请校验以下Logstash.conf配置文件格式是否正确,若有误请指出问题位置(需求:基于日志文件路径内置字段切换Elasticsearch索引)
Hey there, let's walk through your Logstash config and fix the issues that are preventing it from working as expected:
Key Issues Identified
Incorrect field reference in output condition
Your current conditionif ["log.file.path"] == "/a/b/c/d/e.log"is invalid. Logstash doesn't recognize["log.file.path"]as a reference to thelog.file.pathnested field — this syntax treats the string"log.file.path"as an array element, not a field lookup. The correct way to reference nested fields is either using bracket notation ([log][file][path]) or dot notation with quotes ("log.file.path").Wrong syntax for removing the
hostfield
In themutatefilter,remove_field => [ "[host]" ]is passing a string literal"[host]"instead of referencing the actualhostfield. This won't remove the field; you need to use["host"]without the inner quotes to target the field correctly.
Corrected Config
input { beats { port => 5044 } } filter { grok { match => {"message" => "%{TIME:timestamp} \[%{DATA:type}\] %{LOGLEVEL:log-level} %{DATA:app_task}- %{GREEDYDATA:msg_data}"} } mutate { remove_field => ["host"] } } output { stdout {codec => rubydebug} if [log][file][path] == "/a/b/c/d/e.log" { elasticsearch { hosts => ["http://localhost:9200"] index => "abc" } } else { elasticsearch { hosts => ["http://localhost:9200"] index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" } } }
Quick Explanation
- The output condition now correctly checks the value of the
log.file.pathfield using[log][file][path], so logs from/a/b/c/d/e.logwill be routed to theabcindex as intended. - The
mutatefilter now properly removes the entirehostfield object instead of trying to remove a non-existent string field. - The rest of your config (beats input, grok pattern, default Elasticsearch output) looks good and should work as expected once these fixes are applied.
内容的提问来源于stack exchange,提问作者Saishantan goli

