ELK 8.10.x中Kong索引host.ip字段类型冲突及修改问题
host.ip字段类型冲突问题 我使用ELK 8.10.x处理Kong API网关日志时,在Kibana仪表盘发现host.ip字段存在数据类型冲突。排查后确认索引kong-01的host.ip为text类型,其余索引的该字段均为ip类型,导致数据可视化异常。请问如何将现有索引的host.ip字段修改为ip类型?
当前kong-01索引映射配置
{ "kong-01": { "mappings": { "host.ip": { "full_name": "host.ip", "mapping": { "ip": { "type": "text", "fields": { "keyword": { "type": "keyword", "ignore_above": 256 } } } } } } } }
尝试操作及遇到的错误
1. 创建新索引时的语法错误
我尝试通过以下命令创建新索引:
PUT kong-01-new { "mappings": { "host.ip": { "full_name": "host.ip", "mapping": { "ip": { "type": "ip" } } } } }
返回错误:
{ "error": { "root_cause": [ { "type": "mapper_parsing_exception", "reason": "Root mapping definition has unsupported parameters: [host.ip : {mapping={ip={type=ip}}, full_name=host.ip}]" } ], "type": "mapper_parsing_exception", "reason": "Failed to parse mapping: Root mapping definition has unsupported parameters: [host.ip : {mapping={ip={type=ip}}, full_name=host.ip}]", "caused_by": { "type": "mapper_parsing_exception", "reason": "Root mapping definition has unsupported parameters: [host.ip : {mapping={ip={type=ip}}, full_name=host.ip}]" } }, "status": 400 }
2. 重新索引后的ILM滚动别名错误
完成重新索引后,kong-01-new索引出现以下错误:
Index lifecycle error
illegal_argument_exception: index.lifecycle.rollover_alias [kong] does not point to index [kong-01-new]
按照Logstash配置的ilm_pattern->"{now/d}-000001"命名规范重新索引后,依然报错:
Index lifecycle error
illegal_argument_exception: index.lifecycle.rollover_alias [kong] does not point to index [kong-2022-11-24-000001]
正确解决步骤
1. 创建带有正确映射的新索引
Elasticsearch映射语法错误是因为嵌套字段的结构写法不正确,正确的映射定义应为:
PUT kong-01-new { "mappings": { "properties": { "host": { "properties": { "ip": { "type": "ip" } } } } } }
如果需要保留原索引的其他字段映射,可先获取完整映射后修改:
# 获取kong-01的完整映射 GET kong-01/_mapping
复制返回的properties部分,修改host.ip的类型为ip,再用修改后的内容创建新索引。
2. 重新索引数据到新索引
使用_reindex API迁移旧索引数据:
POST _reindex { "source": { "index": "kong-01" }, "dest": { "index": "kong-01-new" } }
3. 修复ILM滚动别名问题
若索引使用了ILM,需确保新索引关联到正确的滚动别名:
- 查看当前别名指向:
GET _alias/kong
- 更新别名,移除旧索引并添加新索引:
POST _aliases { "actions": [ { "remove": { "index": "kong-01", "alias": "kong" } }, { "add": { "index": "kong-01-new", "alias": "kong" } } ] }
- 若新索引遵循ILM命名规范(如
kong-2022-11-24-000001),需设置其为滚动别名的写入索引:
PUT kong-2022-11-24-000001/_settings { "index.lifecycle.rollover_alias": "kong", "index.lifecycle.indexing_complete": false }
然后更新别名:
POST _aliases { "actions": [ { "remove": { "index": "kong-01", "alias": "kong" } }, { "add": { "index": "kong-2022-11-24-000001", "alias": "kong", "is_write_index": true } } ] }
4. 验证字段类型
重新索引完成后,验证新索引的host.ip类型:
GET kong-01-new/_mapping/field/host.ip
返回结果应显示type: ip。
内容的提问来源于stack exchange,提问作者Linux_Admin

