在 Debian 上,Filebeat 过滤日志通常不是“删除文件”,而是在采集阶段或输出前对日志进行过滤、丢弃、加工。常见做法有 4 种,从简单到高级:
exclude_lines / include_lines(最常用)filebeat.inputs:
- type: log
paths:
- /var/log/app/*.log
exclude_lines: ['^DEBUG', '^TRACE']
含义:
DEBUG 或 TRACE 开头的行 不会被采集include_lines: ['^ERROR', '^WARN']
✅ 适合简单日志过滤
❌ 不能做复杂逻辑
exclude_files(忽略整个文件)filebeat.inputs:
- type: log
paths:
- /var/log/app/*.log
exclude_files: ['.gz$', 'access.log']
忽略:
Filebeat 内置 processors,在发送前处理事件。
processors:
- drop_event:
when:
regexp:
message: '^DEBUG'
processors:
- drop_event:
when:
not:
regexp:
message: '^(ERROR|WARN)'
processors:
- add_fields:
target: ''
fields:
env: production
fields + Logstash(高级)如果你后面接 Logstash / Elasticsearch:
fields:
log_type: nginx
filter {
if [log_type] == "nginx" {
grok { ... }
}
}
通常:
/etc/filebeat/filebeat.yml
修改后重启:
sudo systemctl restart filebeat
验证配置:
sudo filebeat test config
sudo filebeat test output
filebeat.inputs:
- type: log
paths:
- /var/log/myapp/*.log
exclude_lines: ['^DEBUG']
processors:
- drop_event:
when:
regexp:
message: 'healthcheck'
| 需求 | 推荐方式 |
|---|---|
| 忽略某类日志 | exclude_lines |
| 忽略文件 | exclude_files |
| 复杂过滤 | processors |
| 后续分析 | Filebeat + Logstash |
如果你是 Nginx / Docker / Java / 系统日志,可以告诉我具体场景,我可以直接给你一份可用配置。