You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为基于Log4j的Zeebe配置JSON日志以对接EFK栈

无需修改代码实现Zeebe日志JSON化并接入EFK的可行方案

方案1:注入JSON布局依赖+重载Log4j配置(原生JSON输出)

利用Spring Boot支持外部Log4j配置的特性,同时通过Init容器将缺失的log4j-layout-template-json包加入Zeebe的类路径,实现原生JSON日志输出。

  • 步骤1:编写Log4j2 JSON配置文件(log4j2.xml),使用JsonTemplateLayout:
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="WARN">
    <Appenders>
        <Console name="Console" target="SYSTEM_OUT">
            <JsonTemplateLayout eventTemplateUri="classpath:JsonEventLayoutV1.json"/>
        </Console>
    </Appenders>
    <Loggers>
        <Root level="info">
            <AppenderRef ref="Console"/>
        </Root>
    </Loggers>
</Configuration>
  • 步骤2:通过Helm配置实现依赖注入和配置挂载:
    在values.yaml中添加Init容器、卷和环境变量,确保jar包被复制到Zeebe的类路径目录(需根据Zeebe镜像结构调整路径),同时加载自定义Log4j配置:
# 注入缺失的JSON布局jar包
extraInitContainers:
  - name: fetch-json-layout
    image: curlimages/curl:latest
    command:
      - sh
      - -c
      - |
        # 下载与Zeebe所用Log4j版本匹配的log4j-layout-template-json包
        curl -o /tmp/log4j-layout-template-json-<对应版本>.jar <Maven中央仓库对应jar包地址>
    volumeMounts:
      - name: lib-dir
        mountPath: /tmp

# 配置卷挂载
volumeMounts:
  - name: lib-dir
    mountPath: /app/lib  # 替换为Zeebe实际的类路径目录
  - name: log4j-config
    mountPath: /app/config

volumes:
  - name: lib-dir
    emptyDir: {}
  - name: log4j-config
    configMap:
      name: zeebe-log4j-config

# 指定自定义Log4j配置文件路径
env:
  - name: LOG4J_CONFIGURATION_FILE
    value: file:/app/config/log4j2.xml
  • 步骤3:创建对应ConfigMap:
kubectl create configmap zeebe-log4j-config --from-file=log4j2.xml

方案2:用Sidecar容器做日志格式转换

无需修改Zeebe容器,通过Sidecar捕获Zeebe的标准输出,将文本日志解析为JSON后输出,EFK直接采集Sidecar的日志即可。以Fluent Bit为例:

  • 步骤1:在Helm的values.yaml中添加Sidecar容器:
extraContainers:
  - name: fluent-bit
    image: fluent/fluent-bit:2.2.0
    args: ["-c", "/fluent-bit/etc/fluent-bit.conf"]
    volumeMounts:
      - name: fluent-bit-config
        mountPath: /fluent-bit/etc
      - name: varlog
        mountPath: /var/log
    resources:
      limits:
        memory: 128Mi
      requests:
        cpu: 100m
        memory: 64Mi

volumes:
  - name: fluent-bit-config
    configMap:
      name: zeebe-fluent-bit-config
  - name: varlog
    hostPath:
      path: /var/log
  • 步骤2:创建Fluent Bit配置的ConfigMap,包含日志采集、解析和输出规则:
# fluent-bit.conf
[SERVICE]
    Flush        1
    Log_Level    info

[INPUT]
    Name         tail
    Path         /var/log/containers/*zeebe*.log  # 匹配Zeebe容器日志文件
    Parser       docker
    Tag          zeebe.*

[FILTER]
    Name         parser
    Match        zeebe.*
    Parser       zeebe-text-log
    Key_Name     log

[OUTPUT]
    Name         stdout
    Match        *
    Format       json_lines

同时添加日志解析规则(放在同一个ConfigMap中):

# 解析Zeebe文本日志的规则,根据实际日志格式调整正则
[PARSER]
    Name        zeebe-text-log
    Format      regex
    Regex       ^(?<timestamp>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3}) (?<level>[A-Z]+) (?<thread>[^ ]+) (?<logger>[^ ]+) - (?<message>.*)$
  • 步骤3:创建ConfigMap:
kubectl create configmap zeebe-fluent-bit-config --from-file=fluent-bit.conf --from-file=parser.conf

方案3:在EFK采集层直接解析转换

如果已部署Fluentd/Fluent Bit作为K8s日志采集器,可直接在采集器层面配置解析规则,将Zeebe的文本日志转为JSON,无需修改Zeebe的Pod配置。
以Fluentd为例,在其配置中添加针对Zeebe容器的过滤规则:

<filter kubernetes.**>
  @type parser
  key_name log
  <parse>
    @type regexp
    expression /^(?<timestamp>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3}) (?<level>[A-Z]+) (?<thread>[^ ]+) (?<logger>[^ ]+) - (?<message>.*)$/
    time_key timestamp
    time_format %Y-%m-%d %H:%M:%S,%L
  </parse>
  <match>
    kubernetes.labels.app=zeebe  # 匹配Zeebe的容器标签
  </match>
</filter>

配置完成后,采集器会自动将Zeebe的文本日志解析为包含时间戳、日志级别、线程、日志器和消息的JSON结构,直接传入Elasticsearch。

内容的提问来源于stack exchange,提问作者Andy Dufresne

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 00:07:04