为什么logstash合并表?

时间:2017-07-13 16:09:31

标签: elasticsearch logstash logstash-configuration logstash-jdbc

我有两个配置文件,每个配置文件指向数据库的不同表,但在elasticsearch中,我得到两个表合并,因此,tablea和tableb项将全部复制为typea,tablea和tableb项将全部被复制为typeb。

但我配置它将tablea作为typea和tableb作为typeb。

这是我的配置文件

input {

    jdbc {
        jdbc_driver_library => "/usr/share/logstash/mysql-connector-java-5.1.42-bin.jar"
        jdbc_driver_class => "com.mysql.jdbc.Driver"
        jdbc_connection_string => "jdbc:mysql://db:3306/nombase"
        jdbc_user => "root"
        jdbc_password => "root"
        schedule => "* * * * *"
        statement => "SELECT * FROM `tablecandelete`"
    }

}


## Add your filters / logstash plugins configuration here


output {

    stdout { codec => json_lines }

    if [deleted] == 1 {
        elasticsearch {
            hosts => "elasticsearch:9200"
            index => "nombase"
            document_type => "tablecandelete"

            ## TO PREVENT DUPLICATE ITEMS
            document_id => "tablecandelete-%{id}"
            action => "delete"
        }
    } else {
        elasticsearch {
            hosts => "elasticsearch:9200"
            index => "nombase"
            document_type => "tablecandelete"

            ## TO PREVENT DUPLICATE ITEMS
            document_id => "tablecandelete-%{id}"
        }
    }

}

这是我的配置文件b

input {

    jdbc {
        jdbc_driver_library => "/usr/share/logstash/mysql-connector-java-5.1.42-bin.jar"
        jdbc_driver_class => "com.mysql.jdbc.Driver"
        jdbc_connection_string => "jdbc:mysql://db:3306/nombase"
        jdbc_user => "root"
        jdbc_password => "root"
        schedule => "* * * * *"
        statement => "SELECT * FROM `nomtable`"
    }

}


## Add your filters / logstash plugins configuration here


output {

    stdout { codec => json_lines }

    elasticsearch {
        hosts => "elasticsearch:9200"
        index => "nombase"
        document_type => "nomtable"

        ## TO PREVENT DUPLICATE ITEMS
        document_id => "nomtable-%{id}"
    }

}

有人有想法吗?感谢您的回复/帮助

1 个答案:

答案 0 :(得分:1)

虽然您有两个不同的配置文件,但是logstash并不将它们视为独立的 - 您可以将所有输入放在一个文件中,将所有输出放在另一个文件中。

要分离出来,您必须在每个输入上添加type => something_unique,然后使用

包围配置文件中的剩余代码
if [type] == 'something_unique' { 
  // config here 
}