Fluentd向CloudWatch发送错误时间的问题及修正方法问询
问题
Fluentd配置中,数据源为syslog,目标插件使用fluent-plugin-cloudwatch-logs,其余功能正常但日志时间存在错误。当前配置如下:
<source> @type syslog <transport tcp> </transport> <parse> message_format auto parser_type string </parse> tag isam </source> <match mysyslog> @type copy <store> @type cloudwatch_logs log_group_name /aws/mysyslog log_stream_name all auto_create_stream true region eu-west-1 include_time_key true localtime true </store> <store> @type http http_method put <format> @type single_value </format> raise_on_error true </store> </match>
CloudWatch中的日志时间超前2小时(显示为未来时间),但摄入时间(ingestion time)正确,示例数据:
ingestion time: 1719208787499 = June 24, 2024, 05:57:26 AM (UTC). timestamp: 1719215985000 = June 24, 2024, 07:57:25 AM time extracted from message: 2024-06-24T07:59:45+00:00 time in message 2024-06-24T07:59:45+00:00
需要将日志时间修正为正确时间(提前2小时)。
解决方案
1. 修正syslog解析的时区配置
当前syslog源的<parse>块未指定时区,可能导致解析出的时间被错误识别为本地时区。在<parse>中添加时区参数,明确消息中的时间为UTC:
<source> @type syslog <transport tcp> </transport> <parse> message_format auto parser_type string timezone UTC </parse> tag isam </source>
2. 调整cloudwatch_logs插件的时区参数
配置中的localtime true会让插件使用Fluentd服务器的本地时区发送时间,若服务器时区非UTC会引发偏移。将该参数改为false,强制使用UTC时间:
<store> @type cloudwatch_logs log_group_name /aws/mysyslog log_stream_name all auto_create_stream true region eu-west-1 include_time_key true localtime false </store>
3. 手动修正时间(若前两步无效)
如果上述调整后仍有时间偏移,添加record_transformer过滤器,手动将日志时间减去2小时(7200秒):
<filter isam> @type record_transformer enable_ruby true <record> time ${Time.at(record["time"].to_i - 7200).iso8601} </record> </filter>
该过滤器需放置在<source>和<match>块之间,确保日志发送到CloudWatch前完成时间修正。
内容的提问来源于stack exchange,提问作者David
相关产品推荐
相关产品推荐

