Logstash 配置elasticsearch index欄位與表中欄位重複的問題
阿新 • • 發佈:2018-11-28
input{ file{ path => ["/tmp/data/t_url.csv"] start_position =>"beginning" } } filter{ csv{ separator => "|" columns => ["rid","dir","username","sip","sport","dip","dport","bytes","starttime","action","url","descid","domain","type","subtype","words","line","platform","browser","grpids","referer","termtype"] } date { match => ["starttime", "yyyy-MM-dd HH:mm:ss"] target => "@timestamp" } } output{ elasticsearch{ index => "webdata" document_id => "%{rid}" document_type => "url" hosts => ["192.168.1.181:9200"] } }
這個是匯入的模板,原來沒有配置index的值,但是 elasticsearch 自動匹配了欄位裡的index值為預設的index值
經過測試發現可以在 output中新增
document_type => "url"
設定對應的type型別