温馨提示×

ubuntu filebeat怎样过滤日志

小樊
46
2026-09-20 11:13:13
栏目: 智能运维

在 Ubuntu 上使用 Filebeat 过滤日志,通常有两种层面的“过滤”:

  1. 采集层过滤(不发送某些日志)
  2. 处理层过滤(drop / 修改 / 结构化日志)

下面按常见场景说明。


一、Filebeat 基本配置文件位置

Ubuntu 上一般是:

/etc/filebeat/filebeat.yml

修改后重启:

sudo systemctl restart filebeat

二、只采集某些日志(输入过滤)

1️⃣ 使用 paths + exclude_lines

filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/myapp/*.log
  exclude_lines: ['DEBUG']

✅ 含义:

  • 读取 /var/log/myapp/*.log
  • 不包含包含 DEBUG 的行

2️⃣ 只保留某些行(include_lines)

  include_lines: ['ERROR', 'WARN']

✅ 只发送 ERROR / WARN 日志


3️⃣ 排除文件

  exclude_files: ['.gz$', '/var/log/myapp/old/']

三、使用 processors 过滤(推荐)

Filebeat 的 processors 功能更强大。

1️⃣ 丢弃包含某关键字的日志

processors:
  - drop_event.when.contains:
      message: "health check"

2️⃣ 按日志级别丢弃

processors:
  - drop_event.when.regexp:
      message: "^DEBUG"

3️⃣ 多条件过滤

processors:
  - drop_event.when:
      and:
        - contains.message: "test"
        - regexp.level: "DEBUG"

四、结构化日志(JSON / 字段提取)

JSON 日志

filebeat.inputs:
- type: log
  paths:
    - /var/log/app/json.log
  json.keys_under_root: true
  json.add_error_key: true

之后可按字段过滤:

processors:
  - drop_event.when.equals:
      level: "debug"

五、多行日志合并(常见 Java / Python)

multiline.type: pattern
multiline.pattern: '^\d{4}-\d{2}-\d{2}'
multiline.negate: true
multiline.match: after

六、验证配置是否正确

filebeat test config
filebeat test output

七、常见组合示例(实战)

✅ 只发送 ERROR 日志到 ES

filebeat.inputs:
- type: log
  paths:
    - /var/log/app/app.log

processors:
  - drop_event.when.not.contains:
      message: "ERROR"

如果你能告诉我:

  • 日志格式(普通 / JSON)
  • 想过滤什么(关键字 / 级别 / 文件)
  • 输出到哪里(ES / Logstash / Kafka)

我可以直接帮你写一份 可用的 filebeat.yml。

0 踩