Logstash拆分单元素数组出现NilClass错误,日志导入ES遇阻
Hey there, let's break down why you're hitting that NilClass error and how to fix it!
1. The Root Cause: Invalid JSON Format
First off, your sample JSON has a critical syntax issue — string values aren't wrapped in double quotes. JSON requires all string keys and values to be enclosed in " (double quotes), but your data has unquoted values like chirs and dave.
When Logstash's json filter tries to parse this invalid JSON, it fails completely. That means the [student] field never gets created in the event, so when the split filter tries to process [student], it's working with a nil value — hence the NilClass error.
Corrected Sample JSON
{"student":[{"details":{"name":"chirs","lname":"dave"},"age":10,"grade":1.2,"id":"323"}],"id":"metric95"}
2. Hardening Your Logstash Configuration
Even after fixing the JSON, it's smart to make your pipeline more resilient to bad data. Here's an improved config with safeguards:
input { beats { port => "5044" } } filter { json { source => "message" tag_on_failure => ["json_parse_failed"] # Tag failed parses for easy debugging } # Only run split if [student] exists (avoids NilClass errors) if [student] { split { field => "[student]" } } } output { elasticsearch { hosts => [ "localhost:9200" ] } stdout { codec => rubydebug } }
3. What This Does
- Valid JSON: Ensures the
jsonfilter can successfully parse your data and create the[student]field needed for splitting. - Failure Tagging: The
tag_on_failureadds a clear tag to any event that fails JSON parsing, so you can easily track down and fix bad logs in Elasticsearch or stdout. - Conditional Split: The
if [student]check ensures we only run the split filter when the field actually exists, eliminating the NilClass error entirely.
If you still run into issues, check your Logstash logs (usually at /var/log/logstash/logstash-plain.log by default) — they'll show exactly why parsing is failing if there are other hidden JSON syntax issues.
内容的提问来源于stack exchange,提问作者ChrisDave

