You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Logstash中用正则移除字段键的前缀下划线

Remove Prefix Underscores from Logstash Field Names Without Ruby Filter

Absolutely! You don't need to rely on the Ruby filter to fix this Kibana compatibility issue—Logstash's built-in mutate filter supports regex-based field renaming, which is far more performant than Ruby scripts and perfect for your use case (like cleaning up Docker journald logs).

Here's the efficient solution using native Logstash filters:

Add this mutate block to your Logstash configuration:

mutate {
  rename => {
    "^_(.+)$" => "%{1}"
  }
}

How this works:

  • The regex pattern ^_(.+)$ matches any field name that starts with an underscore.
  • The (.+) captures everything after the leading underscore into a capture group.
  • The value %{1} references that first capture group, so the field gets renamed to whatever came after the leading _ (e.g., _HELO becomes HELO, _MESSAGE becomes MESSAGE, etc.).

Performance Notes:

This uses Logstash's Java-native mutate filter, which is optimized for speed—you won't see the same performance hit you'd get with a Ruby filter. It's fully capable of handling high-volume log streams like Docker's journald output without slowing down your pipeline.

Bonus: Handling Nested Fields (if needed)

If you have nested fields with leading underscores (e.g., [container][_id]), you can adjust the regex to match nested paths:

mutate {
  rename => {
    "^(.+)_(.+)$" => "%{1}%{2}"
  }
}

This will turn [container][_id] into [container][id] by capturing the parent path and the field name without the underscore.

内容的提问来源于stack exchange,提问作者Akash

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:38:13