You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Filebeat导入并解析.ndjson文件遇问题求助

Filebeat JSON日志解析失败求助

我是Elasticsearch、Kibana和Filebeat领域的新手,了解到可通过在filebeat.yml中配置decode_json_fields让Filebeat将JSON文件导入Elasticsearch,也参照官方文档及示例操作过,还查阅过相关旧文章,但无论怎么调整配置,JSON文件内容始终未被解析,全部存放在message字段里,恳请帮助。

尝试的配置1

filebeat.inputs:
- type: filestream
  paths: 
    - c:\\tmp\\tmf\\events-*.ndjson
  json.keys_under_root: true
  json.add_error_key: true
  #json.message_key: event
  fields: ["inner"]

output.elasticsearch:
  hosts: ["localhost:9200"]
  protocol: "https"
  username: ...
  password: ...

尝试的配置2

filebeat.inputs:
- type: filestream
  paths: 
    - c:\\tmp\\tmf\\events-*.ndjson
  #json.keys_under_root: true
  #json.add_error_key: true
  #json.message_key: event
  #fields: ["inner"]

processors:
  - decode_json_fields:
      fields: [ "outer", "inner" ]
      max_depth: 1
      target: ""
      add_error_key: true

示例JSON日志文件内容

{ "outer": "value", "inner": "{\"data\": \"value\"}" }

Elasticsearch查询情况

查询语句

GET /.ds-filebeat-8.3.2-2022.09.28-000001/_search?_source_excludes=ecs,host,os
{
  "query": {
    "match": {
      "log.file.path": {
        "query": "\"c:\\tmp\\tmf\\events-20220930-11.ndjson\""
      }
    }
  }
}

返回文档(JSON内容未解析,全部在message字段)

{
  "hits": {
    "hits": [
      {
        "_source": {
          "input": {
            "type": "filestream"
          },
          "@timestamp": "2022-09-30T23:26:01.087Z",
          "message": "\"{ \"outer\": \"value\", \"inner\": \"{\\\"data\\\": \\\"value\\\"}\" }\""
        }
      }
    ]
  }
}

内容的提问来源于stack exchange,提问作者Feng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 22:25:25