【发布时间】:2021-06-07 07:35:03
【问题描述】:
我正在尝试在将 logstash 中的一些电子邮件发送到 ES 之前对其进行过滤。
我有一个字段仍然包含电子邮件地址,并且无法通过 mutate 过滤器对其进行 gsub。
mutate {
gsub => [
"log", "[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}", "--- FILTERED FROM LOGS ---",
"message", "[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}", "--- FILTERED FROM LOGS ---"
]
}
JSON:
{
"_index": "logs-2021.03.09.11",
"_type": "doc",
"_id": "sdfsdf",
"_version": 1,
"_score": null,
"_source": {
"source": "stderr",
"@timestamp": "2021-03-09T11:39:38.413Z",
"kubernetes": {
"namespace": "sdfsdk",
"labels": {
"pod-template-hash": "sdfsdf",
"app": {
"softwear": {
"co/name": "sdfsd",
"co/domain": "sdfsdf"
}
},
"log": {
"extra_fields": {
"ctxt_response": "{\"records_id\":[{\"ext_id\":\"sdfsdf\",\"fcc_id\":sdfsdfsd,\"external_id\":\"sdfsdf\"}],\"success\":true}",
"requestDevice": "\"\"",
"ctxt_request": "{\"hash\":\"56kdfhsdfjshdkf\",\"change\":\"sdsd\",\"campaigns_id\":114,\"method\":\"sha1\",\"login\":\"test\",\"records\":[{\"emails\":[\"email-to-delete@gmail.com\"],\"external_id\":\"sdsdK\"}]}",
"ctxt_response_code": "200"
},
我怎样才能得到嵌套字段并 gsub 呢? [日志][额外字段][ctxt_request]
【问题讨论】:
标签: regex filter logstash gsub