Filebeat Cisco Nexus模块配置文件读取错误求助
解决Filebeat Cisco模块YAML配置错误(line102: did not find expected key)
错误根源是YAML缩进格式错误:你配置的var.input、var.syslog_host等变量没有嵌套在nexus节点下,Filebeat无法识别这些属于Nexus模块的配置项,导致加载失败。
修正后的cisco.yml对应片段如下:
nexus: enabled: true # Set which input to use between udp (default), tcp or file. var.input: udp var.syslog_host: 10.0.0.83 var.syslog_port: 9004 # Set paths for the log files when file input is used. # var.paths: # Toggle output of non-ECS fields (default true). # var.rsa_fields: true # Set custom timezone offset. # "local" (default) for system timezone. # "+02:00" for GMT+02:00 # var.tz_offset: local
操作步骤:
- 替换原配置文件中对应片段,确保所有
var.xxx配置项和enabled: true保持相同缩进层级(注意YAML禁止混用空格和制表符,统一用空格缩进) - 重新执行
./filebeat.exe setup -e完成模块初始化 - 启动Filebeat服务,验证是否正常运行
内容的提问来源于stack exchange,提问作者Legend27
相关产品推荐
相关产品推荐

