Logstash Filter中Elasticsearch查询语法报错排查求助
问题解决方法
错误原因
你在query参数里使用的字段引用语法不正确——Logstash中引用事件字段的标准格式是%{字段名},而非${[字段名]}。后者的写法会被Elasticsearch的查询解析器识别为无效语法,这就是导致“期望‘TO’的位置发现‘]’”错误的根源。
修正后的配置
将字段引用改为%{period}、%{station}、%{checkDate}格式即可。如果字段值包含空格、冒号等特殊字符,建议给值加上双引号,避免解析异常:
filter { elasticsearch { hosts => <host ip> ca_file => <ca file path> user => <authentication username> password => <authentication password> index => <index name I want to query> query => "period:%{period} AND station:%{station} AND checkDate:\"%{checkDate}\"" } }
额外优化提示
如果你的需求只是判断重复并丢弃重复记录,还可以添加result_size参数减少查询开销,再配合drop插件实现去重:
filter { elasticsearch { hosts => <host ip> ca_file => <ca file path> user => <authentication username> password => <authentication password> index => <index name I want to query> query => "period:%{period} AND station:%{station} AND checkDate:\"%{checkDate}\"" result_size => 1 # 仅需判断是否存在匹配,无需返回所有结果 } # 若查询到匹配记录,丢弃当前事件 if [hits][total][value] > 0 { drop {} } }
内容的提问来源于stack exchange,提问作者Bardo
相关产品推荐
相关产品推荐

