Elasticsearch Curator的Rollover操作是否不支持名称中的日期数学表达式?
Elasticsearch Curator Rollover日期数学表达式问题解答
问题性质说明
该问题属于Elasticsearch Curator的已知功能限制。Curator处理Rollover动作的name参数时,不会对ES风格的<{now/d}>日期数学表达式做解析,会直接将整段字符串作为别名名称传递给ES接口,导致ES无法匹配到实际存在的别名,触发对应报错。
适配方案
- 方案1:使用Curator原生支持的strftime日期占位符
Curator默认支持在配置中使用%Y(4位年)、%m(2位月)、%d(2位日)等标准strftime格式的日期占位符,运行时会自动替换为当前实际日期,调整后的配置示例如下:
--- actions: 1: action: rollover description: >- Rollover the index associated with alias 'indexname-%Y-%m-%d', index should be in the format of indexname-%Y-%m-%d-000001. options: disable_action: False name: 'indexname-%Y-%m-%d' conditions: max_age: 1d max_docs: 1000000 max_size: 50g extra_settings: index.number_of_shards: 3 index.number_of_replicas: 1
- 方案2:通过外部脚本动态生成别名
如果有自定义日期偏移(比如要取前一天的日期)等复杂需求,可以在执行Curator前通过Shell/Python等脚本生成目标日期,再将日期传入Curator配置。示例Shell调用逻辑:
# 生成当前日期,也可自定义偏移,比如前一天:date -d "-1 day" +%Y-%m-%d CURRENT_DATE=$(date +%Y-%m-%d) # 替换配置中的占位符后执行Curator sed "s/{{date}}/$CURRENT_DATE/g" your_action_file.yml | curator --config your_config.yml -
对应配置中的name字段写为name: 'indexname-{{date}}'即可。
- 方案3:直接调用ES原生Rollover API
如果需要完整使用ES的日期数学表达式能力,可以绕过Curator直接调用ES接口,ES原生支持解析请求路径中的日期数学表达式:
curl -X POST "http://<ES服务地址>:9200/<indexname-{now/d}>/_rollover" -H "Content-Type: application/json" -d ' { "conditions": { "max_age": "1d", "max_docs": 1000000, "max_size": "50g" }, "settings": { "index.number_of_shards": 3, "index.number_of_replicas": 1 } }'
内容的提问来源于stack exchange,提问作者Bhavesh Sharma
相关产品推荐
相关产品推荐

