1. 程式人生 > >Logstash 配置elasticsearch index欄位與表中欄位重複的問題

Logstash 配置elasticsearch index欄位與表中欄位重複的問題

input{
    file{
        path => ["/tmp/data/t_url.csv"]
        start_position =>"beginning"
      }


}
filter{
    csv{
        separator => "|"
        columns => ["rid","dir","username","sip","sport","dip","dport","bytes","starttime","action","url","descid","domain","type","subtype","words","line","platform","browser","grpids","referer","termtype"]
      }
	  
		
	date {
        match => ["starttime", "yyyy-MM-dd HH:mm:ss"]
        target => "@timestamp"
    }

}
output{
    elasticsearch{
        index => "webdata"
         document_id => "%{rid}" 
		document_type => "url" 
		hosts => ["192.168.1.181:9200"]
		
	}
}

 

 

這個是匯入的模板,原來沒有配置index的值,但是  elasticsearch   自動匹配了欄位裡的index值為預設的index值

經過測試發現可以在 output中新增

        document_type => "url" 

設定對應的type型別