温馨提示×

debian中filebeat怎么过滤日志

小樊
34
2026-10-09 09:11:16
栏目: 智能运维

在 Debian 上,Filebeat 过滤日志通常不是“删除文件”,而是在采集阶段或输出前对日志进行过滤、丢弃、加工。常见做法有 4 种,从简单到高级:


一、使用 exclude_lines / include_lines(最常用)

1️⃣ 忽略某些行(正则匹配)

filebeat.inputs:
- type: log
  paths:
    - /var/log/app/*.log
  exclude_lines: ['^DEBUG', '^TRACE']

含义:

  • 以 DEBUG 或 TRACE 开头的行 不会被采集

2️⃣ 只采集某些行

include_lines: ['^ERROR', '^WARN']

✅ 适合简单日志过滤
❌ 不能做复杂逻辑


二、使用 exclude_files(忽略整个文件)

filebeat.inputs:
- type: log
  paths:
    - /var/log/app/*.log
  exclude_files: ['.gz$', 'access.log']

忽略:

  • 压缩文件
  • 特定文件名

三、使用 Processors(推荐,功能强)

Filebeat 内置 processors,在发送前处理事件。

示例 1:丢弃 DEBUG 日志

processors:
  - drop_event:
      when:
        regexp:
          message: '^DEBUG'

示例 2:只保留 ERROR / WARN

processors:
  - drop_event:
      when:
        not:
          regexp:
            message: '^(ERROR|WARN)'

示例 3:给日志加字段

processors:
  - add_fields:
      target: ''
      fields:
        env: production

四、使用 fields + Logstash(高级)

如果你后面接 Logstash / Elasticsearch:

Filebeat 打标签

fields:
  log_type: nginx

Logstash 再过滤

filter {
  if [log_type] == "nginx" {
    grok { ... }
  }
}

五、Debian 上的配置位置

通常:

/etc/filebeat/filebeat.yml

修改后重启:

sudo systemctl restart filebeat

验证配置:

sudo filebeat test config
sudo filebeat test output

六、常见组合示例 ✅

filebeat.inputs:
- type: log
  paths:
    - /var/log/myapp/*.log
  exclude_lines: ['^DEBUG']

processors:
  - drop_event:
      when:
        regexp:
          message: 'healthcheck'

总结

需求 推荐方式
忽略某类日志 exclude_lines
忽略文件 exclude_files
复杂过滤 processors
后续分析 Filebeat + Logstash

如果你是 Nginx / Docker / Java / 系统日志,可以告诉我具体场景,我可以直接给你一份可用配置。

0 踩