You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AKS中为WSO2 APIM 4.2搭建ELK监控及Azure替代方案

AKS中WSO2 APIM 4.2与ELK集成最佳实践

核心问题解决:推送api_metric.log至ELK

在AKS环境下,最可靠的方式是通过Filebeat Sidecar容器收集WSO2 APIM Pod内的api_metric.log,直接推送到Elasticsearch(或经Logstash中转)。相比节点级Filebeat,Sidecar模式能精准绑定目标Pod,避免跨Pod日志权限混乱和数据污染。

步骤1:配置WSO2 APIM输出JSON格式的api_metric日志

修改WSO2 APIM的log4j2.xml配置文件(路径:repository/conf/log4j2.xml),将api_metric的日志输出改为JSON格式,方便ELK解析:

<Appender type="RollingFile" name="API_METRIC" fileName="${sys:carbon.home}/repository/logs/api_metric.log"
          filePattern="${sys:carbon.home}/repository/logs/api_metric-%d{MM-dd-yyyy}.log">
    <Layout type="JsonLayout" complete="false" compact="true" eventEol="true">
        <KeyValuePair key="service" value="wso2-apim"/>
        <KeyValuePair key="environment" value="aks"/>
    </Layout>
    <Policies>
        <TimeBasedTriggeringPolicy interval="1" modulate="true"/>
    </Policies>
</Appender>

确保WSO2的Deployment/YAML中通过ConfigMap或Volume挂载该配置文件。

步骤2:在AKS中部署ELK栈

使用Elastic官方Helm Chart快速部署:

  1. 添加Elastic Helm仓库:
    helm repo add elastic https://helm.elastic.co
    helm repo update
    
  2. 部署单节点Elasticsearch(生产建议多节点集群):
    helm install elasticsearch elastic/elasticsearch --set replicas=1 --namespace elk
    
  3. 部署Kibana:
    helm install kibana elastic/kibana --namespace elk --set elasticsearchHosts=http://elasticsearch-master:9200
    

生产环境需配置持久化存储、RBAC权限和TLS加密。

步骤3:为WSO2 APIM Pod添加Filebeat Sidecar

在WSO2 APIM的Deployment YAML中添加Filebeat容器,挂载WSO2日志目录并配置采集规则:

containers:
  - name: wso2-apim
    image: wso2/wso2am:4.2.0
    volumeMounts:
      - name: wso2-logs
        mountPath: /home/wso2carbon/wso2am-4.2.0/repository/logs
  - name: filebeat
    image: docker.elastic.co/beats/filebeat:8.11.0
    volumeMounts:
      - name: wso2-logs
        mountPath: /var/log/wso2
        readOnly: true
      - name: filebeat-config
        mountPath: /usr/share/filebeat/filebeat.yml
        subPath: filebeat.yml
volumes:
  - name: wso2-logs
    emptyDir: {} # 生产建议替换为PersistentVolumeClaim
  - name: filebeat-config
    configMap:
      name: filebeat-apim-config

对应的Filebeat ConfigMap配置(filebeat-apim-config):

apiVersion: v1
kind: ConfigMap
metadata:
  name: filebeat-apim-config
data:
  filebeat.yml: |
    filebeat.inputs:
      - type: filestream
        paths:
          - /var/log/wso2/api_metric.log
        fields:
          log_type: api_metric
          service: wso2-apim
    output.elasticsearch:
      hosts: ["elasticsearch-master.elk.svc.cluster.local:9200"]
      index: "wso2-apim-metrics-%{+yyyy.MM.dd}"
    setup.ilm.enabled: true
    setup.template.name: "wso2-apim-metrics"
    setup.template.pattern: "wso2-apim-metrics-*"

集成最佳实践

  • Sidecar优先:避免使用节点级Filebeat,防止Pod日志被其他容器干扰,同时简化权限管理(只需授予Filebeat读取当前Pod日志目录的权限)。
  • 日志标准化:统一输出JSON格式日志,减少Logstash的解析逻辑,让Elasticsearch直接识别timestamp、api_name、response_time等核心字段。
  • 资源隔离:为ELK组件和Filebeat配置CPU/内存请求与限制,例如给Elasticsearch分配2CPU/4Gi,Filebeat分配0.2CPU/256Mi,避免耗尽AKS节点资源。
  • 生命周期管理:在Elasticsearch中配置索引生命周期策略(ILM),自动将旧日志归档或删除,降低存储成本。
  • 安全加固:为Elasticsearch启用RBAC,创建专用用户供Filebeat连接;开启TLS加密传输,避免日志数据泄露。

Azure替代服务方案

如果不想自行维护ELK栈,可选择以下Azure托管服务:

  • Azure Monitor + Container Insights:直接集成AKS,自动收集Pod日志(包括api_metric.log)。通过Log Analytics Workspace存储日志,使用Kusto查询语言分析API指标,还可创建自定义仪表盘和告警规则。
  • Azure Elasticsearch Service:托管式ELK服务,由Elastic和Azure联合维护,支持一键部署、自动扩容和备份。只需将Filebeat的输出指向该服务的endpoint,无需自行管理集群。
  • Azure Log Analytics:作为独立的日志分析平台,配合Container Insights采集WSO2 APIM日志,支持多数据源聚合,可与Azure Sentinel集成实现安全监控。

内容的提问来源于stack exchange,提问作者Prakash B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 21:43:17