Kibana以JSON格式记录到Syslog

Jus*_*lly 3 logging syslog kibana

今天,我遍历了ELK堆栈,并且一切正常,但是由于某些原因,Kibana将自己的消息以JSON格式记录到syslog中。例如:

Oct 19 18:49:28 elk-host kibana[11111]: {"type":"response","@timestamp":"2016-10-19T17:49:28+00:00","tags":[],"pid":22749,"method":"post","statusCode":200,"req":{"url":"/elasticsearch/logstash*/_field_stats?level=indices","method":"post","headers":{"host":"1.2.3.4:5601","connection":"keep-alive","content-length":"178","accept":"application/json, text/plain, */*","origin":"http://1.2.3.4:5601","kbn-version":"4.4.2","user-agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36","content-type":"application/json;charset=UTF-8","referer":"http://1.2.3.4:5601/app/kibana","accept-encoding":"gzip, deflate","accept-language":"en-US,en;q=0.8"},"remoteAddress":"5.6.7.8","userAgent":"5.6.7.8","referer":"http://1.2.3.4:5601/app/kibana"},"res":{"statusCode":200,"responseTime":11,"contentLength":9},"message":"POST /elasticsearch/logstash*/_field_stats?level=indices 200 11ms - 9.0B"}
Run Code Online (Sandbox Code Playgroud)

所有其他日志均采用常规格式

这是故意的还是我错过了某个地方的Kibana设置?

如果这是故意的,我可能只会添加一个syslog过滤器以正确记录它...但是希望我不必

Val*_*Val 7

在Kibana配置文件(中的config/kibana.yml)中,您可以添加以下(未记录)设置:

logging.json: false
Run Code Online (Sandbox Code Playgroud)

而且您的Kibana日志将不再格式化为JSON。

  • 不错,谢谢。我还必须添加 `logging.verbose: true` 才能工作。不幸的是,日志仍然包含颜色代码,如:`#033[34m log #033[39m [18:47:39.504]`,但我会浏览源代码,看看是否有办法改变它。无证的东西有点烦人哈哈 (2认同)