需要澄清为什么该映射不起作用。
Logstash字段,
"host" => "vzon-pdm-prod.gnm.dns.denc.nka.net"
模板映射:
"host": {"type": "keyword" }
在将映射发送到Elastic时抛出以下错误
Elasticsearch。 {:status => 400,:action => [“ index”,{:_id => nil,:_index =>“ lsh-usa_verizon_core2a_8650sdm_v4-2019.11.23”,:_type =>“ _ doc”,:_routing => nil },#LogStash :: Event:0x7986175f],:response => {“ index” => {“ _ index” =>“ lsh-usa_verizon_core2a_8650sdm_v4-2019.11.23”,“ _type” =>“ _ doc”,“ _id” = >“ B7aMlm4BIqQPqzL49rWu”,“状态” => 400,“错误” => {“类型” =>“ mapper_parsing_exception”,“原因” =>“找不到为[主机]解析的[字符串]类型。”}}}}