You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Grafana/Elasticsearch按时间戳分组求和结果始终为0

解决方法

1. 修复Logstash日期解析错误

原date插件的匹配格式YYYY-MM-dd'T'HH:mm:ss'.'SSS'Z'与原始数据的YYYY-MM-dd HH:mm:ss格式不匹配,会导致@datetime字段解析失败,还可能干扰字段类型映射。修改Logstash的filter部分:

filter {
    mutate {
        convert => { "total_load_value" => "float"}
    }
    date {
        match => ["date_time", "YYYY-MM-dd HH:mm:ss"]
        target => "@timestamp" # 使用ES默认的时间字段,Grafana会默认识别该字段
    }
}

修改后重新同步数据,确保@timestamp被正确解析,total_load_value为浮点类型。

2. 确认Elasticsearch字段映射

执行以下命令检查字段类型是否正确:

curl -X GET "localhost:9200/network/_mapping?pretty"

需确保:

  • total_load_value的类型是float或double,而非text或keyword
  • @timestamp(或date_time)的类型是date

3. 检查Grafana聚合配置

  • 在面板编辑界面,时间分组选择@timestamp(或正确映射的date_time),时间间隔设置为“天”或“小时”
  • 聚合函数选择Sum,目标字段选择total_load_value(注意ES字段名区分大小写,需完全匹配)
  • 通过Grafana的“查询检查器”,对比Grafana发送给ES的请求与正常CURL请求,确认参数一致

4. 验证ES中的数据有效性

查询单条数据确认total_load_value存在有效值:

curl -X POST "localhost:9200/network/_search?pretty" -H 'Content-Type: application/json' -d'
{
  "size": 1,
  "_source": ["date_time", "total_load_value"]
}
'

如果返回的total_load_value为null,需检查PostgreSQL中该字段的原始类型,确保是数值类型而非字符串。


内容的提问来源于stack exchange,提问作者Cyril

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 02:02:27