You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Terraform配置Azure DCR对接自定义JSON日志(LA Agent转AMA)

解决自定义JSON日志的Azure DCR Terraform配置问题

针对你的场景,需要调整data_sources中log_file的格式配置,并添加必要的转换规则来正确解析JSON日志并映射到自定义日志表。以下是修正后的完整配置及关键说明:

修正后的Data Collection Rule(DCR)Terraform代码

resource "azurerm_monitor_data_collection_rule" "example-dcr-terraform" {
  name                        = "example-dcr-terraform"
  resource_group_name         = module.example.rg.name
  location                    = module.example.rg.location
  data_collection_endpoint_id = azurerm_monitor_data_collection_endpoint.example-dce-terraform.id

  destinations {
    log_analytics {
      name                  = "example-destination-log"
      workspace_resource_id = azurerm_log_analytics_workspace.la.id
    }
  }

  data_sources {
    log_file {
      name               = "example-logfile"
      format             = "json" # 替换原text格式,指定为JSON类型
      record_delimiter   = "newline" # 适配每行一个JSON对象的常见日志格式
      streams            = ["Custom-Json-${azapi_resource.data_collection_logs_table.name}"]
      file_patterns      = ["/var/log/vault_audit.log"]
    }
  }

  # 添加转换规则,映射JSON字段到日志表列
  transformations {
    name   = "transform-json-logs"
    stream = "Custom-Json-${azapi_resource.data_collection_logs_table.name}"
    query  = <<-QUERY
      source
      | extend TimeGenerated = todatetime(TimeGenerated) // 若JSON自带时间字段,替换为对应路径,如todatetime(Properties.timestamp)
      | extend RawData = tostring(parse_json(RawData)) // 保留完整原始JSON字符串,或提取特定字段如Properties.logLevel
      | extend FilePath = tostring(FilePath)
      | project TimeGenerated, RawData, FilePath
    QUERY
  }

  data_flow {
    streams       = ["Custom-Json-${azapi_resource.data_collection_logs_table.name}"]
    destinations  = ["example-destination-log"] // 匹配destinations中定义的日志分析目标名称
    output_stream = "Custom-${azapi_resource.data_collection_logs_table.name}" // 对应自定义日志表的流标识
  }
}

关键配置说明

  1. 日志格式修正

    • 将format从text改为json,告知Azure Monitoring Agent(AMA)按JSON格式解析日志文件
    • record_delimiter = "newline":适用于每行一个独立JSON对象的场景;若日志是多行嵌套JSON,需改为"record_start_marker"并指定匹配起始的正则表达式
  2. 数据流向修正

    • destinations字段需填写destinations.log_analytics.name的具体值(即example-destination-log),替换原未定义的log_analytics_id变量
  3. 转换规则适配

    • 用Kusto查询语法将JSON字段映射到自定义日志表的列:
      • 若JSON日志自带时间字段,需将TimeGenerated = todatetime(TimeGenerated)替换为对应路径(如todatetime(Properties.timestamp))
      • 若需提取特定JSON字段(如日志级别),可修改RawData的赋值逻辑,比如RawData = tostring(Properties.logLevel)
    • 转换逻辑需和你在Azure门户中配置的规则完全一致
  4. 日志表匹配

    • output_stream = "Custom-${azapi_resource.data_collection_logs_table.name}"确保数据流向你创建的自定义日志表,Custom-是Log Analytics自定义表的固定前缀要求

验证步骤

部署完成后,可在Log Analytics工作区执行以下查询验证数据采集:

DCR_Table_TC_Example_CL
| take 10

内容的提问来源于stack exchange,提问作者thelearner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 06:22:04