在 Ubuntu 上使用 Filebeat 过滤日志,通常有两种层面的“过滤”:
下面按常见场景说明。
Ubuntu 上一般是:
/etc/filebeat/filebeat.yml
修改后重启:
sudo systemctl restart filebeat
paths + exclude_linesfilebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/myapp/*.log
exclude_lines: ['DEBUG']
✅ 含义:
/var/log/myapp/*.logDEBUG 的行 include_lines: ['ERROR', 'WARN']
✅ 只发送 ERROR / WARN 日志
exclude_files: ['.gz$', '/var/log/myapp/old/']
Filebeat 的 processors 功能更强大。
processors:
- drop_event.when.contains:
message: "health check"
processors:
- drop_event.when.regexp:
message: "^DEBUG"
processors:
- drop_event.when:
and:
- contains.message: "test"
- regexp.level: "DEBUG"
filebeat.inputs:
- type: log
paths:
- /var/log/app/json.log
json.keys_under_root: true
json.add_error_key: true
之后可按字段过滤:
processors:
- drop_event.when.equals:
level: "debug"
multiline.type: pattern
multiline.pattern: '^\d{4}-\d{2}-\d{2}'
multiline.negate: true
multiline.match: after
filebeat test config
filebeat test output
✅ 只发送 ERROR 日志到 ES
filebeat.inputs:
- type: log
paths:
- /var/log/app/app.log
processors:
- drop_event.when.not.contains:
message: "ERROR"
如果你能告诉我:
我可以直接帮你写一份 可用的 filebeat.yml。