You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将filelog receiver的file.log.name从attributes复制到resource?

解决OpenTelemetry filelog receiver复制attributes.log.file.name到resource字段的报错问题

问题背景

配置OpenTelemetry的filelog receiver时,尝试将自动生成的attributes.log.file.name复制到resource字段,但报错提示该属性不存在。复制其他属性(如attributes.sev到resource.sev)可正常工作。相关配置片段如下:

receivers:
  filelog:
    include: [/var/log/app/sample.log]
    start_at: beginning
    operators:
      - type: regex_parser
        regex: '^(?P<time>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{3}) \[?(?P<sev>[A-Z]*)\]? (?P<msg>.*)$'
        timestamp:
          parse_from: attributes.time
          layout: '%Y-%m-%d %H:%M:%S.%L'
        severity:
          parse_from: attributes.sev

      - type: copy
        from: attributes.log.file.name
        to: resource.filename

    resource:
      deployment.env: "dev"
      service.name: "app"
      service.version: "1.0.0"
      host.name: ${env:HOSTNAME}

附加上下文:

  • 无源码访问权限,无法通过SDK埋点应用
  • 依赖filelog receiver采集磁盘日志
  • filelog receiver默认将log.file.name加入attributes,直接在receiver的resource块配置会导致其他属性迁移问题
  • 机器日志文件过多,无法通过环境变量管理文件名
  • 曾尝试attributes processor和resource processor但未成功

问题原因

filelog receiver的operators执行顺序早于默认属性添加逻辑:当copy operator运行时,receiver还未自动生成log.file.name属性,因此会提示该字段不存在。而自定义解析生成的sev等属性在operators执行过程中已经存在,所以复制操作正常。

解决方案

使用resource processor在receiver完成所有默认属性添加后,再将log.file.name从attributes复制到resource字段。具体配置修改如下:

receivers:
  filelog:
    include: [/var/log/app/sample.log]
    start_at: beginning
    operators:
      - type: regex_parser
        regex: '^(?P<time>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{3}) \[?(?P<sev>[A-Z]*)\]? (?P<msg>.*)$'
        timestamp:
          parse_from: attributes.time
          layout: '%Y-%m-%d %H:%M:%S.%L'
        severity:
          parse_from: attributes.sev

    resource:
      deployment.env: "dev"
      service.name: "app"
      service.version: "1.0.0"
      host.name: ${env:HOSTNAME}

# 添加resource processor配置
processors:
  resource:
    attributes:
      - action: insert
        key: filename  # resource中要生成的字段名
        from_attribute: log.file.name  # attributes中的源字段名
        resource: true  # 指定操作对象为resource而非attributes

service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [resource]  # 将resource processor加入日志处理流水线
      exporters: [your_exporter]  # 替换为实际使用的exporter

关键说明

  1. processor执行时机:resource processor运行在receiver完成所有日志解析和默认属性添加之后,此时log.file.name已存在于attributes中,可正常读取。
  2. 配置要点:必须设置resource: true,否则默认会修改attributes字段而非resource字段;from_attribute直接填写log.file.name即可,无需加attributes.前缀。
  3. 验证方法:可使用debug exporter临时替换实际exporter,查看处理后的日志条目,确认resource字段中已包含filename属性。

内容的提问来源于stack exchange,提问作者Yeile

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 15:07:49