ELK日志集中化部署遇阻:Elasticsearch索引模板加载失败求替代源
Hey there, I’ve dealt with this exact broken link issue when following that older DigitalOcean ELK tutorial — no worries, here are a couple of solid ways to get the Filebeat index template you need:
1. Copy the Template Content Directly
The original gist’s content is still valid for that ELK version. Just create a new file named filebeat-index-template.json and paste this entire JSON into it:
{ "mappings": { "_default_": { "_all": { "enabled": true, "norms": { "enabled": false } }, "dynamic_templates": [ { "message_field": { "match": "message", "match_mapping_type": "string", "mapping": { "type": "string", "index": "analyzed", "omit_norms": true, "fielddata": { "format": "disabled" } } } }, { "string_fields": { "match": "*", "match_mapping_type": "string", "mapping": { "type": "string", "index": "analyzed", "omit_norms": true, "fielddata": { "format": "disabled" }, "fields": { "raw": { "type": "string", "index": "not_analyzed", "ignore_above": 256 } } } } } ], "properties": { "@timestamp": { "type": "date" }, "@version": { "type": "string", "index": "not_analyzed" }, "geoip": { "dynamic": true, "properties": { "ip": { "type": "ip" }, "location": { "type": "geo_point" }, "latitude": { "type": "float" }, "longitude": { "type": "float" } } } } } } }
2. Generate It via Filebeat (If Already Installed)
If you’ve already got Filebeat set up on your Ubuntu 14.04 server, you can have it output the template directly to a file using this command:
filebeat export template > filebeat-index-template.json
This will create the exact template matching your installed Filebeat version, which is even more reliable than the original gist link.
Once you have the template file, you can proceed with the tutorial step to upload it to Elasticsearch using:
curl -XPUT 'http://localhost:9200/_template/filebeat?pretty' -d @filebeat-index-template.json
内容的提问来源于stack exchange,提问作者z.rico

