ELK Stack中Elasticsearch单字段出现多值问题求助
I'm stuck on a confusing issue with my ELK Stack setup—tons of fields in my Elasticsearch index are showing up as multi-value arrays, even though the source data shouldn't have duplicate values. Here's what I'm seeing in the index:
records.Type:Event, Event, Event, Eventrecords.EventCategory:1, 1, 1, 1, 1, 1, 1records.EventLevelName:Success, Success, Success, Success, Success, Success, Success
My implementation is super simple with no complex parsing rules: I'm pulling logs from Event Hub via Logstash and storing them in Elasticsearch. The only Logstash filter I've configured is a basic json filter to parse the incoming message. Here's the exact filter config:
filter { json { add_tag => [ "EventHub" ] source => "message" remove_field => [ "message" ] } }
I've checked the raw logs coming from Event Hub, and there's no sign of duplicate values in those fields. I've also scoured through troubleshooting resources but haven't found anything that matches this scenario. Has anyone else run into this issue, or have any clues about what might be causing it?
内容的提问来源于stack exchange,提问作者h0llym0lly

