无法通过Fluent-Bit向Loki发送日志,请求排查配置问题
问题排查:Fluent-Bit无法将Nginx日志发送至Loki
环境与问题描述
使用组件版本:Fluent-Bit 2.2、Grafana 8.3.4、Loki 3.0.0,两台Rocky OS 8虚拟机。第一台部署Loki与Grafana,第二台部署Nginx与Fluent-Bit。目标是通过Fluent-Bit将Nginx访问日志推送至Loki,并在Grafana中可视化日志数据,但目前Loki未接收来自第二台机器的Fluent-Bit日志,导致Grafana中无法看到配置的job=fluentbit标签。已排除防火墙问题(替换为Promtail时可正常推送日志),现附上两台机器的配置,请求排查错误。
第一台虚拟机Loki配置
auth_enabled: false server: http_listen_port: 3100 grpc_listen_port: 9096 common: instance_addr: 10.xxx.xxx.xxx path_prefix: /tmp/loki storage: filesystem: chunks_directory: /tmp/loki/chunks rules_directory: /tmp/loki/rules replication_factor: 1 ring: kvstore: store: inmemory query_range: results_cache: cache: embedded_cache: enabled: true max_size_mb: 100 schema_config: configs: - from: 2020-10-24 store: tsdb object_store: filesystem schema: v13 index: prefix: index_ period: 24h ruler: alertmanager_url: http://localhost:9093 # By default, Loki will send anonymous, but uniquely-identifiable usage and configuration # analytics to Grafana Labs. These statistics are sent to https://stats.grafana.org/ # # Statistics help us better understand how Loki is used, and they show us performance # levels for most users. This helps us prioritize features and documentation. # For more information on what's sent, look at # https://github.com/grafana/loki/blob/main/pkg/analytics/stats.go # Refer to the buildReport method to see what goes into a report. # # If you would like to disable reporting, uncomment the following lines: #analytics: # reporting_enabled: false
第二台虚拟机Fluent-Bit配置
[PARSER] Name std_nginx_parser Format regex Regex ^(?<remote>[^ ]*)(?: (?<x_forwarded_for>[^\[]*))+ \[(?<time>[^\]]*)\] "(?<method>\S+)(?: +(?<path>[^\"]*?)(?: +\S*)?)?" (?<code>[^ ]*) (?<size>[^ ]*) (?<elapsed_time>[^ ]*)(?: "(?<referer>[^\"]*)" "(?<agent>[^\"]*)")?$ Time_Key time Time_Format %d/%b/%Y:%H:%M:%S %z Types code:integer size:integer [INPUT] Name tail Path /data01/logs/webLog/ssl_mssgmall/access/*_access.log Parser std_nginx_parser Tag std_nginx [OUTPUT] name loki match * host 10.206.21.122 port 3100 uri /loki/api/v1/push labels job=fluentbit
排查建议
- 适配Loki 3.x多租户机制:Loki 3.0.0默认启用多租户模式,即使
auth_enabled设为false,也需要显式指定租户ID。在Fluent-Bit的输出配置中添加tenant_id ""参数:[OUTPUT] name loki match * host 10.206.21.122 port 3100 uri /loki/api/v1/push labels job=fluentbit tenant_id "" - 检查Fluent-Bit运行日志:查看第二台机器上Fluent-Bit的日志(默认路径
/var/log/fluent-bit/fluent-bit.log),确认是否存在日志解析失败、连接Loki超时或API请求报错的信息。比如正则表达式不匹配Nginx日志格式会导致日志被丢弃。 - 验证tail输入配置有效性:确认
Path指向的日志路径正确,日志文件有新内容生成,且Fluent-Bit进程拥有读取该路径的权限。可添加Read_from_head true参数让Fluent-Bit读取历史日志进行测试。 - 直接测试Loki API连通性:在第二台机器上执行curl命令,模拟Fluent-Bit推送日志,验证Loki API是否正常响应:
若curl请求成功,说明Loki API正常,问题出在Fluent-Bit配置;若失败,检查Loki配置中curl -X POST -H "Content-Type: application/json" -d '{"streams":[{"stream":{"job":"test"},"values":[["'$(date +%s000)'","test log from curl"]]}]}' http://10.206.21.122:3100/loki/api/v1/pushcommon.instance_addr是否为第一台机器的可访问IP,且Loki确实监听了该地址(而非仅localhost)。 - 查看Loki运行日志:检查第一台机器上Loki的日志,确认是否存在拒绝Fluent-Bit请求的记录,比如API格式错误、租户ID不匹配等问题。
内容的提问来源于stack exchange,提问作者Aiden
相关产品推荐
相关产品推荐

