Suggested mappings for highly structured data

Hello. I have over a trillion documents that are similar to the following:

    "ip": "",
    "mac_address": "00:0a:95:9d:68:16",
    "email_address": "",
    "url": "",
    "phone": "111-111-1111",
    "count": 9000,
    "message": "A really interesting messaging containing a lot of text"

I am going to want to query my data using any one of these fields. I will also want to be able to write queries where I can find out if any field contains, starts with, or ends with with they term searched on.

I am looking suggestions on what mapping, analyzers, normalizers, and tokenizers I should use.


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.