使用FluentD & Fluent-bit无法将日志发送至Grafana Loki求助
问题:Fluent-bit无法采集EC2应用日志至Grafana Loki
我正尝试将EC2实例上的应用日志通过FluentD & Fluent-bit集成至Grafana Loki,目前遇到以下状况:
- Fluent-bit服务运行正常
- 应用日志无法发送至Loki
- 监控
fluent-bit.service时看到重复调试日志:
[debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/csp-nmgr-1/ocomc_IoT.log, inode 100987803 [debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/event-nmgr-1/ocomc_IoT.log, inode 100727404 [debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/session-nmgr-1/ocomc_IoT.log, inode 854909 [debug] [input:tail:tail.3] 0 new files found on path '/opt/SP/users/oracle/ocomc/logs/*-nmgr*/ocomc_IoT.log' [debug] [input:tail:tail.3] scanning path /opt/SP/users/oracle/ocomc/logs/*-nmgr*/ocomc_IoT.log [debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/collection-nmgr-1/ocomc_IoT.log, inode 84468627 [debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/csp-nmgr-1/ocomc_IoT.log, inode 100987803 [debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/event-nmgr-1/ocomc_IoT.log, inode 100727404 [debug] [input:tail:tail.3] scan_blog add(): dismissed: /opt/SP/users/oracle/ocomc/logs/session-nmgr-1/ocomc_IoT.log, inode 854909 [debug] [input:tail:tail.3] 0 new files found on path '/opt/SP/users/oracle/ocomc/logs/*-nmgr*/ocomc_IoT.log'
可能的原因及解决方案
1. 位置文件记录已存在,导致文件被标记为已处理
调试日志中的scan_blog add(): dismissed表示Fluent-bit已通过inode记录过这些文件,认为无需重复添加。若为首次配置,大概率是位置文件已留存旧记录。
- 操作步骤:
- 找到Fluent-bit配置中
[INPUT]段tail模块的position_file路径 - 停止服务:
systemctl stop fluent-bit - 删除位置文件:
rm -f /path/to/your/position/file.pos - 重启服务:
systemctl start fluent-bit
- 找到Fluent-bit配置中
2. 日志文件无新内容写入
Fluent-bit的tail输入默认仅采集新写入的日志,若文件长期无更新,不会主动读取历史内容。
- 操作步骤:
- 验证日志更新状态:
tail -f /opt/SP/users/oracle/ocomc/logs/csp-nmgr-1/ocomc_IoT.log,确认应用在持续写入 - 若需采集历史日志,在
[INPUT]段添加配置:read_from_head true
- 验证日志更新状态:
3. Fluent-bit无文件读取权限
服务运行正常不代表进程有目标日志的访问权限,需检查权限配置。
- 操作步骤:
- 查看文件权限:
ls -l /opt/SP/users/oracle/ocomc/logs/*-nmgr*/ocomc_IoT.log - 递归检查父目录权限:
namei -l /opt/SP/users/oracle/ocomc/logs/csp-nmgr-1/ocomc_IoT.log - 给Fluent-bit用户授权:将
fluent-bit用户加入日志所属用户组,或临时用chmod o+r开放读权限测试
- 查看文件权限:
4. 路径匹配规则失效
配置中的glob路径可能未正确匹配所有目标文件,或Fluent-bit的glob解析存在限制。
- 操作步骤:
- 手动验证路径:
ls /opt/SP/users/oracle/ocomc/logs/*-nmgr*/ocomc_IoT.log,确认能列出所有目标文件 - 尝试拆分路径为具体条目:
[INPUT] Name tail Path /opt/SP/users/oracle/ocomc/logs/csp-nmgr-1/ocomc_IoT.log Path /opt/SP/users/oracle/ocomc/logs/event-nmgr-1/ocomc_IoT.log Path /opt/SP/users/oracle/ocomc/logs/session-nmgr-1/ocomc_IoT.log Path /opt/SP/users/oracle/ocomc/logs/collection-nmgr-1/ocomc_IoT.log
- 手动验证路径:
5. 输出段配置错误
即使输入采集正常,若Loki输出配置有误,日志也无法推送成功。
- 操作步骤:
- 检查
[OUTPUT]段的Loki配置,确认url、labels等参数正确 - 开启输出调试:在配置文件中添加
Log_Level debug,查看输出阶段的错误日志
- 检查
内容的提问来源于stack exchange,提问作者Haytham
相关产品推荐
相关产品推荐

