如何让Elastic.Serilog.Sinks强制使用已有索引?
问题描述
我从Serilog.Sinks.Elasticsearch包切换到Elastic.Serilog.Sinks后,遇到了索引写入异常的问题:
之前使用Serilog.Sinks.Elasticsearch时,通过以下配置可以正常将日志写入指定的qa-stem-backend-log索引:
string indexFormat = settings.IndexName; configuration .WriteTo.Elasticsearch(new ElasticsearchSinkOptions(new Uri(settings.ConnectionString)) { MinimumLogEventLevel = logLevel.Value, AutoRegisterTemplate = true, IndexFormat = indexFormat, // 指定目标索引名称 BatchAction = ElasticOpType.Create });
切换到Elastic.Serilog.Sinks后,我尝试通过DataStream指定索引,但日志并未写入已有索引,而是自动生成了类似.ds-qa-stem-backend-log-generic-default-2025.01.15-000001的隐藏索引,配置代码如下:
string indexFormat = settings.IndexName; configuration.WriteTo.Elasticsearch([new Uri(settings.ConnectionString)], options => { options.LevelSwitch = new() { MinimumLevel = logLevel.Value, }; options.DataStream = new DataStreamName(indexFormat); // 尝试设置索引名称 options.TextFormatting = new EcsTextFormatterConfiguration(); options.BootstrapMethod = BootstrapMethod.Failure; options.ConfigureChannel = channelOptions => { channelOptions.BufferOptions = new BufferOptions(); }; });
需要实现强制写入指定的已有索引,且不创建新的隐藏索引。
解决方案
核心原因是DataStream配置会让Sink默认写入Elasticsearch的数据流(Data Stream),而数据流的底层由隐藏时序索引组成,因此生成了.ds-开头的索引。要直接写入普通索引,只需将DataStream配置替换为Index选项即可:
修改后的配置代码:
string indexFormat = settings.IndexName; configuration.WriteTo.Elasticsearch([new Uri(settings.ConnectionString)], options => { options.LevelSwitch = new() { MinimumLevel = logLevel.Value, }; // 替换DataStream为Index配置,直接指定目标索引 options.Index = indexFormat; options.TextFormatting = new EcsTextFormatterConfiguration(); options.BootstrapMethod = BootstrapMethod.Failure; options.ConfigureChannel = channelOptions => { channelOptions.BufferOptions = new BufferOptions(); }; });
修改完成后,Sink会直接将日志写入你指定的qa-stem-backend-log索引,不会再自动创建数据流相关的隐藏索引。
内容的提问来源于stack exchange,提问作者Nick Farsi
相关产品推荐
相关产品推荐

