我在ElasticSearch中记录用户操作,并且我使用C#Log4Net
我正在使用C#NEST库来访问ElasticSearch数据库。
我的日志行如下所示:
{
"_index" : "log-2016.07.27",
"_type" : "logEvent",
"_id" : "AVYrwmW5Hc5CAgECpn_X",
"_score" : 1.0,
"_source" : {
"timeStamp" : "2016-07-27T09:49:35.3774113Z",
"message" : "Upload file operation took 11683 ms",
"loggerName" : "Reviewer.Web.WebApi.GroupsController",
"identity" : "",
"level" : "INFO",
"properties" : {
"log4net:UserName" : "CORP\\g",
"log4net:ElapsedTime" : "11683",
"log4net:Identity" : "",
"IP" : "::1",
"log4net:HostName" : "GBWOTIOM68052D",
"@timestamp" : "2016-07-27T09:49:35.3774113Z"
}
}
我想将log4net:ElapsedTime
值存储为整数而不是字符串。
目前我在存储已用时间时这样做:
long ms = 1000;
LogicalThreadContext.Properties["log4net:ElapsedTime"] = ms;
我知道我应该指定一个模板,以告诉ElasticSearch将经过的值存储为整数但是怎么做?
答案 0 :(得分:1)
如果您希望elasticsearch识别您的字段,则应该发送没有双引号的数据值。
curl -XPUT 'localhost:9200/tmp/tmp/1' -d '{
"field1":"3",
"field2":3
}'
-
curl -XGET 'localhost:9200/tmp'
{"tmp":{"aliases":{},"mappings":{"tmp":{"properties":{"field1":{"type":"string"},"field2":{"type":"long"}}}},"settings":{"index":{"creation_date":"1469621916488","uuid":"Qj64-CU5RUW6ShOyRqLZXQ","number_of_replicas":"0","number_of_shards":"1","version":{"created":"1070599"}}},"warmers":{}}}
您可以看到field1是字符串,但field2是数字。