You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ELK新手求助:如何移除Filebeat的id、hostname等标签?

Hey there! 作为ELK新手,要移除这些不需要的字段/标签其实很简单,咱们可以从Filebeat配置和Logstash Filter两个层面入手,一步步来:

一、在Filebeat中移除自带的字段(id、hostname、version)

Filebeat默认会给每条日志添加beat.id、beat.hostname、beat.version这些嵌套字段,咱们可以通过配置processors来直接丢弃它们,修改你的Filebeat配置如下:

filebeat.prospectors:
  - input_type: log
    paths:
      - /opt/apache-tomcat-7.0.82/logs/*.log
    document_type: apache-access
    fields_under_root: true
    # 新增处理器,移除指定的beat自带字段
    processors:
      - drop_fields:
          fields: ["beat.id", "beat.hostname", "beat.version"]

注意:这些字段默认是嵌套在beat对象下的,所以要写完整的字段路径;如果你的配置里有其他自定义的不需要字段,也可以加到fields列表里一起移除。

二、在Logstash中处理grok_failure及残留字段

grok_failure(准确说是Logstash默认生成的_grokparsefailure标签)是当grok匹配失败时自动添加的,另外如果Filebeat端没删干净的字段,也可以在Logstash里二次处理:

1. 移除_grokparsefailure标签

如果不想保留匹配失败的标签,直接在filter里添加mutate插件移除:

filter {
  grok {
    match => [ "message", "your-complete-grok-pattern-here" ]
  }
  
  # 移除grok匹配失败的标签
  mutate {
    remove_tag => ["_grokparsefailure"]
  }
}

2. 移除其他残留字段

如果还有Filebeat端没删干净的字段,或者其他不需要的字段(比如原始的message字段,如果你已经解析完了),也可以用mutate的remove_field来处理:

filter {
  grok {
    match => [ "message", "your-complete-grok-pattern-here" ]
  }
  
  mutate {
    # 移除grok失败标签
    remove_tag => ["_grokparsefailure"]
    # 移除不需要的字段
    remove_field => ["beat.id", "beat.hostname", "beat.version", "message"]
  }
}

小提示

如果只想在grok匹配成功时移除某些字段,可以加个条件判断:

if "_grokparsefailure" not in [tags] {
  mutate {
    remove_field => ["message"]
  }
}

这样配合下来,就能彻底移除你提到的那些不需要的标签和字段啦!

内容的提问来源于stack exchange,提问作者Ashok Reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:17:12