You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fluentd向CloudWatch发送错误时间的问题及修正方法问询

问题

Fluentd配置中,数据源为syslog,目标插件使用fluent-plugin-cloudwatch-logs,其余功能正常但日志时间存在错误。当前配置如下:

<source>
  @type syslog
  <transport tcp>
  </transport>
   <parse>
    message_format auto
    parser_type string
  </parse>
  tag isam
</source>


<match mysyslog>
@type copy
<store>
  @type cloudwatch_logs
  log_group_name /aws/mysyslog
  log_stream_name all
  auto_create_stream true
  region eu-west-1
  include_time_key true
  localtime true
  </store>
  <store>
    @type http
    http_method put
    <format>
     @type single_value
    </format>
    raise_on_error true
</store>
</match>

CloudWatch中的日志时间超前2小时(显示为未来时间),但摄入时间(ingestion time)正确,示例数据:

ingestion time: 1719208787499 = June 24, 2024, 05:57:26 AM (UTC).  
timestamp: 1719215985000 = June 24, 2024, 07:57:25 AM
time extracted from message: 2024-06-24T07:59:45+00:00
time in message 2024-06-24T07:59:45+00:00

需要将日志时间修正为正确时间(提前2小时)。

解决方案

1. 修正syslog解析的时区配置

当前syslog源的<parse>块未指定时区,可能导致解析出的时间被错误识别为本地时区。在<parse>中添加时区参数,明确消息中的时间为UTC:

<source>
  @type syslog
  <transport tcp>
  </transport>
   <parse>
    message_format auto
    parser_type string
    timezone UTC
  </parse>
  tag isam
</source>

2. 调整cloudwatch_logs插件的时区参数

配置中的localtime true会让插件使用Fluentd服务器的本地时区发送时间,若服务器时区非UTC会引发偏移。将该参数改为false,强制使用UTC时间:

<store>
  @type cloudwatch_logs
  log_group_name /aws/mysyslog
  log_stream_name all
  auto_create_stream true
  region eu-west-1
  include_time_key true
  localtime false
</store>

3. 手动修正时间(若前两步无效)

如果上述调整后仍有时间偏移,添加record_transformer过滤器,手动将日志时间减去2小时(7200秒):

<filter isam>
  @type record_transformer
  enable_ruby true
  <record>
    time ${Time.at(record["time"].to_i - 7200).iso8601}
  </record>
</filter>

该过滤器需放置在<source>和<match>块之间,确保日志发送到CloudWatch前完成时间修正。

内容的提问来源于stack exchange,提问作者David

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 22:13:25