如何在Databricks笔记本中使用Azure OpenTelemetry将自定义日志写入LAW
基于OpenTelemetry将Azure ADB自定义日志留存至Log Analytics Workspace
前置要求
- 拥有Azure订阅权限,可访问目标Log Analytics Workspace(LAW),并获取其工作区ID和主共享密钥(在LAW的「代理管理」菜单下查看)
- 部署OpenTelemetry Collector(推荐用Azure Monitor OpenTelemetry Distro,适配Azure生态更顺畅)
- 明确Azure ADB自定义日志的输出方式:文件输出、HTTP推送、或ADB原生日志钩子(如Databricks作业日志写入DBFS)
核心配置流程
1. 配置日志采集接收器(Receiver)
根据ADB日志的输出方式选择对应接收器:
场景1:ADB日志写入本地/挂载文件
用filelog接收器监控指定日志文件:
receivers: filelog: include: ["/adb/logs/custom/*.log"] # 替换为ADB自定义日志的实际路径 start_at: beginning operators: - type: regex_parser regex: '^\[(?P<timestamp>.*)\] \[(?P<log_level>INFO|WARN|ERROR)\] (?P<log_content>.*)$' timestamp: parse_from: attributes.timestamp layout: '%Y-%m-%dT%H:%M:%SZ'
场景2:ADB通过HTTP推送日志
用http接收器监听指定端口接收推送:
receivers: http: endpoint: "0.0.0.0:4318" # 可自定义端口,确保ADB能访问该地址
2. 配置LAW导出器(Exporter)
将采集到的日志发送至目标LAW,自定义日志表名(LAW中会自动生成[表名]_CL格式的表):
exporters: azuremonitor/loganalytics: workspace_id: "YOUR_LAW_WORKSPACE_ID" shared_key: "YOUR_LAW_PRIMARY_KEY" log_type: "ADBCustomLogs" # 自定义日志表的基础名称
3. 组装采集管道(Pipeline)
关联接收器、处理器和导出器,实现日志的采集-处理-导出流程:
service: pipelines: logs: receivers: [filelog] # 替换为实际使用的接收器(如http) processors: [batch] exporters: [azuremonitor/loganalytics] processors: batch: timeout: 10s send_batch_size: 100 # 批量发送优化性能
可选:日志字段增强
如果需要给日志添加ADB集群ID、作业ID等元数据,添加attributes处理器:
processors: attributes: actions: - key: adb_cluster_id value: "adb-cluster-001" action: insert - key: adb_job_id from_context: "adb_job_id" # 若从日志上下文获取则用此,否则直接写value action: insert
部署与验证
- 将配置保存为
otel-config.yaml,启动OpenTelemetry Collector:
# 若用二进制包 otelcol --config otel-config.yaml # 若用Docker docker run -v $(pwd)/otel-config.yaml:/etc/otelcol/config.yaml otel/opentelemetry-collector-contrib:latest
- 触发ADB生成自定义日志,等待5-10分钟后,在LAW中执行Kusto查询验证:
ADBCustomLogs_CL | take 10 | project TimeGenerated, log_level_s, log_content_s, adb_cluster_id_s
关键注意事项
- 确保OpenTelemetry Collector能访问ADB的日志源(如文件路径权限、网络端口开放)
- 用Azure Monitor OpenTelemetry Distro可省略部分基础配置,自动适配Azure环境
- 日志格式尽量标准化,便于后续在LAW中进行多维度分析
内容的提问来源于stack exchange,提问作者Shailesh
相关产品推荐
相关产品推荐

