logstash是什么就不介绍了,具体看代码
1.input为elasticsearch
input {
elasticsearch {
hosts => "192.168.1.16:9200" //这里是你es的IP地址和端口号
index => "position" //索引名
size => 10000 //每次刷入的量
query => '{"query":{"bool":{"disable_coord":false,"adjust_pure_negative":true,"boost":1}},"_source":{"includes":["_id","ent_status","formatted_address","dom","city","adcode","level","ent_type","city_code","data_date","update_date","pripid","province","entname","district","location"]}}' //需要查询的条件
scroll => "5m"
docinfo => true
}
}
2.filter对input进来的数据做操作
数据格式如下图