You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自定义Watcher索引动作日志无法在Kibana可观测性日志流显示

解决方案

1. 排查文档实际结构

先确认写入的文档中是否真的包含@timestamp字段:
执行查询查看完整文档:

GET /watcher-index/_search
{
  "query": { "match_all": {} },
  "_source": true
}

如果返回的文档里没有@timestamp,说明Watcher的索引动作没有自动填充该字段——Watcher默认不会为索引动作添加@timestamp,需要手动配置。

2. 修改Watcher配置,显式添加@timestamp

更新Watcher定义,在index动作中通过document字段指定@timestamp值(使用Watcher内置的执行时间变量):

PUT _watcher/watch/[你的Watcher名称]
{
  // 保留原有的trigger、input等配置
  "actions": {
    "index": {
      "index": "watcher-index",
      "document": {
        "@timestamp": "{{ctx.execution_time}}",
        // 可按需添加其他业务字段,比如告警内容
        "alert_content": "{{ctx.payload}}"
      }
    }
  }
}

3. 修正索引映射(适配Elasticsearch 8.x)

你的原映射使用了已弃用的_default_语法,8.x中需改用标准的字段映射定义:

  • 若允许重建索引,重新创建索引:
PUT /watcher-index
{
  "settings": {
    "number_of_shards": 3,
    "number_of_replicas": 1
  },
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date",
        "store": true
      }
    }
  }
}
  • 若无法重建,直接更新现有索引的映射:
PUT /watcher-index/_mapping
{
  "properties": {
    "@timestamp": {
      "type": "date",
      "store": true
    }
  }
}

4. 配置Kibana索引模式

确保Kibana已正确识别该索引的时间字段:

  1. 进入Kibana「管理」→「索引模式」
  2. 创建匹配watcher-index的索引模式
  3. 在「时间字段」下拉菜单中选择@timestamp并保存

5. 验证结果

执行以下查询确认@timestamp字段已正确写入:

GET /watcher-index/_search
{
  "query": {
    "exists": {
      "field": "@timestamp"
    }
  }
}

之后再进入Kibana可观测性的「日志/流」,选择对应的索引模式即可看到文档。

内容的提问来源于stack exchange,提问作者mrin9san

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 00:07:29