect(query.aggs['1'].terms.order._key).toBeUndefined();
  491. expect(query.aggs['1'].terms.order._count).toBe('asc');
  492. });
  493. // Logs query
  494. it('getTermsQuery should request documents and date histogram', () => {
  495. const query = builder.getLogsQuery({});
  496. expect(query).toHaveProperty('query.bool.filter');
  497. expect(query.aggs['2']).toHaveProperty('date_histogram');
  498. });
  499. });