You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请校验以下Logstash.conf配置文件格式是否正确,若有误请指出问题位置(需求:基于日志文件路径内置字段切换Elasticsearch索引)

Logstash Config Validation & Fixes

Hey there, let's walk through your Logstash config and fix the issues that are preventing it from working as expected:

Key Issues Identified

  • Incorrect field reference in output condition
    Your current condition if ["log.file.path"] == "/a/b/c/d/e.log" is invalid. Logstash doesn't recognize ["log.file.path"] as a reference to the log.file.path nested field — this syntax treats the string "log.file.path" as an array element, not a field lookup. The correct way to reference nested fields is either using bracket notation ([log][file][path]) or dot notation with quotes ("log.file.path").

  • Wrong syntax for removing the host field
    In the mutate filter, remove_field => [ "[host]" ] is passing a string literal "[host]" instead of referencing the actual host field. This won't remove the field; you need to use ["host"] without the inner quotes to target the field correctly.

Corrected Config

input { 
  beats { 
    port => 5044 
  } 
} 
filter { 
  grok { 
    match => {"message" => "%{TIME:timestamp} \[%{DATA:type}\] %{LOGLEVEL:log-level} %{DATA:app_task}- %{GREEDYDATA:msg_data}"}
  } 
  mutate { 
    remove_field => ["host"] 
  } 
} 
output { 
  stdout {codec => rubydebug} 
  if [log][file][path] == "/a/b/c/d/e.log" { 
    elasticsearch { 
      hosts => ["http://localhost:9200"] 
      index => "abc" 
    } 
  } else { 
    elasticsearch { 
      hosts => ["http://localhost:9200"] 
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" 
    } 
  } 
}

Quick Explanation

  • The output condition now correctly checks the value of the log.file.path field using [log][file][path], so logs from /a/b/c/d/e.log will be routed to the abc index as intended.
  • The mutate filter now properly removes the entire host field object instead of trying to remove a non-existent string field.
  • The rest of your config (beats input, grok pattern, default Elasticsearch output) looks good and should work as expected once these fixes are applied.

内容的提问来源于stack exchange,提问作者Saishantan goli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 12:49:08