You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fluentd日志聚合器故障排查:服务器间连通性问题

问题排查与解决步骤

1. 修复Fluentd服务器2的核心配置缺失

你当前的Fluentd服务器2配置没有接收forward流量的source模块,这是日志无法转发的核心问题:Fluentd1已经在发送forward请求,但Fluentd2根本没在24225端口监听接收请求。

给Fluentd2添加以下source配置,放在<match>块之前:

<source>
  @type forward
  @id input_forward
  port 24225
  bind 0.0.0.0  <!-- 监听所有接口,确保能接收Fluentd1的请求 -->
</source>

2. 手动验证服务器间网络连通性

即使你确认过监听配置,仍需手动验证端口连通性:

  • 在Fluentd1服务器上执行以下命令测试:
    # 用telnet测试
    telnet 18.212.132.77 24225
    # 或者用nc工具
    nc -zv 18.212.132.77 24225
    
    如果连接失败,排查方向:
    • 两台服务器的防火墙(iptables/ufw等)是否开放了24225端口的TCP流量(forward插件默认使用TCP协议)
    • 若为云服务器,检查服务商安全组是否允许24225端口的入站请求

3. 查看Fluentd日志定位错误

查看两台Fluentd的运行日志,获取具体错误信息:

  • Fluentd1日志默认路径:/var/log/fluentd/fluentd.log 或 /var/log/td-agent/td-agent.log,重点查看是否有连接超时、拒绝的报错
  • Fluentd2日志:确认是否有接收forward连接的日志,或启动时的配置错误

4. 验证Fluentd2到Elasticsearch的连通性

先单独确认Fluentd2能正常向Elasticsearch发送日志:

  • 在Fluentd2上临时添加测试用source:
    <source>
      @type tail
      path /tmp/test.log
      tag test.log
      <parse>
        @type json
      </parse>
    </source>
    
    然后在/tmp/test.log写入一条JSON格式日志,检查是否能正常进入Elasticsearch,排除ES侧的问题

5. 优化Fluentd1的forward配置(可选)

添加buffer和重试机制,提升转发可靠性并便于排查失败情况:

<match api.log>
  @type forward
  @id output_system_forward
  <server>
    host 18.212.132.77
    port 24225
  </server>
  <buffer>
    @type file
    path /var/log/fluentd/buffer/api_log
    flush_interval 5s
    retry_type exponential_backoff
    retry_wait 2s
    retry_max_interval 30s
    retry_timeout 300s
  </buffer>
  <secondary>
    @type file
    path /var/log/fluentd/failed_api_log/%Y%m%d.log
  </secondary>
</match>

配置后,转发失败的日志会先暂存本地buffer,最终失败的日志会写入本地文件,便于后续排查。

内容的提问来源于stack exchange,提问作者vidhi yadav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 21:04:56