能否通过Logstash配置文件禁用Elasticsearch动态映射或设置dynamic参数为false?
关于通过Logstash配置控制Elasticsearch动态映射的问题
可以通过Logstash配置实现禁用Elasticsearch的动态映射(即设置索引的dynamic参数为false),核心是借助Logstash的elasticsearch输出插件结合索引模板完成,以下是两种常用实现方式:
方式一:使用外部自定义模板文件
- 编写包含
dynamic: false的Elasticsearch索引模板文件(示例命名为custom_template.json):
{ "index_patterns": ["my_index-*"], "mappings": { "dynamic": false, "properties": { "username": {"type": "keyword"}, "log_time": {"type": "date"}, "message": {"type": "text"} } } }
- 在Logstash输出配置中引用该模板,并开启模板覆盖:
output { elasticsearch { hosts => ["localhost:9200"] index => "my_index-%{+YYYY.MM.dd}" template => "/opt/logstash/config/custom_template.json" template_overwrite => true } }
方式二:直接在Logstash配置中内嵌模板内容
如果不想维护外部文件,可通过template_body参数直接在Logstash配置里定义模板:
output { elasticsearch { hosts => ["localhost:9200"] index => "my_index-%{+YYYY.MM.dd}" template_body => '{ "index_patterns": ["my_index-*"], "mappings": { "dynamic": false, "properties": { "username": {"type": "keyword"}, "log_time": {"type": "date"}, "message": {"type": "text"} } } }' template_overwrite => true } }
关键说明
- Logstash默认会自动生成索引模板,开启
template_overwrite: true可确保自定义模板覆盖默认模板,使dynamic: false配置生效。 - 设置
dynamic: false后,Elasticsearch会忽略文档中未预先定义的字段,不会自动创建新映射,从而达到禁用动态映射的效果。
内容的提问来源于stack exchange,提问作者Shirisha
相关产品推荐
相关产品推荐

