如何在AKS中为WSO2 APIM 4.2搭建ELK监控及Azure替代方案
AKS中WSO2 APIM 4.2与ELK集成最佳实践
核心问题解决:推送api_metric.log至ELK
在AKS环境下,最可靠的方式是通过Filebeat Sidecar容器收集WSO2 APIM Pod内的api_metric.log,直接推送到Elasticsearch(或经Logstash中转)。相比节点级Filebeat,Sidecar模式能精准绑定目标Pod,避免跨Pod日志权限混乱和数据污染。
步骤1:配置WSO2 APIM输出JSON格式的api_metric日志
修改WSO2 APIM的log4j2.xml配置文件(路径:repository/conf/log4j2.xml),将api_metric的日志输出改为JSON格式,方便ELK解析:
<Appender type="RollingFile" name="API_METRIC" fileName="${sys:carbon.home}/repository/logs/api_metric.log" filePattern="${sys:carbon.home}/repository/logs/api_metric-%d{MM-dd-yyyy}.log"> <Layout type="JsonLayout" complete="false" compact="true" eventEol="true"> <KeyValuePair key="service" value="wso2-apim"/> <KeyValuePair key="environment" value="aks"/> </Layout> <Policies> <TimeBasedTriggeringPolicy interval="1" modulate="true"/> </Policies> </Appender>
确保WSO2的Deployment/YAML中通过ConfigMap或Volume挂载该配置文件。
步骤2:在AKS中部署ELK栈
使用Elastic官方Helm Chart快速部署:
- 添加Elastic Helm仓库:
helm repo add elastic https://helm.elastic.co helm repo update - 部署单节点Elasticsearch(生产建议多节点集群):
helm install elasticsearch elastic/elasticsearch --set replicas=1 --namespace elk - 部署Kibana:
helm install kibana elastic/kibana --namespace elk --set elasticsearchHosts=http://elasticsearch-master:9200
生产环境需配置持久化存储、RBAC权限和TLS加密。
步骤3:为WSO2 APIM Pod添加Filebeat Sidecar
在WSO2 APIM的Deployment YAML中添加Filebeat容器,挂载WSO2日志目录并配置采集规则:
containers: - name: wso2-apim image: wso2/wso2am:4.2.0 volumeMounts: - name: wso2-logs mountPath: /home/wso2carbon/wso2am-4.2.0/repository/logs - name: filebeat image: docker.elastic.co/beats/filebeat:8.11.0 volumeMounts: - name: wso2-logs mountPath: /var/log/wso2 readOnly: true - name: filebeat-config mountPath: /usr/share/filebeat/filebeat.yml subPath: filebeat.yml volumes: - name: wso2-logs emptyDir: {} # 生产建议替换为PersistentVolumeClaim - name: filebeat-config configMap: name: filebeat-apim-config
对应的Filebeat ConfigMap配置(filebeat-apim-config):
apiVersion: v1 kind: ConfigMap metadata: name: filebeat-apim-config data: filebeat.yml: | filebeat.inputs: - type: filestream paths: - /var/log/wso2/api_metric.log fields: log_type: api_metric service: wso2-apim output.elasticsearch: hosts: ["elasticsearch-master.elk.svc.cluster.local:9200"] index: "wso2-apim-metrics-%{+yyyy.MM.dd}" setup.ilm.enabled: true setup.template.name: "wso2-apim-metrics" setup.template.pattern: "wso2-apim-metrics-*"
集成最佳实践
- Sidecar优先:避免使用节点级Filebeat,防止Pod日志被其他容器干扰,同时简化权限管理(只需授予Filebeat读取当前Pod日志目录的权限)。
- 日志标准化:统一输出JSON格式日志,减少Logstash的解析逻辑,让Elasticsearch直接识别
timestamp、api_name、response_time等核心字段。 - 资源隔离:为ELK组件和Filebeat配置CPU/内存请求与限制,例如给Elasticsearch分配
2CPU/4Gi,Filebeat分配0.2CPU/256Mi,避免耗尽AKS节点资源。 - 生命周期管理:在Elasticsearch中配置索引生命周期策略(ILM),自动将旧日志归档或删除,降低存储成本。
- 安全加固:为Elasticsearch启用RBAC,创建专用用户供Filebeat连接;开启TLS加密传输,避免日志数据泄露。
Azure替代服务方案
如果不想自行维护ELK栈,可选择以下Azure托管服务:
- Azure Monitor + Container Insights:直接集成AKS,自动收集Pod日志(包括
api_metric.log)。通过Log Analytics Workspace存储日志,使用Kusto查询语言分析API指标,还可创建自定义仪表盘和告警规则。 - Azure Elasticsearch Service:托管式ELK服务,由Elastic和Azure联合维护,支持一键部署、自动扩容和备份。只需将Filebeat的输出指向该服务的endpoint,无需自行管理集群。
- Azure Log Analytics:作为独立的日志分析平台,配合Container Insights采集WSO2 APIM日志,支持多数据源聚合,可与Azure Sentinel集成实现安全监控。
内容的提问来源于stack exchange,提问作者Prakash B
相关产品推荐
相关产品推荐

