You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Filebeat配置:如何为不同日志路径指定独立Elasticsearch索引?

Filebeat配置:将不同路径日志发送至Elasticsearch不同索引

我正在收集两个路径下的日志:

  • /var/log/containers/*.log
  • /var/log/agents/*.log

希望将每个路径的日志发送到Elasticsearch的不同索引,但尝试了多种配置都未生效:

尝试的配置1

output.elasticsearch:
  protocol: http
  hosts: ["elasticsearch:9200"]
  compression_level: 1
  indices:
  - index: "agent-logs"
    when:
     contains:
      log.file.path: "/var/log/agents/*.log"
  - index: "container-logs"
    when:
     contains:
      log.file.path: "/var/log/containers/*.log"

尝试的配置2

output.elasticsearch:
  protocol: http
  hosts: ["elasticsearch:9200"]
  compression_level: 1
  indices:
  - index: "agent-logs"
    when.contains:
      log.file.path: "/var/log/agents/*.log"
  - index: "container-logs"
    when.contains:
      log.file.path: "/var/log/containers/*.log"

尝试的配置3

output.elasticsearch:
  protocol: http
  hosts: ["elasticsearch:9200"]
  compression_level: 1
  indices:
  - index: "agent-logs"
    when.equals:
      log.file.path: "/var/log/agents/*.log"
  - index: "container-logs"
    when.equals:
      log.file.path: "/var/log/containers/*.log"

问题原因

配置无效的核心原因是:log.file.path字段存储的是具体的日志文件路径(比如/var/log/agents/agent_01.log),而非你在input中配置的带通配符的路径。用contains匹配带*.log的字符串、或用equals完全匹配带通配符的路径,都无法匹配到真实的文件路径。

解决方案

方案1:用contains匹配路径前缀

直接匹配目录前缀,无需通配符:

output.elasticsearch:
  protocol: http
  hosts: ["elasticsearch:9200"]
  compression_level: 1
  indices:
  - index: "agent-logs"
    when.contains:
      log.file.path: "/var/log/agents/"
  - index: "container-logs"
    when.contains:
      log.file.path: "/var/log/containers/"

方案2:用regexp匹配正则表达式

如果需要精确匹配.log后缀,可使用正则:

output.elasticsearch:
  protocol: http
  hosts: ["elasticsearch:9200"]
  compression_level: 1
  indices:
  - index: "agent-logs"
    when.regexp:
      log.file.path: "^/var/log/agents/.+\\.log$"
  - index: "container-logs"
    when.regexp:
      log.file.path: "^/var/log/containers/.+\\.log$"

方案3:在input阶段添加自定义字段(推荐)

在Filebeat的input配置中,给不同路径的日志添加自定义字段,后续output根据该字段判断索引,维护性更强:

filebeat.inputs:
- type: filestream
  id: container-logs-input
  paths:
    - "/var/log/containers/*.log"
  fields:
    log_source: "container"
  fields_under_root: true

- type: filestream
  id: agent-logs-input
  paths:
    - "/var/log/agents/*.log"
  fields:
    log_source: "agent"
  fields_under_root: true

output.elasticsearch:
  protocol: http
  hosts: ["elasticsearch:9200"]
  compression_level: 1
  indices:
  - index: "agent-logs"
    when.equals:
      log_source: "agent"
  - index: "container-logs"
    when.equals:
      log_source: "container"

内容的提问来源于stack exchange,提问作者user15937765

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 07:05:17