本文使用修改時間modify_date
作為增量同步檢測字段,可檢測新增和修改,檢測不到刪除,檢測刪除請使用canal查詢binlog日志同步數據
檢測修改時間字段為varchar的時候可以先創建索引,并設置對應的mapping為(可以無視時區問題)
...
"time": {"type": "date","format": "yyyy-MM-dd HH:mm:ss||strict_date_optional_time||epoch_millis"}...
檢測修改時間字段為datetime的時候需要注意時區問題
前提:正常存儲時間,mysql是UTC+8,Logstash 和ES則都使用UTC
下面幾個測試得出的結論
使用測試4,不需要考慮客戶端連接es的時區問題(直觀上忽略es存儲的時間格式為UTC,把其當作UTC+8來用)
使用測試1,需要注意es中存儲UTC,使用客戶端client連接時需要轉換對應的事件UTC+8轉為UTC
SearchRequest searchRequest = new SearchRequest("stu_sign");
SearchSourceBuilder searchSourceBuilder = new SearchSourceBuilder();
LocalDateTime localDateTime1 = LocalDateTime.of(2021, 1, 1, 8, 0, 0);
LocalDateTime localDateTime2 = LocalDateTime.of(2023, 3, 1, 8, 0, 0);
ZonedDateTime zonedDateTime1 = localDateTime1.atZone(ZoneId.of("UTC+8"));
ZonedDateTime zonedDateTime2 = localDateTime2.atZone(ZoneId.of("UTC+8"));// 將ZonedDateTime轉換為UTC時區
ZonedDateTime utcZonedDateTime1 = zonedDateTime1.withZoneSameInstant(ZoneId.of("UTC"));
ZonedDateTime utcZonedDateTime2 = zonedDateTime2.withZoneSameInstant(ZoneId.of("UTC"));searchSourceBuilder.query(QueryBuilders.rangeQuery("sing_date").gte(utcZonedDateTime1).lte(utcZonedDateTime2));
searchRequest.source(searchSourceBuilder);
try {SearchResponse searchResponse = restHighLevelClient.search(searchRequest, RequestOptions.DEFAULT);System.out.println(searchResponse.getHits().getHits());
} catch (IOException e) {e.printStackTrace();
}
測試1:
不創建mapping
設置時區都為Asia/Shanghai,ES中存儲時間均為UTC,比正常少八個小時,
追蹤日志記錄時間為UTC:
— !ruby/object:DateTime ‘2024-12-31 02:13:30.000000000 Z’
定時任務執行正常
SELECT count(*) AS count
FROM (SELECT * FROM stu_sign_2023202401
WHERE modify_date > ‘2024-12-31 10:13:30’ AND modify_date < NOW() ) AS t1
LIMIT 1
配置文件為:
input {jdbc {# 配置數據庫信息jdbc_connection_string => "jdbc:mysql://188.18.66.185:3306/eschool?useUnicode=true&characterEncoding=UTF-8&serverTimezone=Asia/Shanghai"jdbc_driver_class => "com.mysql.cj.jdbc.Driver"jdbc_user => "root"jdbc_password => "123456"jdbc_paging_enabled => "true"jdbc_page_size => "50000"jdbc_default_timezone => "Asia/Shanghai"# mysql驅動所在位置jdbc_driver_library => "D:\environment\apache-maven-3.8.8\maven_repository\mysql\mysql-connector-java\8.0.27\mysql-connector-java-8.0.27.jar"#sql執行語句statement => "SELECT * FROM `stu_sign_2023202401` WHERE modify_date > :sql_last_value AND modify_date < NOW() "use_column_value => truetracking_column => "modify_date"tracking_column_type => "timestamp"last_run_metadata_path => "E:\software\logstash\last_run_stu_login.txt"schedule => "*/3 * * * * Asia/Shanghai"lowercase_column_names => false}
}output {elasticsearch {hosts => ["127.0.0.1:9200"]index => "stu_sign_test"# document_id => "%{id}"}stdout {codec => json_lines}
}
測試2:
使用mapping,將自動映射的date轉為其他允許的時間格式
"modify_date": {"type": "date","format": "yyyy-MM-dd HH:mm:ss||strict_date_optional_time||epoch_millis"}
與測試1結果完全一致
測試3:
不使用mapping,時間日期調整
mysql中時間為"modify_date":“2024-12-31 10:13:30”
ES記錄時間多8個小時:“modify_date”:“2024-12-31T18:13:30.000Z”
{"id":20120,"appeal_time":null,"teacher_name":"黃雅平","stu_id":736,"stu_name":"鄭欣欣","modify_date":"2024-12-31T18:13:30.000Z","sing_date":"2024-12-31T18:13:30.000Z","teach_time":"2024-12-31T08:00:00.000Z","teach_time_str":"20241231","stu_sign_status":0,"@timestamp":"2025-04-01T01:54:25.599Z","teacher_id":731,"@version":"1","class_num_end":null,"leave_status":null,"sign_status":0,"stu_num":"20233003","course_name":"數字系統基礎","appeal_msg":null,"course_sched_id":186641,"grade_id":"DE44AF38ADB74D9BBF42A6C8285B8285","appeal_status":null,"academy_id":471,"classroom_id":440428,"roll_call_status":0,"roll_call_date":"2024-12-31T18:13:30.000Z","classroom":"304","class_end_time":"2024-12-31 18:30:00","create_date":"2024-12-31T18:13:30.000Z","course_id":1373,"academy_superior_id":6,"late_status":null,"sign_type":null,"class_id":5407,"class_num_begin":null,"class_begin_time":"2024-12-31 16:35:00","semester_id":1,"leave_statusersss":null,"leave_statuser":null}
追蹤日志記錄為— !ruby/object:DateTime ‘2024-12-31 18:13:30.000000000 Z’
執行sql為:SELECT count(*) AS count
FROM (SELECT * FROM stu_sign_2023202401
WHERE modify_date > ‘2024-12-31 18:13:30’ AND modify_date < NOW() ) AS t1
LIMIT 1
對應的配置文件為:
input {jdbc {# 配置數據庫信息jdbc_connection_string => "jdbc:mysql://188.18.66.185:3306/eschool?useUnicode=true&characterEncoding=UTF-8&serverTimezone=UTC"jdbc_driver_class => "com.mysql.cj.jdbc.Driver"jdbc_user => "root"jdbc_password => "123456"jdbc_paging_enabled => "true"jdbc_page_size => "50000"jdbc_default_timezone => "UTC"# mysql驅動所在位置jdbc_driver_library => "D:\environment\apache-maven-3.8.8\maven_repository\mysql\mysql-connector-java\8.0.27\mysql-connector-java-8.0.27.jar"#sql執行語句statement => "SELECT * FROM `stu_sign_2023202401` WHERE modify_date > :sql_last_value AND modify_date < NOW() "use_column_value => truetracking_column => "modify_date"tracking_column_type => "timestamp"last_run_metadata_path => "E:\software\logstash\last_run_stu_login.txt"schedule => "*/3 * * * * Asia/Shanghai"lowercase_column_names => false}
}
測試4:
不使用mapping,時間日期調整
mysql中時間為"modify_date":“2024-12-31 10:13:30”
ES記錄時間:“modify_date”:“2024-12-31T10:13:30.000Z”
{"teacher_id":731,"class_num_end":null,"stu_sign_status":0,"roll_call_status":0,"semester_id":1,"stu_id":749,"leave_statusersss":null,"classroom_id":440428,"course_sched_id":186641,"teacher_name":"黃雅平","create_date":"2024-12-31T10:13:30.000Z","appeal_msg":null,"appeal_status":null,"class_end_time":"2024-12-31 18:30:00","modify_date":"2024-12-31T10:13:30.000Z","class_begin_time":"2024-12-31 16:35:00","leave_statuser":null,"teach_time":"2024-12-31T00:00:00.000Z","appeal_time":null,"academy_superior_id":6,"sign_type":null,"roll_call_date":"2024-12-31T10:13:30.000Z","late_status":null,"classroom":"304","@timestamp":"2025-04-01T02:03:36.223Z","class_id":5407,"stu_num":"2024008","@version":"1","id":20107,"teach_time_str":"20241231","sign_status":0,"sing_date":"2024-12-31T10:13:30.000Z","course_name":"數字系統基礎","course_id":1373,"stu_name":"張恒","class_num_begin":null,"academy_id":471,"leave_status":null,"grade_id":"DE44AF38ADB74D9BBF42A6C8285B8285"}
追蹤日志記錄為— !ruby/object:DateTime ‘2024-12-31 10:13:30.000000000 Z’
執行sql為:SELECT count(*) AS count
FROM (SELECT * FROM stu_sign_2023202401
WHERE modify_date > ‘2024-12-31 10:13:30’ AND modify_date < NOW() ) AS t1
LIMIT 1
對應的配置文件為:
input {jdbc {# 配置數據庫信息jdbc_connection_string => "jdbc:mysql://188.18.66.185:3306/eschool?useUnicode=true&characterEncoding=UTF-8&serverTimezone=Asia/Shanghai"jdbc_driver_class => "com.mysql.cj.jdbc.Driver"jdbc_user => "root"jdbc_password => "123456"jdbc_paging_enabled => "true"jdbc_page_size => "50000"jdbc_default_timezone => "UTC"# mysql驅動所在位置jdbc_driver_library => "D:\environment\apache-maven-3.8.8\maven_repository\mysql\mysql-connector-java\8.0.27\mysql-connector-java-8.0.27.jar"#sql執行語句statement => "SELECT * FROM `stu_sign_2023202401` WHERE modify_date > :sql_last_value AND modify_date < NOW() "use_column_value => truetracking_column => "modify_date"tracking_column_type => "timestamp"last_run_metadata_path => "E:\software\logstash\last_run_stu_login.txt"schedule => "*/3 * * * * Asia/Shanghai"lowercase_column_names => false}
}
時間配置正確符合預期需求
其中定時任務配置
schedule => “/3 * * * * Asia/Shanghai"
schedule => "/3 * * * * UTC”
schedule => "*/3 * * * * "
效果一致
測試5:
不使用mapping,時間日期調整
與測試1相反,時間都調整為UTC的時候,es儲存的時間均多出八個小時
如下:
mysql中時間為"modify_date":“2024-12-31 18:13:30”
ES記錄時間:“modify_date”:“2024-12-31T18:13:30.000Z”
追蹤日志記錄為— !ruby/object:DateTime ‘2024-12-31 18:13:30.000000000 Z’
執行sql為:SELECT count(*) AS count
FROM (SELECT * FROM stu_sign_2023202401
WHERE modify_date > ‘2024-12-31 18:13:30’ AND modify_date < NOW() ) AS t1
LIMIT 1
可自行得出結論:
jdbc_connection_string和jdbc_default_timezone需要配合使用,效果會疊加。具體為什么會這樣?懂得兄弟可以在評論區解釋一下,博主也學習學習
本文環境相關:
elasticsearch-7.16.3
kibana-7.16.3-windows-x86_64
logstash-7.16.3
mysql5.7.38
客戶端:RestHighLevelClient
<dependency><groupId>org.elasticsearch.client</groupId><artifactId>elasticsearch-rest-high-level-client</artifactId><version>7.16.3</version></dependency>
啟動命令:
logstash.bat -f E:\software\logstash\logstash-7.16.3\conf\stu_sign.conf
最后附上配置文件解釋
Logstash配置文件conf介紹:
input {jdbc {# mysql 數據庫鏈接jdbc_connection_string => "jdbc:mysql:localhost/database?characterEncoding=utf8"# 用戶名和密碼jdbc_user => "xxx"jdbc_password => "xxxx"# 驅動jdbc_driver_library => "D:/xx/xx/logstash-6.2.4/config/mysql-connector-java-8.0.18.jar"# 驅動類名jdbc_driver_class => "com.mysql.jdbc.Driver"jdbc_paging_enabled => "true"jdbc_page_size => "50000"# 執行的sql 文件路徑+名稱#statement_filepath => ""parameters => { "sql_last_value" => "UpdateTime" }statement => "SELECT * FROM (SELECT * FROM table1 ) t WHERE t.updatetime > :sql_last_value"# 設置監聽間隔 各字段含義(由左至右)分、時、天、月、年,全部為*默認含義為每分鐘都更新schedule => "* * * * *"# 索引類型#type => "article"# 防止自動將大小轉為小寫lowercase_column_names => false# 記錄上一次運行記錄record_last_run => true# 使用字段值use_column_value => true# 追蹤字段名tracking_column => "updatetime"# 字段類型tracking_column_type => "timestamp"# 上一次運行元數據保存路徑last_run_metadata_path => "./logstash_last_id"# 是否刪除記錄的數據clean_run => false}
}
filter {json {source => "message"remove_field => ["message"]}
}
output {elasticsearch {hosts => "http://localhost:9200/"index => "indexname"document_type => "articles"document_id => "%{articleid}"template_overwrite => true}# 這里輸出調試,正式運行時可以注釋掉stdout {codec => json_lines}
}