You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过Fluent-Bit向Loki发送日志,请求排查配置问题

问题排查:Fluent-Bit无法将Nginx日志发送至Loki

环境与问题描述

使用组件版本:Fluent-Bit 2.2、Grafana 8.3.4、Loki 3.0.0,两台Rocky OS 8虚拟机。第一台部署Loki与Grafana,第二台部署Nginx与Fluent-Bit。目标是通过Fluent-Bit将Nginx访问日志推送至Loki,并在Grafana中可视化日志数据,但目前Loki未接收来自第二台机器的Fluent-Bit日志,导致Grafana中无法看到配置的job=fluentbit标签。已排除防火墙问题(替换为Promtail时可正常推送日志),现附上两台机器的配置,请求排查错误。

第一台虚拟机Loki配置

auth_enabled: false

server:
  http_listen_port: 3100
  grpc_listen_port: 9096

common:
  instance_addr: 10.xxx.xxx.xxx
  path_prefix: /tmp/loki
  storage:
    filesystem:
      chunks_directory: /tmp/loki/chunks
      rules_directory: /tmp/loki/rules
  replication_factor: 1
  ring:
    kvstore:
      store: inmemory

query_range:
  results_cache:
    cache:
      embedded_cache:
        enabled: true
        max_size_mb: 100

schema_config:
  configs:
    - from: 2020-10-24
      store: tsdb
      object_store: filesystem
      schema: v13
      index:
        prefix: index_
        period: 24h

ruler:
  alertmanager_url: http://localhost:9093

# By default, Loki will send anonymous, but uniquely-identifiable usage and configuration
# analytics to Grafana Labs. These statistics are sent to https://stats.grafana.org/
#
# Statistics help us better understand how Loki is used, and they show us performance
# levels for most users. This helps us prioritize features and documentation.
# For more information on what's sent, look at
# https://github.com/grafana/loki/blob/main/pkg/analytics/stats.go
# Refer to the buildReport method to see what goes into a report.
#
# If you would like to disable reporting, uncomment the following lines:
#analytics:
#  reporting_enabled: false

第二台虚拟机Fluent-Bit配置

[PARSER]
    Name std_nginx_parser
    Format regex
    Regex ^(?<remote>[^ ]*)(?: (?<x_forwarded_for>[^\[]*))+ \[(?<time>[^\]]*)\] "(?<method>\S+)(?: +(?<path>[^\"]*?)(?: +\S*)?)?" (?<code>[^ ]*) (?<size>[^ ]*) (?<elapsed_time>[^ ]*)(?: "(?<referer>[^\"]*)" "(?<agent>[^\"]*)")?$
    Time_Key time
    Time_Format %d/%b/%Y:%H:%M:%S %z
    Types code:integer size:integer

[INPUT]
    Name tail
    Path /data01/logs/webLog/ssl_mssgmall/access/*_access.log
    Parser std_nginx_parser
    Tag std_nginx

[OUTPUT]
    name loki
    match *
    host 10.206.21.122
    port 3100
    uri /loki/api/v1/push
    labels job=fluentbit

排查建议

  • 适配Loki 3.x多租户机制:Loki 3.0.0默认启用多租户模式,即使auth_enabled设为false,也需要显式指定租户ID。在Fluent-Bit的输出配置中添加tenant_id ""参数:
    [OUTPUT]
        name loki
        match *
        host 10.206.21.122
        port 3100
        uri /loki/api/v1/push
        labels job=fluentbit
        tenant_id ""
    
  • 检查Fluent-Bit运行日志:查看第二台机器上Fluent-Bit的日志(默认路径/var/log/fluent-bit/fluent-bit.log),确认是否存在日志解析失败、连接Loki超时或API请求报错的信息。比如正则表达式不匹配Nginx日志格式会导致日志被丢弃。
  • 验证tail输入配置有效性:确认Path指向的日志路径正确,日志文件有新内容生成,且Fluent-Bit进程拥有读取该路径的权限。可添加Read_from_head true参数让Fluent-Bit读取历史日志进行测试。
  • 直接测试Loki API连通性:在第二台机器上执行curl命令,模拟Fluent-Bit推送日志,验证Loki API是否正常响应:
    curl -X POST -H "Content-Type: application/json" -d '{"streams":[{"stream":{"job":"test"},"values":[["'$(date +%s000)'","test log from curl"]]}]}' http://10.206.21.122:3100/loki/api/v1/push
    
    若curl请求成功,说明Loki API正常,问题出在Fluent-Bit配置;若失败,检查Loki配置中common.instance_addr是否为第一台机器的可访问IP,且Loki确实监听了该地址(而非仅localhost)。
  • 查看Loki运行日志:检查第一台机器上Loki的日志,确认是否存在拒绝Fluent-Bit请求的记录,比如API格式错误、租户ID不匹配等问题。

内容的提问来源于stack exchange,提问作者Aiden

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 00:28:13