Kibana未按索引映射存储数据至对应字段的问题求助
问题分析与解决方案
从你提供的信息来看,核心问题是Logstash没有解析你输入的JSON日志内容,导致整个JSON字符串被原样塞进了message字段——哪怕你在Elasticsearch中配置了自定义映射,也无法将数据拆分到对应字段里。
问题根源
你的file输入读取的是TestLogPourMapping_09_05.json这类JSON格式的日志文件,但当前的Logstash filter只处理了syslog类型的日志,完全没有对JSON格式的日志做解析处理。Logstash会把整个JSON文本当作普通字符串存入message字段,Elasticsearch自然也无法识别里面的结构,只能按照动态映射规则处理。
解决方案步骤
1. 给Logstash添加JSON解析过滤器
修改你的Logstash过滤配置,针对JSON格式的日志添加json过滤器。可以通过判断文件路径或者直接检测内容格式来触发:
filter { # 保留原有syslog处理逻辑 if [type] == "syslog"{ grok { match => ["message", "<(?<sys_priority>\d+?)>(?<syslog_timestamp>%{CISCOTIMESTAMP})\s(?<logsource>%{URIHOST})(\s(?:(?<application>.*?)(%(?<project>.*?))?))?:(?:\s)?(?<logmessage>.*$)"] } if [logmessage] { mutate { replace => [ "message", "%{logmessage}" ] remove_field => [ "logmessage" ] } } if [project] { mutate { replace => [ "type", "%{project}" ] remove_field => [ "project" ] } }else if [application] { mutate { lowercase => [ "application" ] } mutate { gsub => [ "application", " ", "_" ] } mutate { replace => [ "type", "%{application}" ] } }else { mutate { replace => [ "type", "uknapp" ] add_field => { "application" => "uknapp" } } } } # 新增:解析JSON格式的日志 else if [path] =~ /\.json$/ { # 匹配.json结尾的日志文件 json { source => "message" # 从message字段读取JSON原始内容 target => "" # 解析后直接将字段放到根级别(不嵌套) } # 可选:删除原message和path字段,避免冗余数据 mutate { remove_field => ["message", "path"] } } }
2. 修正Elasticsearch自定义映射中的错误
你提供的自定义映射里,relatedContent下有两个字段的type是空值,这会导致映射创建失败或异常,需要补全:
"og:description": { "type": "text" }, "og:url": { "type": "text" }
3. 重新导入数据
因为之前写入的日志数据已经被存在message字段里,无法自动拆分,所以需要做以下操作:
- 删除现有错误的索引:
curl -XDELETE http://localhost:9200/logstash-2019.05.09
- 重新创建修正后的自定义映射:
curl -XPUT http://localhost:9200/logstash-2019.05.09 -H "Content-Type: application/json" -d '{ "mappings": { "doc": { "properties": { "@timestamp": { "type": "date" }, "ip": { "type": "ip" }, "extension": { "type": "text" }, "response": { "type": "text" }, "geo": { "coordinates": { "type": "geo_point" }, "src": { "type": "text" }, "dest": { "type": "text" }, "srcdest": { "type": "text" } }, "tags": { "type": "text" }, "utc_time": { "type": "date" }, "referer": { "type": "text" }, "agent": { "type": "text" }, "clientip": { "type": "ip" }, "bytes": { "type": "integer" }, "host": { "type": "text" }, "request": { "type": "text" }, "url": { "type": "text" }, "@message": { "type": "text" }, "spaces": { "type": "text" }, "xss": { "type": "text" }, "links": { "type": "text" }, "relatedContent": { "url": { "type": "text" }, "og:type": { "type": "text" }, "og:title": { "type": "text" }, "og:description": { "type": "text" }, "og:url": { "type": "text" }, "article:published_time": { "type": "date" }, "article:modified_time": { "type": "date" }, "article:section": { "type": "keyword" }, "article:tag": { "type": "text" }, "og:image": { "type": "text" }, "og:image:height": { "type": "integer" }, "og:image:width": { "type": "integer" }, "og:site_name": { "type": "text" }, "twitter:title": { "type": "text" }, "twitter:description": { "type": "text" }, "twitter:card": { "type": "keyword" }, "twitter:image": { "type": "text" }, "twitter:site": { "type": "keyword" } }, "machine": { "os": { "type": "text" }, "ram": { "type": "integer" } }, "@version": { "type": "integer" } } } } }'
- 重启Logstash,让新的filter配置生效,Logstash会重新读取日志文件并解析JSON内容,将字段正确写入Elasticsearch。
验证结果
处理完成后,你可以在Kibana的Discover页面查看文档,应该能看到所有字段都被正确拆分,不再全部堆积在message字段中。
内容的提问来源于stack exchange,提问作者Rodolphe G.
相关产品推荐
相关产品推荐

