You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Fluent-Bit仅保留经正则解析成功的日志?

问题:如何让Fluent-Bit仅发送msg字段解析成功的日志?

我正在用Fluent-Bit从指定目录抓取JSON格式日志,相关解析器配置如下:

[PARSER]
    Name        json
    Format      json
    Time_Key    time
    # Time_Format %llu
    Time_Keep   On
[PARSER]
    Name    extract
    Format  regex
    Skip_Empty_Values On
    Regex   ^(?<event>[^,]*),(?<app>[^,]*),(?<user>[^,]*)$

示例日志:

{"level":33,"time":1710879528,"msg":"app_opened,\"test_dashboard\",user1"}

正常日志能被成功解析并发送到上游存储,但目录里可能存在配置错误的日志,Fluent-Bit不会丢弃解析失败的日志,仍会尝试发送。当前配置文件Config.yaml如下:

service:
    flush: ${flush_interval}
    grace: ${flush_interval}
    log_level: info
    http_server: On
    http_listen: 0.0.0.0
    http_port: 2020

pipeline:
  inputs:
    - name: tail
      Read_from_Head: True
      Mem_Buf_Limit: 2mb
      parser: json
      tag: userlogs
      path: ${input_path}
  filters:
    - name: parser
      match: '*'
      parser: extract
      Key_Name: msg
      Reserve_Data: True
      Preserve_Key: False
  outputs:
    # - name: file
    #   match: login
    #   path: /var/log/userlogs_output
    - name: http
      match: '*'
      host: ${rec_host} 
      port: ${rec_port}
      uri: ${rec_endpoint}
      Retry_Limit: False
      format: json
      header_tag:  FLUENT-TAG
      log_response_payload: False

需要配置Fluent-Bit,仅选择那些msg字段被成功解析的日志发送。


解决方案

Fluent-Bit的parser过滤器在解析失败时,会自动为日志添加一个parser_error字段。我们可以利用这个特性,通过grep过滤器过滤掉所有包含该字段的日志,只保留解析成功的条目。

修改Config.yaml中的filters部分,在parser过滤器之后添加grep过滤器:

pipeline:
  inputs:
    - name: tail
      Read_from_Head: True
      Mem_Buf_Limit: 2mb
      parser: json
      tag: userlogs
      path: ${input_path}
  filters:
    - name: parser
      match: '*'
      parser: extract
      Key_Name: msg
      Reserve_Data: True
      Preserve_Key: False
    # 添加grep过滤器过滤解析失败的日志
    - name: grep
      match: '*'
      exclude:
        - parser_error: .*
  outputs:
    # - name: file
    #   match: login
    #   path: /var/log/userlogs_output
    - name: http
      match: '*'
      host: ${rec_host} 
      port: ${rec_port}
      uri: ${rec_endpoint}
      Retry_Limit: False
      format: json
      header_tag:  FLUENT-TAG
      log_response_payload: False

说明

  • grep过滤器的exclude规则会匹配所有包含parser_error字段(无论字段值是什么)的日志,并将它们丢弃。
  • 只有解析成功、没有parser_error字段的日志会继续流向输出环节,发送到上游存储。
  • 该方案无需额外配置,依赖Fluent-Bit默认的解析错误标记行为,简单高效。

内容的提问来源于stack exchange,提问作者Bennimi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 15:45:00