【问题标题】:ConfigurationError in LogstashLogstash 中的配置错误
【发布时间】:2021-09-22 16:18:23
【问题描述】:

当我运行这个配置文件时:

input {
  file {
    path => "/tmp/linuxServerHealthReport.csv"
    start_position => "beginning"
    sincedb_path => "/home/infra/logstash-7.14.1/snowdb/health_check"
  }
  codec => multiline {
    pattern => "\""
    negate => true
    what => previous
  }
}

filter {
  csv {
    columns => ["Report_timestamp","Hostname","OS_Relese","Server_Uptime","Internet_Status","Current_CPU_Utilization","Current_Memory_Utilization","Current_SWAP_Utilization","FS_Utilization","Inode_Utilization","FS_Read_Only_Mode_Status","Disk_Multipath_Status","Besclient_Status","Antivirus_Status","Cron_Service_Status","Nagios_Status","Nagios_Heartbest_Status","Redhat_Cluster_Status"]
    separator => ","
    skip_header => true
  }
  mutate {
    remove_field => ["path", "host"]
  }
  skip_empty_columns => true
  skip_empty_row => true
}

# quote_char => "'"

output {
  stdout { codec => rubydebug }
}

我收到此错误:

错误: [2021-09-22T15:57:04,929][ERROR][logstash.agent] 无法执行操作 {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError" , :message=>“在输入 {\n 文件 {\n\t\tpath => 后,第 7 行第 9 列(字节 226)应为 [ \t\r\n]、“#”、“{”之一"/tmp/linuxServerHealthReport.csv"\n start_position => "开始"\n sincedb_path => "/home/imiinfra/logstash-7.14.1/snowdb/health_check"\n }\n\t\tcodec ", :backtrace =>["/home/imiinfra/logstash-7.14.1/logstash-core/lib/logstash/compiler.rb:32:in compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:在initialize'", "/home/imiinfra/logstash-7.14.1/logstash-core/lib/logstash/java_pipeline.rb:47:in initialize'", "/home/imiinfra/logstash-7.14.1/logstash-core/lib/logstash/pipeline_action/create.rb:52:in execute'", "/home/imiinfra/logstash-7.14.1/logstash-core/lib/logstash/agent.rb:391:in block inverge_state'"]}

【问题讨论】:

  • 第 6 行有一个额外的大括号,这会在编解码器配置之前关闭您的文件输入,删除它并重试。
  • 我已经删除它并尝试过,但它又失败了,所以我在文件部分的最后添加了大括号。它给了我错误。无法执行操作 {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"预期为 [ \\t\\r\\n 之一], \"#\", \"{\" 在第 24 行,第 36 列(字节 1005)过滤后 {\n csv {\n columns => [\"Report_timestamp\",\"Hostname\",\" OS_Relese\",\"Server_Uptime\",\"Internet_Status\",\"Current_CPU_Utilization\",\"Current_Memory_Utilization\",\"Current_SW'"]}

标签: logstash logstash-grok


【解决方案1】:

你必须处理你的格式,但这是我从问题中重建的。主要问题似乎是file 的参数,您出于某种原因将codec 放在file 之外。另一个问题是csv 参数skip_empty_columns 和skip_empty_row 也在csv 之外。

所以我做了一些格式化并修复了这些问题,它现在应该可以工作了。

input {
  file {
    path => "/tmp/linuxServerHealthReport.csv"
    codec => multiline {
      pattern => "\""
      negate => true
      what => previous
    }
    start_position => "beginning"
    sincedb_path => "/home/infra/logstash-7.14.1/snowdb/health_check"
  }
}

filter {
  csv {
    columns => ["Report_timestamp","Hostname","OS_Relese","Server_Uptime","Internet_Status","Current_CPU_Utilization","Current_Memory_Utilization","Current_SWAP_Utilization","FS_Utilization","Inode_Utilization","FS_Read_Only_Mode_Status","Disk_Multipath_Status","Besclient_Status","Antivirus_Status","Cron_Service_Status","Nagios_Status","Nagios_Heartbest_Status","Redhat_Cluster_Status"]
    separator => ","
    skip_header => true
    skip_empty_columns => true
    skip_empty_row => true
  }
  mutate {
    remove_field => ["path", "host"]
  }
}

output {
  stdout { codec => rubydebug }
}

【讨论】:

  • 代码正在运行,但我收到“_csvparsefailure”错误:----------- { "tags" => [ [0] "_csvparsefailure" ], "@版本" => "1", "@timestamp" => 2021-09-23T16:58:06.974Z, "消息" => "'2021.09.13-10.23.31', 'bfaaprdmon01', 'Red Hat Enterprise Linx服务器版本 7.9 (Maipo) ', '28 days', 'Disconnected ', '1% ', '7%', '0%', No FSs has threshold abobe 80%\", \"No FSs Inode has threshold above 80%,'Nll','Mltipath_not_configred','Stopped','Rnning','Rnning','Stopped','Not Configred','Stopped'" } ------------- -
  • 这是一个单独的问题并尝试使用它,您会看到 CSV 存在问题,因此使用filter。在您尝试了几次之后,返回堆栈溢出并提出一个新问题,说明您尝试了什么,并发布您的 CSV,以便我们有一些工作要做。祝你好运!
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 2016-12-28
  • 2020-01-19
  • 1970-01-01
  • 1970-01-01
  • 2020-01-27
  • 1970-01-01
  • 2015-05-30
相关资源
最近更新 更多