如何配置Unified CloudWatch Agent仅发送新增日志?
Unified CloudWatch Agent 避免重复日志配置方案
Unified CloudWatch Agent 支持和旧版相同的 initial_position 配置参数,设置为 end_of_file 即可实现仅发送新增日志行,避免重复推送整个文件内容。
修改后的配置文件
将 initial_position 参数添加到日志收集列表的条目里,示例如下:
"logs": { "logs_collected": { "files": { "collect_list": [ { "file_path": "<path>/test.log", "log_group_name": "test.log", "log_stream_name": "test.{date}", "timestamp_format": "%Y/%m/%d %H:%M:%S.%f", "initial_position": "end_of_file" } ] } } }
关键说明
initial_position: end_of_file:Agent 启动时会从日志文件的当前末尾位置开始读取,不会发送已存在的历史日志内容;如果需要首次推送全部历史日志,可将值设为start_of_file,但后续新增日志仍会仅推送增量。- 确保 Agent 状态文件目录有读写权限:Unified CloudWatch Agent 会将日志读取位置记录在状态文件中(Linux 路径为
/var/lib/awslogs/state/agent-state,Windows 路径为C:\ProgramData\Amazon\CloudWatchAgent\state\agent-state),若该文件无法正常读写,Agent 重启后会重新从头读取日志文件,导致重复推送。
修改配置后重启 CloudWatch Agent,新增日志内容即可仅推送增量,不会出现重复的历史日志条目。
内容的提问来源于stack exchange,提问作者Mozz
相关产品推荐
相关产品推荐

