如图所示,尝试了多种时间字段的格式的输入,均发现无法通过时间日期字段检索出日志,只能通过系统名称检索。另外通过“近10分钟”选项检索出来的也不符合时间日期的筛选:
# 示例中发送测试数据的参考脚本中的时间格式
curl -X POST -d '{"system":"demo", "date":"20230816 06:44:54.456,"text":"demo log text"}' \
-H "Content-Type:application/json" http://127.0.0.1:8080/glc/v1/log/add
# filebeat中生成的时间格式
curl -X POST -d '{
"@timestamp": "2023-08-16T06:44:54.389Z",
"@metadata": {
"beat": "filebeat",
"type": "_doc",
"version": "8.9.0"
},
"system": "iot-sync-local-deployment",
"date": "2023-08-16T06:44:54.389Z",
"message": "2023-08-16 06:44:54.386 DEBUG 1 --- [p-nio-80-exec-4] o.s.web.servlet.DispatcherServlet : Completed 200 OK",
"text": "2023-08-16 06:44:54.386 DEBUG 1 --- [p-nio-80-exec-4] o.s.web.servlet.DispatcherServlet : Completed 200 OK"
}' \
-H "Content-Type:application/json" http://127.0.0.1:8080/glc/v1/log/add