You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fluentd聚合器未输出stdout排查:Calico日志转发异常

问题排查:Fluentd转发日志至聚合器失败

场景描述

在K8s环境中,Fluentd以DaemonSet形式运行,Pod通过ConfigMap挂载fluent.conf配置文件:

  • 采集以calico-node开头的容器日志,标记为kube.kubeproxy
  • 转发至同网段的Fluentd聚合器(IP:192.168.123.230,端口:24224)
  • 本地Fluentd已通过stdout确认日志正常输出,但聚合器未收到日志并执行stdout输出
  • Pod可ping通聚合器节点

配置详情

节点Fluentd配置(DaemonSet Pod)

<source>
  @type tail
  path /var/log/containers/calico-node*.log
  tag kube.kubeproxy
  <parse>
        @type json
  </parse>
</source>

<match kube.kubeproxy>
    @type forward
    send_timeout 60s
    recover_wait 10s
    hard_timeout 60s

    <server>
      host 192.168.123.230
      port 24224
    </server>
</match>

<match kube.kubeproxy>
  @type stdout
</match>

聚合器Fluentd配置

<source>
  @type forward
  port 24224
</source>

<match kube.kubeproxy>
  @type stdout
  @id output_stdout
</match>

错误点排查与修复

1. 聚合器Forward Source监听地址限制(核心问题)

Fluentd的forward source插件默认仅监听127.0.0.1,导致K8s Pod中的Fluentd无法通过集群网络连接到聚合器的24224端口(虽然能ping通,但端口未对外开放)。

修复方案:在聚合器的source配置中添加bind 0.0.0.0,允许所有地址访问:

<source>
  @type forward
  port 24224
  bind 0.0.0.0  <!-- 新增:监听所有网卡地址 -->
</source>

2. 节点Fluentd的Forward与Stdout匹配顺序问题

Fluentd的match规则是按配置从上到下匹配执行,当前配置中forward是异步发送,后续的stdout同步执行,虽然本地能看到日志,但可能存在转发逻辑未正确触发的情况(比如buffer未及时flush)。

优化方案:
使用copy插件确保日志同时被转发和输出,避免顺序匹配导致的问题,同时添加buffer配置强制立即刷新便于调试:

<match kube.kubeproxy>
  @type copy
  <store>
    @type forward
    send_timeout 60s
    recover_wait 10s
    hard_timeout 60s
    <server>
      host 192.168.123.230
      port 24224
    </server>
    <buffer>
      @type memory
      flush_mode immediate
    </buffer>
  </store>
  <store>
    @type stdout
  </store>
</match>

3. 额外验证点

  • 检查聚合器节点的防火墙/安全组是否允许24224端口的TCP流量
  • 在K8s Pod中执行telnet 192.168.123.230 24224或nc -zv 192.168.123.230 24224确认端口可达
  • 查看节点Fluentd的Pod日志,检查是否有连接超时/拒绝的错误信息:kubectl logs <fluentd-daemonset-pod-name>

内容的提问来源于stack exchange,提问作者심준보

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 02:05:57