I pass custom logs to elastocsearch using logstash
For example, the string "A+B=AB" contains the field name in "fields1".
If I search for "A+B=AB" literally, other fields containing A,B,AB are partially searched. This is my problem.
I will list the methods I would like to solve in order.
I know that the problem I have is because elasticsearch automatically analyzes the search terms, so can I pass the type of "fileds1" from logstash to elasticsearch as "keyword"?
After checking, the type of fields1 is automatically text.
When I searched a lot of documents, I found that the reserved words (+,-...) specified in elasticsearch are processed as blanks.
Is that correct?
Question 2 is suspicious. I searched "₩₩+" but nothing was found. As a workaround I found, you can replace "+" with a character like "plus" in logstash and pass it to Elastic.
However, I haven't been able to find a way to change it in Logstash, which function should I use to change it?