You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kibana未按索引映射存储数据至对应字段的问题求助

问题分析与解决方案

从你提供的信息来看,核心问题是Logstash没有解析你输入的JSON日志内容,导致整个JSON字符串被原样塞进了message字段——哪怕你在Elasticsearch中配置了自定义映射,也无法将数据拆分到对应字段里。

问题根源

你的file输入读取的是TestLogPourMapping_09_05.json这类JSON格式的日志文件,但当前的Logstash filter只处理了syslog类型的日志,完全没有对JSON格式的日志做解析处理。Logstash会把整个JSON文本当作普通字符串存入message字段,Elasticsearch自然也无法识别里面的结构,只能按照动态映射规则处理。

解决方案步骤

1. 给Logstash添加JSON解析过滤器

修改你的Logstash过滤配置,针对JSON格式的日志添加json过滤器。可以通过判断文件路径或者直接检测内容格式来触发:

filter {
  # 保留原有syslog处理逻辑
  if [type] == "syslog"{ 
    grok { 
      match => ["message", "<(?<sys_priority>\d+?)>(?<syslog_timestamp>%{CISCOTIMESTAMP})\s(?<logsource>%{URIHOST})(\s(?:(?<application>.*?)(%(?<project>.*?))?))?:(?:\s)?(?<logmessage>.*$)"] 
    } 
    if [logmessage] { 
      mutate { 
        replace => [ "message", "%{logmessage}" ] 
        remove_field => [ "logmessage" ] 
      } 
    } 
    if [project] { 
      mutate { 
        replace => [ "type", "%{project}" ] 
        remove_field => [ "project" ] 
      } 
    }else if [application] { 
      mutate { lowercase => [ "application" ] } 
      mutate { gsub => [ "application", " ", "_" ] } 
      mutate { replace => [ "type", "%{application}" ] } 
    }else { 
      mutate { 
        replace => [ "type", "uknapp" ] 
        add_field => { "application" => "uknapp" } 
      } 
    } 
  }

  # 新增:解析JSON格式的日志
  else if [path] =~ /\.json$/ { # 匹配.json结尾的日志文件
    json {
      source => "message" # 从message字段读取JSON原始内容
      target => "" # 解析后直接将字段放到根级别(不嵌套)
    }
    # 可选:删除原message和path字段,避免冗余数据
    mutate {
      remove_field => ["message", "path"]
    }
  }
}

2. 修正Elasticsearch自定义映射中的错误

你提供的自定义映射里,relatedContent下有两个字段的type是空值,这会导致映射创建失败或异常,需要补全:

"og:description": { "type": "text" },
"og:url": { "type": "text" }

3. 重新导入数据

因为之前写入的日志数据已经被存在message字段里,无法自动拆分,所以需要做以下操作:

  • 删除现有错误的索引:
curl -XDELETE http://localhost:9200/logstash-2019.05.09
  • 重新创建修正后的自定义映射:
curl -XPUT http://localhost:9200/logstash-2019.05.09 -H "Content-Type: application/json" -d '{
  "mappings": {
    "doc": {
      "properties": {
        "@timestamp": { "type": "date" },
        "ip": { "type": "ip" },
        "extension": { "type": "text" },
        "response": { "type": "text" },
        "geo": {
          "coordinates": { "type": "geo_point" },
          "src": { "type": "text" },
          "dest": { "type": "text" },
          "srcdest": { "type": "text" }
        },
        "tags": { "type": "text" },
        "utc_time": { "type": "date" },
        "referer": { "type": "text" },
        "agent": { "type": "text" },
        "clientip": { "type": "ip" },
        "bytes": { "type": "integer" },
        "host": { "type": "text" },
        "request": { "type": "text" },
        "url": { "type": "text" },
        "@message": { "type": "text" },
        "spaces": { "type": "text" },
        "xss": { "type": "text" },
        "links": { "type": "text" },
        "relatedContent": {
          "url": { "type": "text" },
          "og:type": { "type": "text" },
          "og:title": { "type": "text" },
          "og:description": { "type": "text" },
          "og:url": { "type": "text" },
          "article:published_time": { "type": "date" },
          "article:modified_time": { "type": "date" },
          "article:section": { "type": "keyword" },
          "article:tag": { "type": "text" },
          "og:image": { "type": "text" },
          "og:image:height": { "type": "integer" },
          "og:image:width": { "type": "integer" },
          "og:site_name": { "type": "text" },
          "twitter:title": { "type": "text" },
          "twitter:description": { "type": "text" },
          "twitter:card": { "type": "keyword" },
          "twitter:image": { "type": "text" },
          "twitter:site": { "type": "keyword" }
        },
        "machine": {
          "os": { "type": "text" },
          "ram": { "type": "integer" }
        },
        "@version": { "type": "integer" }
      }
    }
  }
}'
  • 重启Logstash,让新的filter配置生效,Logstash会重新读取日志文件并解析JSON内容,将字段正确写入Elasticsearch。

验证结果

处理完成后,你可以在Kibana的Discover页面查看文档,应该能看到所有字段都被正确拆分,不再全部堆积在message字段中。

内容的提问来源于stack exchange,提问作者Rodolphe G.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:24:01