You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Serilog Splunk Sink日志嵌套问题:如何将event内属性提至顶层?

解决Serilog Splunk Sink日志嵌套在event对象的问题

一、从Serilog端直接调整输出结构(推荐)

默认的Serilog Splunk Sink会把日志属性包裹在event对象里,你可以通过自定义格式化器直接输出平级的JSON结构,从源头避免嵌套问题。

方法1:使用CompactJsonFormatter

直接替换默认的格式化器为CompactJsonFormatter,它会把所有日志属性(包括消息、级别、自定义参数)都输出为顶级字段,同时保留Splunk需要的基础元数据(如时间、主机名):

Log.Logger = new LoggerConfiguration()
    .Enrich.WithMachineName()
    .WriteTo.SplunkHttp(
        uri: "https://your-splunk-collector-url/services/collector/event",
        token: "your-splunk-hec-token",
        options: new SplunkHttpSinkOptions
        {
            Formatter = new CompactJsonFormatter()
        })
    .CreateLogger();

方法2:自定义格式化器(更灵活)

如果需要精确控制输出字段,可以实现ITextFormatter,手动拼接JSON结构,把原event内的内容直接放到顶级:

public class FlatSplunkFormatter : ITextFormatter
{
    public void Format(LogEvent logEvent, TextWriter output)
    {
        var json = new JObject();
        // 添加Splunk必需字段
        json["time"] = logEvent.Timestamp.ToUnixTimeSeconds();
        json["host"] = Environment.MachineName;
        // 添加日志核心字段
        json["message"] = logEvent.RenderMessage();
        json["level"] = logEvent.Level.ToString();
        // 添加自定义属性(原event内的内容)
        foreach (var property in logEvent.Properties)
        {
            json[property.Key] = JToken.FromObject(property.Value);
        }
        output.Write(json.ToString(Formatting.None));
    }
}

然后在配置中使用这个自定义格式化器:

options: new SplunkHttpSinkOptions
{
    Formatter = new FlatSplunkFormatter()
}

二、在Splunk端处理已有的嵌套日志

如果已经有大量嵌套日志存在,不想修改Serilog配置,可以在Splunk侧通过搜索命令或字段提取来自动展开event内容:

方法1:搜索时自动展开并平级字段

在Splunk搜索栏中使用spath解析event的JSON结构,再用rename把嵌套字段提升到顶级:

index=your_index sourcetype=your_sourcetype 
| spath input=event 
| rename event.* as * 
| table _time, host, message, level, *your_custom_fields*

可以把这个搜索保存为搜索宏,每次直接调用即可,不用重复输入命令。

方法2:配置源类型自动提取字段

进入Splunk的【设置】→【源类型】,找到对应的日志源类型:

  1. 编辑源类型,在【高级】选项卡中设置:
    • INDEXED_EXTRACTIONS = json
    • KV_MODE = json
    • JSON_MODE = auto
  2. 保存后,Splunk会自动解析event内的JSON内容,并将其作为顶级字段索引,之后搜索时就无需手动展开了。

内容的提问来源于stack exchange,提问作者JuztBe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 23:05:28