如何从Elastic Common Schema日志中移除host、process等不必要对象?
问题描述
我正在使用Serilog和Elastic.CommonSchema.Serilog生成带有ECS字段的JSON格式控制台日志,不需要输出中的host、process这类对象,请问该如何移除它们?
环境
- ASP.NET Core 6
- Alpine Linux容器
当前代码
Log.Logger = new LoggerConfiguration() .MinimumLevel.Is(LogEventLevel.Debug) .MinimumLevel.Override("Microsoft", LogEventLevel.Warning) .MinimumLevel.Override("Microsoft.Hosting.Lifetime", LogEventLevel.Information) .Enrich.FromLogContext() .WriteTo.Async(a => a.Console(new EcsTextFormatter())) .CreateLogger();
appsettings.json中无任何Serilog相关配置
当前日志输出
{ "@timestamp": "2023-08-16T10:06:24.0917831+00:00", "log.level": "Information", "message": "xxxx ccccc vvvv", "ecs.version": "8.6.0", "log": { "logger": "xx.yy.ccc.BBBB" }, "labels": { "MessageTemplate": "xxxx ccccc vvvv"" }, "agent": { "type": "Elastic.CommonSchema.Serilog", "version": "8.6.1" }, "event": { "created": "2023-08-16T10:06:24.0917831+00:00", "severity": 2, "timezone": "Coordinated Universal Time" }, "host": { "os": { "full": "aaaa xxx yyy", "platform": "vvvv", "version": "x.x.x.xx" }, "architecture": "X64", "hostname": "xxxx" }, "process": { "name": "xxx", "pid": 11, "thread.id": 4, "thread.name": "xxxx", "title": "" }, "service": { "name": "xxx", "type": "xxx", "version": "1.0.0" }, "user": { "domain": "xxx", "name": "" } }
解决方案
方法一:通过EcsTextFormatterOptions直接排除指定字段
EcsTextFormatter支持通过配置项指定要排除的顶级ECS字段,这是最直接高效的方式。修改代码如下:
Log.Logger = new LoggerConfiguration() .MinimumLevel.Is(LogEventLevel.Debug) .MinimumLevel.Override("Microsoft", LogEventLevel.Warning) .MinimumLevel.Override("Microsoft.Hosting.Lifetime", LogEventLevel.Information) .Enrich.FromLogContext() .WriteTo.Async(a => a.Console(new EcsTextFormatter(new EcsTextFormatterOptions { ExcludeProperties = new HashSet<string> { "host", "process" } }))) .CreateLogger();
如果需要移除其他字段(如user、service),只需在ExcludeProperties集合中添加对应的字段名即可。
方法二:使用Serilog的Destructure自定义处理日志事件
如果需要更灵活的字段修改逻辑(比如移除嵌套字段),可以通过Destructure转换操作移除目标属性:
Log.Logger = new LoggerConfiguration() .MinimumLevel.Is(LogEventLevel.Debug) .MinimumLevel.Override("Microsoft", LogEventLevel.Warning) .MinimumLevel.Override("Microsoft.Hosting.Lifetime", LogEventLevel.Information) .Enrich.FromLogContext() .Destructure.ByTransforming<LogEvent>(le => { le.Properties.Remove("host"); le.Properties.Remove("process"); return le; }) .WriteTo.Async(a => a.Console(new EcsTextFormatter())) .CreateLogger();
这种方式适合需要对日志事件做更多自定义调整的场景。
内容的提问来源于stack exchange,提问作者Bishan Vithanage
相关产品推荐
相关产品推荐

