如何为基于Log4j的Zeebe配置JSON日志以对接EFK栈
无需修改代码实现Zeebe日志JSON化并接入EFK的可行方案
方案1:注入JSON布局依赖+重载Log4j配置(原生JSON输出)
利用Spring Boot支持外部Log4j配置的特性,同时通过Init容器将缺失的log4j-layout-template-json包加入Zeebe的类路径,实现原生JSON日志输出。
- 步骤1:编写Log4j2 JSON配置文件(
log4j2.xml),使用JsonTemplateLayout:
<?xml version="1.0" encoding="UTF-8"?> <Configuration status="WARN"> <Appenders> <Console name="Console" target="SYSTEM_OUT"> <JsonTemplateLayout eventTemplateUri="classpath:JsonEventLayoutV1.json"/> </Console> </Appenders> <Loggers> <Root level="info"> <AppenderRef ref="Console"/> </Root> </Loggers> </Configuration>
- 步骤2:通过Helm配置实现依赖注入和配置挂载:
在values.yaml中添加Init容器、卷和环境变量,确保jar包被复制到Zeebe的类路径目录(需根据Zeebe镜像结构调整路径),同时加载自定义Log4j配置:
# 注入缺失的JSON布局jar包 extraInitContainers: - name: fetch-json-layout image: curlimages/curl:latest command: - sh - -c - | # 下载与Zeebe所用Log4j版本匹配的log4j-layout-template-json包 curl -o /tmp/log4j-layout-template-json-<对应版本>.jar <Maven中央仓库对应jar包地址> volumeMounts: - name: lib-dir mountPath: /tmp # 配置卷挂载 volumeMounts: - name: lib-dir mountPath: /app/lib # 替换为Zeebe实际的类路径目录 - name: log4j-config mountPath: /app/config volumes: - name: lib-dir emptyDir: {} - name: log4j-config configMap: name: zeebe-log4j-config # 指定自定义Log4j配置文件路径 env: - name: LOG4J_CONFIGURATION_FILE value: file:/app/config/log4j2.xml
- 步骤3:创建对应ConfigMap:
kubectl create configmap zeebe-log4j-config --from-file=log4j2.xml
方案2:用Sidecar容器做日志格式转换
无需修改Zeebe容器,通过Sidecar捕获Zeebe的标准输出,将文本日志解析为JSON后输出,EFK直接采集Sidecar的日志即可。以Fluent Bit为例:
- 步骤1:在Helm的
values.yaml中添加Sidecar容器:
extraContainers: - name: fluent-bit image: fluent/fluent-bit:2.2.0 args: ["-c", "/fluent-bit/etc/fluent-bit.conf"] volumeMounts: - name: fluent-bit-config mountPath: /fluent-bit/etc - name: varlog mountPath: /var/log resources: limits: memory: 128Mi requests: cpu: 100m memory: 64Mi volumes: - name: fluent-bit-config configMap: name: zeebe-fluent-bit-config - name: varlog hostPath: path: /var/log
- 步骤2:创建Fluent Bit配置的ConfigMap,包含日志采集、解析和输出规则:
# fluent-bit.conf [SERVICE] Flush 1 Log_Level info [INPUT] Name tail Path /var/log/containers/*zeebe*.log # 匹配Zeebe容器日志文件 Parser docker Tag zeebe.* [FILTER] Name parser Match zeebe.* Parser zeebe-text-log Key_Name log [OUTPUT] Name stdout Match * Format json_lines
同时添加日志解析规则(放在同一个ConfigMap中):
# 解析Zeebe文本日志的规则,根据实际日志格式调整正则 [PARSER] Name zeebe-text-log Format regex Regex ^(?<timestamp>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3}) (?<level>[A-Z]+) (?<thread>[^ ]+) (?<logger>[^ ]+) - (?<message>.*)$
- 步骤3:创建ConfigMap:
kubectl create configmap zeebe-fluent-bit-config --from-file=fluent-bit.conf --from-file=parser.conf
方案3:在EFK采集层直接解析转换
如果已部署Fluentd/Fluent Bit作为K8s日志采集器,可直接在采集器层面配置解析规则,将Zeebe的文本日志转为JSON,无需修改Zeebe的Pod配置。
以Fluentd为例,在其配置中添加针对Zeebe容器的过滤规则:
<filter kubernetes.**> @type parser key_name log <parse> @type regexp expression /^(?<timestamp>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3}) (?<level>[A-Z]+) (?<thread>[^ ]+) (?<logger>[^ ]+) - (?<message>.*)$/ time_key timestamp time_format %Y-%m-%d %H:%M:%S,%L </parse> <match> kubernetes.labels.app=zeebe # 匹配Zeebe的容器标签 </match> </filter>
配置完成后,采集器会自动将Zeebe的文本日志解析为包含时间戳、日志级别、线程、日志器和消息的JSON结构,直接传入Elasticsearch。
内容的提问来源于stack exchange,提问作者Andy Dufresne
相关产品推荐
相关产品推荐

