Vega-Lite基于lastEvent值调整填充色的ELK日志可视化问题排查
解决方案
核心修改点
- 给Elasticsearch查询新增排序和条数限制,仅返回最新1条设备日志,避免多日志干扰判定
- 配置Vega数据解析规则,正确读取ES返回的嵌套结构里的字段值,解决
lastEvent读取为undefined的问题
修正后完整代码
{ "$schema": "https://vega.github.io/schema/vega-lite/v5.json", "data": { "url": { "%context%": false, "%timefield%": "@timestamp", "index": "mtconnect*", "body": { "size": 1, "sort": [ { "@timestamp": { "order": "desc" } } ] } }, "format": {"property": "hits.hits"} }, "transform": [ {"calculate": "datum._source.lastEvent", "as": "lastEvent"} ], "height": "container", "width": "container", "mark": "rect", "encoding": { "color": { "condition": [ {"test": "datum['lastEvent'] === 'ACTIVE'", "value": "blue"}, {"test": "datum['lastEvent'] === 'STOPPED'", "value": "red"}, {"test": "datum['lastEvent'] === 'READY'", "value": "green"}, {"test": "datum['lastEvent'] === 'UNAVAILABLE'", "value": "black"}, {"test": "datum['lastEvent'] === 'PROGRAM_STOPPED'", "value": "pink"}, {"test": "datum['lastEvent'] === 'FEED_HOLD'", "value": "purple"}, {"test": "datum['lastEvent'] === 'INTERRUPTED'", "value": "yellow"} ], "value": "Pink" } } }
说明
已将你要求的ACTIVE状态对应颜色调整为蓝色,其余状态颜色可自行修改condition对应value值调整。修改后每次仪表盘刷新会自动拉取最新日志,正确读取lastEvent字段值匹配对应颜色。
内容的提问来源于stack exchange,提问作者Raiu
相关产品推荐
相关产品推荐

