ElasticSearch 6.2.4创建Filebeat索引模板报错求助
解决Elasticsearch 6.2.4创建Filebeat索引模板的
string类型错误 这个问题我之前帮不少开发者解决过,核心原因很明确——Elasticsearch 6.x 已经彻底废弃了旧的string字段类型,而你用的Filebeat索引模板里还在沿用这个过时的定义,所以ES才会抛出No handler for type [string]的错误。
具体解决步骤:
修改Filebeat索引模板中的字段类型
找到你的Filebeat模板文件(通常是filebeat.template.json),把所有"type": "string"的定义替换成ES 6.x支持的类型:- 对于需要全文检索的字段(比如
message),改用text类型,同时可以附加keyword子字段支持精确匹配:"message": { "type": "text", "norms": false, "fields": { "keyword": { "type": "keyword", "ignore_above": 256 } } } - 对于只需要精确匹配的字段(比如标签、ID类字段),直接改用
keyword类型即可。
- 对于需要全文检索的字段(比如
重新加载索引模板
先删除已经存在的错误模板(如果已经创建):curl -XDELETE 'http://你的ES地址:9200/_template/filebeat-*'再上传修改后的模板:
curl -XPUT 'http://你的ES地址:9200/_template/filebeat' -H 'Content-Type: application/json' -d @filebeat.template.json版本匹配建议
尽量保证Filebeat版本和Elasticsearch版本同属6.x系列,新版本的Filebeat会自动生成适配ES 6.x的模板,避免手动修改的麻烦。如果你的Filebeat版本过老,建议升级到对应6.x版本。
内容的提问来源于stack exchange,提问作者invisal
相关产品推荐
相关产品推荐

