使用OpenTelemetry Collector Transform处理器设置日志时间戳报错
问题:替换OTLP日志时间戳为消息自带的纳秒级时间戳
环境与需求
- 使用OpenTelemetry Collector版本:otel/opentelemetry-collector-contrib:0.82.0
- 通过FluentForward接收器接收的事件结构:
{ "message": "hello world", "timestamp": "1692092369949725000" }
- 核心需求:将最终OTLP payload中的日志时间戳替换为消息自带的纳秒级时间戳,而非Collector的采集时间
尝试的配置
receivers: fluentforward: endpoint: 0.0.0.0:8006 processors: transform/example: log_statements: - context: log statements: - set(timestamp, attributes["timestamp"]) exporters: logging: loglevel: debug service: pipelines: logs: receivers: [fluentforward] processors: [transform/example] exporters: [logging]
触发的错误
Error: invalid configuration: processors::transform/example: unable to parse OTTL statement "set(timestamp, attributes["timestamp"])". Error details: error while parsing arguments for call to "set": invalid argument at position 0: invalid path expression [{timestamp []}]
解决方案
错误源于OTTL语句的语法错误,正确配置需注意两点:
- 日志时间戳的正确路径是
log.timestamp,而非直接写timestamp - 传入的
timestamp是字符串类型,需要先转为整数再转换为OTLP支持的时间格式
修改后的transform处理器配置:
processors: transform/example: log_statements: - context: log statements: - set(log.timestamp, time_unix_nano(to_int(attributes["timestamp"])))
完整可用配置:
receivers: fluentforward: endpoint: 0.0.0.0:8006 processors: transform/example: log_statements: - context: log statements: - set(log.timestamp, time_unix_nano(to_int(attributes["timestamp"]))) exporters: logging: loglevel: debug service: pipelines: logs: receivers: [fluentforward] processors: [transform/example] exporters: [logging]
内容的提问来源于stack exchange,提问作者Eitan
相关产品推荐
相关产品推荐

