You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ELK FileBeat配置异常:Pipeline未生效问题修复

问题描述

在同一filebeat.yml中配置了多个AWS CloudWatch输入及对应索引,Pipeline测试无报错且能成功解析文档ID,但Pipeline并未执行,Kibana中无法看到处理后的字段。

原配置

#=========================== Filebeat inputs =============================
filebeat.inputs:
- type: aws-cloudwatch
  enabled: true
  access_key_id: "xxxxxxxxxxxxx"
  secret_access_key: "xxxxxxxxxxxx"
  region_name: "xxxxxxxxx"
  log_group_arn: "arn:aws:logs:xxxxxxxx:apache_logs"
  log_group_name: "xxxxxxxxx/apache"
  fields:
    name: "prod-cloudwatch_apache_logs"
  ignore_older: 720h
  start_position: end
- type: aws-cloudwatch
  enabled: true
  access_key_id: "xxxxxxxxxxxxx"
  secret_access_key: "xxxxxxxxxxxx"
  region_name: "xxxxxxxxx"
  log_group_arn: "arn:aws:logs:xxxxxxxx:apache_logs"
  log_group_name: "xxxxxxxxx/apache"
  fields:
    name: "uat-cloudwatch_apache_logs"
  ignore_older: 720h
  start_position: end

output.elasticsearch:
  hosts: ["https://xxxxxxx.aws.elastic-cloud.com:xxxxxx"]
  protocol: "https"
  username: "${ESUSER}"
  password: "${ESPASS}"
  output.elasticsearch.allow_older_versions: true
  indices:
   - index: "cloudwatch_uat_apache_logs-%{+yyyy.MM}"
     when.contains:
      fields.name: "uat-cloudwatch_apache_logs"
   - index: "cloudwatch_prod_apache_logs%{+yyyy.MM}"
     when.contains:
      fields.name: "prod-cloudwatch_apache_logs"
  pipelines:
    - pipeline: "apache_pipeline"
      when:
       has_fields: ['name.prod-cloudwatch_apache_logs']

配置错误分析与修复方案

  • Pipeline匹配条件错误:原条件写法无效,需通过fields.name的值匹配,同时覆盖UAT环境;
  • 参数缩进错误:allow_older_versions应与hosts等同级,无需重复嵌套output.elasticsearch前缀;
  • 索引格式不一致:Prod索引名缺少连接符-,需统一格式。

修复后的配置

#=========================== Filebeat inputs =============================
filebeat.inputs:
- type: aws-cloudwatch
  enabled: true
  access_key_id: "xxxxxxxxxxxxx"
  secret_access_key: "xxxxxxxxxxxx"
  region_name: "xxxxxxxxx"
  log_group_arn: "arn:aws:logs:xxxxxxxx:apache_logs"
  log_group_name: "xxxxxxxxx/apache"
  fields:
    name: "prod-cloudwatch_apache_logs"
  ignore_older: 720h
  start_position: end
- type: aws-cloudwatch
  enabled: true
  access_key_id: "xxxxxxxxxxxxx"
  secret_access_key: "xxxxxxxxxxxx"
  region_name: "xxxxxxxxx"
  log_group_arn: "arn:aws:logs:xxxxxxxx:apache_logs"
  log_group_name: "xxxxxxxxx/apache"
  fields:
    name: "uat-cloudwatch_apache_logs"
  ignore_older: 720h
  start_position: end

output.elasticsearch:
  hosts: ["https://xxxxxxx.aws.elastic-cloud.com:xxxxxx"]
  protocol: "https"
  username: "${ESUSER}"
  password: "${ESPASS}"
  allow_older_versions: true
  indices:
   - index: "cloudwatch_uat_apache_logs-%{+yyyy.MM}"
     when.contains:
      fields.name: "uat-cloudwatch_apache_logs"
   - index: "cloudwatch_prod_apache_logs-%{+yyyy.MM}"
     when.contains:
      fields.name: "prod-cloudwatch_apache_logs"
  pipelines:
    - pipeline: "apache_pipeline"
      when.contains:
        fields.name: ["prod-cloudwatch_apache_logs", "uat-cloudwatch_apache_logs"]

内容的提问来源于stack exchange,提问作者user1428716

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 10:32:01