You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Logstash读取CSV文件无输出?原因排查与解决方法咨询

Logstash读取CSV无输出(无报错)的原因与修复方案

问题重现

你的Logstash配置如下:

input {
    file {
        path => "C:\\elastic\\logstash-8.3.2\\config\\in.csv"
        start_position => beginning
    }
}

filter {
    csv {
        separator => ";"
        columns => ["Name","Deposit","Month"]
    }
    mutate {
        convert => {
            "Deposit" => "integer"
        }
    }
}

output {
    stdout {
        codec => rubydebug
    }

    elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "randomname"
    }
}

CSV文件内容(分号分隔):

Name;Number;Month
Name;Number;Month
Name;Number;Month
Name;Number;Month
Name;Number;Month
Name;Number;Month
Name;Number;Month

运行后无报错,但控制台和ElasticSearch均无输出。

核心原因

  1. CSV列名不匹配:配置中csv插件定义的列名Deposit与CSV实际第二列Number不一致,导致mutate转换字段时失败,部分场景下事件会被静默丢弃。
  2. Sincedb读取位置记录:Logstash默认会通过.sincedb文件记录已读取文件的位置,若之前运行过该配置读取过此CSV,再次运行时会判定文件已读完,不再重复读取。

简易修复方法

1. 修正列名匹配问题

修改filter模块的csv和mutate配置,让字段名与CSV实际列名一致:

filter {
    csv {
        separator => ";"
        columns => ["Name","Number","Month"] # 同步CSV列名
    }
    mutate {
        convert => {
            "Number" => "integer" # 转换存在的字段
        }
    }
}

2. 强制重新读取文件

针对sincedb的问题,任选一种方法即可:

  • 配置禁用sincedb记录:在input的file插件中添加sincedb_path参数,Windows系统设为NUL,Linux/macOS设为/dev/null,这样每次运行都会从头读取文件:
    input {
        file {
            path => "C:\\elastic\\logstash-8.3.2\\config\\in.csv"
            start_position => beginning
            sincedb_path => "NUL" # Windows用NUL,Linux/macOS用/dev/null
        }
    }
    
  • 手动删除sincedb文件:Windows下该文件默认路径为C:\Users\<你的用户名>\.sincedb_*,找到对应文件删除后重启Logstash。
  • 触发文件变更:打开CSV文件添加空行并保存,让Logstash检测到文件变化后重新读取。

3. 验证配置合法性(可选)

运行以下命令验证配置是否存在语法错误:

logstash -f your_config.conf --config.test_and_exit

完成以上修改后重新运行Logstash,即可在控制台看到rubydebug输出,同时ElasticSearch中会生成randomname索引。

内容的提问来源于stack exchange,提问作者Yağız Can Aslan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 10:18:33