You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Filebeat采集至Elastic的日志中单个message字段拆分为多字段?

解决Filebeat传输JSON日志到Elastic时字段未拆分的问题

当前日志链路是ECS → Filebeat → Elastic,Kibana中所有日志内容都集中在message字段内,但该字段本身是完整的JSON格式(包含name、level、apiCall等嵌套字段),要在Kibana中便捷过滤这些字段,需让Filebeat自动解析message里的JSON并将字段拆分到根级别。

具体配置修改步骤

  1. 编辑Filebeat配置文件(filebeat.yml)
    在filebeat.inputs模块下添加JSON解析相关配置,确保日志中的JSON字段被正确提取:

    filebeat.inputs:
    - type: log
      enabled: true
      paths:
        - /var/log/your-app/*.log  # 替换为你的ECS日志实际路径
      # 开启JSON解析配置
      json.keys_under_root: true    # 将JSON中的字段直接放到文档根级别,而非嵌套在message下
      json.add_error_key: true      # 当JSON解析失败时,添加`error`字段记录错误信息
      json.message_key: message     # 指定要解析的目标字段为message
    
  2. 确保Elasticsearch输出配置正确
    输出到Elasticsearch的配置无需额外调整,保持原有正常配置即可,示例:

    output.elasticsearch:
      hosts: ["your-elastic-host:9200"]
      username: "elastic"
      password: "your-password"
    
  3. 重启Filebeat服务
    根据操作系统执行重启命令:

    • Linux系统:sudo systemctl restart filebeat
    • Docker部署:docker restart your-filebeat-container

验证效果

重启后,新采集的日志会自动将name、level、apiCall.request.method等字段拆分为独立字段,在Kibana的Discover页面即可直接筛选这些字段。如果旧索引仍未显示拆分后的字段,可删除旧索引(或创建新的索引模式),让新日志生成的索引使用正确的字段映射。

内容的提问来源于stack exchange,提问作者Trilok Patel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 07:57:29