在 Debian 上,Filebeat 的“过滤”通常分几种场景,下面按常见用法给你说明,并给出配置示例。
Filebeat 本身不是重度处理器(不像 Logstash),但它支持:
drop_event)drop_fields)if/then)filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/nginx/access.log
exclude_files: ['.gz$']
exclude_files: ['\.tmp$', 'error\.log']
processors:
- drop_event:
when:
contains:
message: "healthcheck"
processors:
- drop_event:
when:
not:
contains:
message: "ERROR"
processors:
- drop_fields:
fields: ["agent.version", "ecs.version"]
processors:
- if:
contains:
message: "DEBUG"
then:
- drop_event: {}
multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
multiline.negate: true
multiline.match: after
output.elasticsearch:
hosts: ["localhost:9200"]
indices:
- index: "nginx-%{+yyyy.MM.dd}"
when.contains:
log.file.path: "/var/log/nginx"
/etc/filebeat/filebeat.yml
重启:
sudo systemctl restart filebeat
测试配置:
sudo filebeat test config
sudo filebeat test output
❌ Filebeat 不能做复杂正则替换
✅ 复杂处理建议:
如果你能告诉我:
我可以直接给你一份可复制的 filebeat.yml。