watcher的配置可參照:https://kibana.logstash.es/content/elasticsearch/other/watcher.htmlhtml
按照指南中操做後,transform中的查詢會觸發該錯誤,將字段名後追加.raw便可。該例中:filename =》 filename.rawapi
watcher的郵件配置請參照【https://www.elastic.co/guide/en/watcher/2.4/email-services.html】,追加到elasticsearch.yml文件後,watcher前必須加空格,不然啓動elasticsearch將出錯。app
watcher.actions.email.service.account: work: profile: gmail email_defaults: from: 'John Doe <john.doe@host.domain>' bcc: archive@host.domain smtp: auth: true starttls.enable: true host: smtp.gmail.com port: 587 user: <username> password: <password>