如何使用transform/attribute处理器混淆/脱敏OpenTelemetry日志?
问题描述
在EKS集群的Splunk OpenTelemetry发行版环境中,尝试对日志中的upstream_namespace字段进行脱敏/混淆,但始终未成功。
日志样例:
2024-03-11T21:04:41.411025006Z stdout F {"time": "2024-03-11T21:04:41+00:00", "upstream_namespace":"system-monitoring", "remote_user": "sample-user"}
测试过的处理器配置汇总:
processors: attributes/upsert: actions: - key: upstream_namespace action: upsert value: "REDACTED_NS" transform: log_statements: - context: log statements: - replace_all_patterns(attributes,"value","upstream_namespace", "REDACTED_NS") - replace_all_patterns(attributes,"key","upstream_namespace", "REDACTED_NS") - replace_match(attributes["upstream_namespace"], "*" , "REDACTED_NS") - replace_match(attributes["upstream_namespace"], "system-monitoring" , "REDACTED_NS") - delete_key(attributes,"upstream_namespace") - delete_key(resource.attributes,"upstream_namespace") - replace_all_patterns(attributes["upstream_namespace"],"value","upstream_namespace", "REDACTED_NS") - replace_all_patterns(attributes["upstream_namespace"],"value","system-monitoring", "REDACTED_NS")
使用attributes/upsert处理器时,出现字段值重复的情况,结果如下:
upstream_namespace: REDACTED_NS system-monitoring
可行方案建议
方案1:修正Attributes处理器配置实现覆盖
upsert动作默认会将新值追加到已有字段(转为数组形式),这是导致重复的原因。可以改用update动作直接覆盖,或者在upsert中添加update_if_exists: true参数:
配置示例(使用update动作)
processors: attributes/redact_ns: actions: - key: upstream_namespace action: update value: "REDACTED_NS"
配置示例(使用upsert+update_if_exists)
processors: attributes/redact_ns: actions: - key: upstream_namespace action: upsert value: "REDACTED_NS" update_if_exists: true
方案2:使用Transform处理器正确替换值
Transform处理器的语法需要准确,直接用set语句覆盖字段值是最简单的方式;如果需要匹配特定值再替换,用replace_match(注意正则语法,*不是通配符,要用.*匹配任意内容):
配置示例(直接覆盖)
processors: transform/redact_ns: log_statements: - context: log statements: - set(attributes["upstream_namespace"], "REDACTED_NS")
配置示例(匹配特定值替换)
processors: transform/redact_ns: log_statements: - context: log statements: - replace_match(attributes["upstream_namespace"], "^system-monitoring$", "REDACTED_NS")
方案3:确保日志已被正确解析为结构化属性
如果日志原始是JSON格式,必须先通过json_parser处理器将JSON字段提取为OTel attributes,否则Transform/Attributes处理器无法找到upstream_namespace字段。添加解析配置:
processors: json_parser: parse_from: body parse_to: attributes timestamp: parse_from: attributes.time layout: "%Y-%m-%dT%H:%M:%S%z"
注意:需要将json_parser、脱敏处理器按顺序加入到pipeline的processors列表中,确保执行顺序正确。
内容的提问来源于stack exchange,提问作者ppal
相关产品推荐
相关产品推荐

