You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用transform/attribute处理器混淆/脱敏OpenTelemetry日志?

问题描述

在EKS集群的Splunk OpenTelemetry发行版环境中,尝试对日志中的upstream_namespace字段进行脱敏/混淆,但始终未成功。

日志样例:

2024-03-11T21:04:41.411025006Z stdout F {"time": "2024-03-11T21:04:41+00:00", "upstream_namespace":"system-monitoring", "remote_user": "sample-user"}

测试过的处理器配置汇总:

processors:
  attributes/upsert:
   actions:
   - key: upstream_namespace
     action: upsert
     value: "REDACTED_NS"
  transform:  
   log_statements:
   - context: log
     statements:
      - replace_all_patterns(attributes,"value","upstream_namespace", "REDACTED_NS")
      - replace_all_patterns(attributes,"key","upstream_namespace", "REDACTED_NS")
      - replace_match(attributes["upstream_namespace"], "*" , "REDACTED_NS")
      - replace_match(attributes["upstream_namespace"], "system-monitoring" , "REDACTED_NS")
      - delete_key(attributes,"upstream_namespace")
      - delete_key(resource.attributes,"upstream_namespace")
      - replace_all_patterns(attributes["upstream_namespace"],"value","upstream_namespace", "REDACTED_NS")
      - replace_all_patterns(attributes["upstream_namespace"],"value","system-monitoring", "REDACTED_NS")

使用attributes/upsert处理器时,出现字段值重复的情况,结果如下:

upstream_namespace: REDACTED_NS
                    system-monitoring
可行方案建议

方案1:修正Attributes处理器配置实现覆盖

upsert动作默认会将新值追加到已有字段(转为数组形式),这是导致重复的原因。可以改用update动作直接覆盖,或者在upsert中添加update_if_exists: true参数:

配置示例(使用update动作)

processors:
  attributes/redact_ns:
    actions:
    - key: upstream_namespace
      action: update
      value: "REDACTED_NS"

配置示例(使用upsert+update_if_exists)

processors:
  attributes/redact_ns:
    actions:
    - key: upstream_namespace
      action: upsert
      value: "REDACTED_NS"
      update_if_exists: true

方案2:使用Transform处理器正确替换值

Transform处理器的语法需要准确,直接用set语句覆盖字段值是最简单的方式;如果需要匹配特定值再替换,用replace_match(注意正则语法,*不是通配符,要用.*匹配任意内容):

配置示例(直接覆盖)

processors:
  transform/redact_ns:
    log_statements:
    - context: log
      statements:
        - set(attributes["upstream_namespace"], "REDACTED_NS")

配置示例(匹配特定值替换)

processors:
  transform/redact_ns:
    log_statements:
    - context: log
      statements:
        - replace_match(attributes["upstream_namespace"], "^system-monitoring$", "REDACTED_NS")

方案3:确保日志已被正确解析为结构化属性

如果日志原始是JSON格式,必须先通过json_parser处理器将JSON字段提取为OTel attributes,否则Transform/Attributes处理器无法找到upstream_namespace字段。添加解析配置:

processors:
  json_parser:
    parse_from: body
    parse_to: attributes
    timestamp:
      parse_from: attributes.time
      layout: "%Y-%m-%dT%H:%M:%S%z"

注意:需要将json_parser、脱敏处理器按顺序加入到pipeline的processors列表中,确保执行顺序正确。

内容的提问来源于stack exchange,提问作者ppal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 08:49:54