FluentBit向Splunk导入日志时出现Connection reset by peer错误的排查求助
FluentBit向Splunk导入日志时出现Connection reset by peer错误的排查求助
大家好,我现在遇到一个棘手的问题,想请各位帮忙排查一下:我们正在测试通过FluentBit把日志导入Splunk,测试环境里两者都是运行在同一个K8s集群、同一个命名空间下的Pod,但一直收到**"Recv failure: Connection reset by peer"**的错误。我已经做了一些尝试来定位问题,具体过程如下:
第一步:从日志采集Pod向Splunk Pod发起CURL测试
我在负责采集日志的Pod里执行了以下curl命令:
curl -vvv http://splunk-deployment-server-service.devnamespace.svc:8089/services/collector \ -H 'Authorization: Welcome1' \ -d '{"sourcetype": "manual-testing", "event":"Hello Splunk, World!", "index":"cf"}'
得到的输出是:
Trying 172.20.5.31... TCP_NODELAY set Connected to splunk-deployment-server-service.devnamespace.svc (172.20.5.31) port 8089 (#0) > POST /services/collector HTTP/1.1 > Host: splunk-deployment-server-service.devnamespace.svc:8089 > User-Agent: curl/7.61.1 > Accept: */* > Authorization: Welcome1 > Content-Length: 78 > Content-Type: application/x-www-form-urlencoded > * upload completely sent off: 78 out of 78 bytes * Recv failure: Connection reset by peer * Closing connection 0 curl: (56) Recv failure: Connection reset by peer
第二步:在Splunk Pod内部执行本地CURL测试
为了排除网络连通性的问题,我直接进入Splunk Pod内部,执行了本地的curl命令:
curl -vvv http://localhost:8089/services/collector \ -H 'Authorization: Welcome1' \ -d '{"sourcetype": "manual-testing", "event":"Hello Splunk, World!", "index":"cf"}'
结果还是得到了相同的错误:
Trying 127.0.0.1... TCP_NODELAY set Connected to localhost (127.0.0.1) port 8089 (#0) > POST /services/collector HTTP/1.1 > Host: localhost:8089 > User-Agent: curl/7.61.1 > Accept: */* > Authorization: Welcome1 > Content-Length: 78 > Content-Type: application/x-www-form-urlencoded > upload completely sent off: 78 out of 78 bytes Recv failure: Connection reset by peer Closing connection 0 curl: (56) Recv failure: Connection reset by peer
使用的版本信息
- Splunk 9.1.0.1
- Fluent Bit v2.0.4
请问各位,我到底哪里做错了?希望能得到大家的指点,谢谢!
备注:内容来源于stack exchange,提问作者Balaji Krishnan
相关产品推荐
相关产品推荐

