filebeat更改mapping 字段类型
采集nginx日志的时候发现从filebeat采集的json日志到elasticsearch里面都是keyword类型,导致我模糊查询部分字段的时候无法模糊匹配,所以需要将某些字段改成text类型。
filebeat.inputs: - type: log enabled: true json.keys_under_root: true json.overwrite_keys: true paths: - "/x/*.log" tags: ["php-nginx-access"] output.elasticsearch: hosts: ["10.8.44.5:9200"] username: "xxx" password: "xxx" indices: - index: "php-nginx-access-%{[agent.version]}-%{+yyyy.MM}" when.contains: tags: "php-nginx-access" setup.template.name: "php-nginx-access" setup.template.pattern: "php-nginx-access-*" setup.template.fields: "myfields.yml" setup.template.overwrite: true setup.template.enabled: true setup.ilm.enabled: false
关键的地方就是修改了fields.yml。
- key: php-nginx-access title: php description: > php access log fields: - name: request type: text ignore_above: 1024 - name: '@timestamp' level: core required: true type: date description: 'Date/time when the event originated. This is the date/time extracted from the event, typically representing when the event was generated by the source. If the event source has no original timestamp, this value is typically populated by the first time the event was received by the pipeline. Required field for all events.' example: '2016-05-23T08:05:34.853Z'
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· AI与.NET技术实操系列:向量存储与相似性搜索在 .NET 中的实现
· 基于Microsoft.Extensions.AI核心库实现RAG应用
· Linux系列:如何用heaptrack跟踪.NET程序的非托管内存泄露
· 开发者必知的日志记录最佳实践
· SQL Server 2025 AI相关能力初探
· 震惊!C++程序真的从main开始吗?99%的程序员都答错了
· 【硬核科普】Trae如何「偷看」你的代码?零基础破解AI编程运行原理
· 单元测试从入门到精通
· winform 绘制太阳,地球,月球 运作规律
· 上周热点回顾(3.3-3.9)