使用Grafana/Elasticsearch按时间戳分组求和结果始终为0
解决方法
1. 修复Logstash日期解析错误
原date插件的匹配格式YYYY-MM-dd'T'HH:mm:ss'.'SSS'Z'与原始数据的YYYY-MM-dd HH:mm:ss格式不匹配,会导致@datetime字段解析失败,还可能干扰字段类型映射。修改Logstash的filter部分:
filter { mutate { convert => { "total_load_value" => "float"} } date { match => ["date_time", "YYYY-MM-dd HH:mm:ss"] target => "@timestamp" # 使用ES默认的时间字段,Grafana会默认识别该字段 } }
修改后重新同步数据,确保@timestamp被正确解析,total_load_value为浮点类型。
2. 确认Elasticsearch字段映射
执行以下命令检查字段类型是否正确:
curl -X GET "localhost:9200/network/_mapping?pretty"
需确保:
total_load_value的类型是float或double,而非text或keyword@timestamp(或date_time)的类型是date
3. 检查Grafana聚合配置
- 在面板编辑界面,时间分组选择
@timestamp(或正确映射的date_time),时间间隔设置为“天”或“小时” - 聚合函数选择
Sum,目标字段选择total_load_value(注意ES字段名区分大小写,需完全匹配) - 通过Grafana的“查询检查器”,对比Grafana发送给ES的请求与正常CURL请求,确认参数一致
4. 验证ES中的数据有效性
查询单条数据确认total_load_value存在有效值:
curl -X POST "localhost:9200/network/_search?pretty" -H 'Content-Type: application/json' -d' { "size": 1, "_source": ["date_time", "total_load_value"] } '
如果返回的total_load_value为null,需检查PostgreSQL中该字段的原始类型,确保是数值类型而非字符串。
内容的提问来源于stack exchange,提问作者Cyril
相关产品推荐
相关产品推荐

