配置Filebeat导入并解析.ndjson文件遇问题求助
Filebeat JSON日志解析失败求助
我是Elasticsearch、Kibana和Filebeat领域的新手,了解到可通过在filebeat.yml中配置decode_json_fields让Filebeat将JSON文件导入Elasticsearch,也参照官方文档及示例操作过,还查阅过相关旧文章,但无论怎么调整配置,JSON文件内容始终未被解析,全部存放在message字段里,恳请帮助。
尝试的配置1
filebeat.inputs: - type: filestream paths: - c:\\tmp\\tmf\\events-*.ndjson json.keys_under_root: true json.add_error_key: true #json.message_key: event fields: ["inner"] output.elasticsearch: hosts: ["localhost:9200"] protocol: "https" username: ... password: ...
尝试的配置2
filebeat.inputs: - type: filestream paths: - c:\\tmp\\tmf\\events-*.ndjson #json.keys_under_root: true #json.add_error_key: true #json.message_key: event #fields: ["inner"] processors: - decode_json_fields: fields: [ "outer", "inner" ] max_depth: 1 target: "" add_error_key: true
示例JSON日志文件内容
{ "outer": "value", "inner": "{\"data\": \"value\"}" }
Elasticsearch查询情况
查询语句
GET /.ds-filebeat-8.3.2-2022.09.28-000001/_search?_source_excludes=ecs,host,os { "query": { "match": { "log.file.path": { "query": "\"c:\\tmp\\tmf\\events-20220930-11.ndjson\"" } } } }
返回文档(JSON内容未解析,全部在message字段)
{ "hits": { "hits": [ { "_source": { "input": { "type": "filestream" }, "@timestamp": "2022-09-30T23:26:01.087Z", "message": "\"{ \"outer\": \"value\", \"inner\": \"{\\\"data\\\": \\\"value\\\"}\" }\"" } } ] } }
内容的提问来源于stack exchange,提问作者Feng
相关产品推荐
相关产品推荐

