You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Elastic Common Schema日志中移除host、process等不必要对象?

问题描述

我正在使用Serilog和Elastic.CommonSchema.Serilog生成带有ECS字段的JSON格式控制台日志,不需要输出中的host、process这类对象,请问该如何移除它们?

环境

  • ASP.NET Core 6
  • Alpine Linux容器

当前代码

Log.Logger = new LoggerConfiguration()
    .MinimumLevel.Is(LogEventLevel.Debug)
    .MinimumLevel.Override("Microsoft", LogEventLevel.Warning)
    .MinimumLevel.Override("Microsoft.Hosting.Lifetime", LogEventLevel.Information)
    .Enrich.FromLogContext()
    .WriteTo.Async(a => a.Console(new EcsTextFormatter()))
    .CreateLogger();

appsettings.json中无任何Serilog相关配置

当前日志输出

{
    "@timestamp": "2023-08-16T10:06:24.0917831+00:00",
    "log.level": "Information",
    "message": "xxxx ccccc vvvv",
    "ecs.version": "8.6.0",
    "log": {
        "logger": "xx.yy.ccc.BBBB"
    },
    "labels": {
        "MessageTemplate": "xxxx ccccc vvvv""
    },
    "agent": {
        "type": "Elastic.CommonSchema.Serilog",
        "version": "8.6.1"
    },
    "event": {
        "created": "2023-08-16T10:06:24.0917831+00:00",
        "severity": 2,
        "timezone": "Coordinated Universal Time"
    },
    "host": {
        "os": {
            "full": "aaaa xxx yyy",
            "platform": "vvvv",
            "version": "x.x.x.xx"
        },
        "architecture": "X64",
        "hostname": "xxxx"
    },
    "process": {
        "name": "xxx",
        "pid": 11,
        "thread.id": 4,
        "thread.name": "xxxx",
        "title": ""
    },
    "service": {
        "name": "xxx",
        "type": "xxx",
        "version": "1.0.0"
    },
    "user": {
        "domain": "xxx",
        "name": ""
    }
}
解决方案

方法一:通过EcsTextFormatterOptions直接排除指定字段

EcsTextFormatter支持通过配置项指定要排除的顶级ECS字段,这是最直接高效的方式。修改代码如下:

Log.Logger = new LoggerConfiguration()
    .MinimumLevel.Is(LogEventLevel.Debug)
    .MinimumLevel.Override("Microsoft", LogEventLevel.Warning)
    .MinimumLevel.Override("Microsoft.Hosting.Lifetime", LogEventLevel.Information)
    .Enrich.FromLogContext()
    .WriteTo.Async(a => a.Console(new EcsTextFormatter(new EcsTextFormatterOptions
    {
        ExcludeProperties = new HashSet<string> { "host", "process" }
    })))
    .CreateLogger();

如果需要移除其他字段(如user、service),只需在ExcludeProperties集合中添加对应的字段名即可。

方法二:使用Serilog的Destructure自定义处理日志事件

如果需要更灵活的字段修改逻辑(比如移除嵌套字段),可以通过Destructure转换操作移除目标属性:

Log.Logger = new LoggerConfiguration()
    .MinimumLevel.Is(LogEventLevel.Debug)
    .MinimumLevel.Override("Microsoft", LogEventLevel.Warning)
    .MinimumLevel.Override("Microsoft.Hosting.Lifetime", LogEventLevel.Information)
    .Enrich.FromLogContext()
    .Destructure.ByTransforming<LogEvent>(le =>
    {
        le.Properties.Remove("host");
        le.Properties.Remove("process");
        return le;
    })
    .WriteTo.Async(a => a.Console(new EcsTextFormatter()))
    .CreateLogger();

这种方式适合需要对日志事件做更多自定义调整的场景。

内容的提问来源于stack exchange,提问作者Bishan Vithanage

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 03:34:51