【发布时间】:2021-10-11 15:06:28
【问题描述】:
这里是日志 json 字符串的示例,message 字段又是一个 json 字符串。
{
"service_id" => "sec-sip",
"@version" => "1",
"logplane" => "containerlogs",
"componentName" => "container",
"message" => "{"version":"1.0","timestamp":"2021-08-06T13:48:56.640+0000","severity":"info","service_id":"MANAGER@m.syslog","message":"santu testtttttttttttttttttttttt","extra_data":{"manager":{"log_plane":"alarmlogs","alarm_raise_time":"1628251669506","alarm_update_time":"1628257736581","source_type":"MANAGER","alarm_instance_id":"1","alarm_proposed_repair_action":"Informational alarm no action required.","alarm_handler_specific_problem":null,"specific_problem":"Business Logic Updated","event_type":"Processing",}}}",
"version" => "0.2.0",
"timestamp" => "2021-08-06T16:47:13.736Z"
}
我需要在 [extra_data][manager][logplane] == "alarmlogs" 的基础上更改 logplane 值
您能帮我吗,我们如何从消息字段中提取此密钥并应用条件?
我想实现下面给出的。
if [extra_data][manager][logplane] == "alarmlogs" {
mutate {
replace => {"[logplane]" => "informational"}
}
}
【问题讨论】:
标签: logstash logstash-grok logstash-configuration elk logstash-file