如何配置Fluent-Bit仅保留经正则解析成功的日志?
问题:如何让Fluent-Bit仅发送msg字段解析成功的日志?
我正在用Fluent-Bit从指定目录抓取JSON格式日志,相关解析器配置如下:
[PARSER] Name json Format json Time_Key time # Time_Format %llu Time_Keep On [PARSER] Name extract Format regex Skip_Empty_Values On Regex ^(?<event>[^,]*),(?<app>[^,]*),(?<user>[^,]*)$
示例日志:
{"level":33,"time":1710879528,"msg":"app_opened,\"test_dashboard\",user1"}
正常日志能被成功解析并发送到上游存储,但目录里可能存在配置错误的日志,Fluent-Bit不会丢弃解析失败的日志,仍会尝试发送。当前配置文件Config.yaml如下:
service: flush: ${flush_interval} grace: ${flush_interval} log_level: info http_server: On http_listen: 0.0.0.0 http_port: 2020 pipeline: inputs: - name: tail Read_from_Head: True Mem_Buf_Limit: 2mb parser: json tag: userlogs path: ${input_path} filters: - name: parser match: '*' parser: extract Key_Name: msg Reserve_Data: True Preserve_Key: False outputs: # - name: file # match: login # path: /var/log/userlogs_output - name: http match: '*' host: ${rec_host} port: ${rec_port} uri: ${rec_endpoint} Retry_Limit: False format: json header_tag: FLUENT-TAG log_response_payload: False
需要配置Fluent-Bit,仅选择那些msg字段被成功解析的日志发送。
解决方案
Fluent-Bit的parser过滤器在解析失败时,会自动为日志添加一个parser_error字段。我们可以利用这个特性,通过grep过滤器过滤掉所有包含该字段的日志,只保留解析成功的条目。
修改Config.yaml中的filters部分,在parser过滤器之后添加grep过滤器:
pipeline: inputs: - name: tail Read_from_Head: True Mem_Buf_Limit: 2mb parser: json tag: userlogs path: ${input_path} filters: - name: parser match: '*' parser: extract Key_Name: msg Reserve_Data: True Preserve_Key: False # 添加grep过滤器过滤解析失败的日志 - name: grep match: '*' exclude: - parser_error: .* outputs: # - name: file # match: login # path: /var/log/userlogs_output - name: http match: '*' host: ${rec_host} port: ${rec_port} uri: ${rec_endpoint} Retry_Limit: False format: json header_tag: FLUENT-TAG log_response_payload: False
说明
grep过滤器的exclude规则会匹配所有包含parser_error字段(无论字段值是什么)的日志,并将它们丢弃。- 只有解析成功、没有
parser_error字段的日志会继续流向输出环节,发送到上游存储。 - 该方案无需额外配置,依赖Fluent-Bit默认的解析错误标记行为,简单高效。
内容的提问来源于stack exchange,提问作者Bennimi
相关产品推荐
相关产品推荐

