Elasticsearch log4j2配置后旧.gz日志未按规则删除排查求助
Elasticsearch 7.17.11 log4j2旧日志删除规则未生效排查方案
核心问题点排查
1. 配置笔误(最关键)
你的rolling_old appender的删除策略配置存在前缀错误:原配置中rolling_old的Delete Action部分仍使用了appender.rolling.strategy.action前缀,而非appender.rolling_old.strategy.action,导致该appender的删除规则完全未被加载。
错误配置片段:
appender.rolling_old.strategy.action.type = Delete appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path} appender.rolling.strategy.action.condition.type = IfFileName ...
修正后应为:
appender.rolling_old.strategy.action.type = Delete appender.rolling_old.strategy.action.basepath = ${sys:es.logs.base_path} appender.rolling_old.strategy.action.condition.type = IfFileName appender.rolling_old.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*-*.log.gz appender.rolling_old.strategy.action.condition.nested_condition.type = IfLastModified appender.rolling_old.strategy.action.condition.nested_condition.age = 1D
2. Glob模式配置错误
IfFileName的glob参数存在两个问题:
- 无需在glob中重复
basepath路径(已由basepath字段指定,glob仅需匹配basepath下的文件名) - 不能使用log4j的日期占位符
%d{yyyy-MM-dd},需使用标准文件通配符匹配文件名
正确的glob写法示例:
- 匹配json.gz日志:
${sys:es.logs.cluster_name}-*-*.json.gz - 匹配log.gz日志:
${sys:es.logs.cluster_name}-*-*.log.gz
3. Delete Action触发时机误解
log4j2的DefaultRolloverStrategy下的Delete Action仅在日志滚动事件发生时执行,并非定时后台清理。如果测试期间未触发滚动(比如日志大小未达100MB、时间未到滚动周期),删除逻辑不会运行。
测试建议:
- 临时将
SizeBasedTriggeringPolicy的size改为1MB,快速触发滚动 - 手动重启Elasticsearch触发初始滚动
4. 权限与文件属性验证
- 确认elasticsearch用户对
/var/log/elasticsearch目录有删除权限:su - elasticsearch -c "touch /var/log/elasticsearch/test-delete && rm /var/log/elasticsearch/test-delete" - 检查旧日志的LastModified时间,确认确实超过1天:
ls -l /var/log/elasticsearch/*.gz
5. 配置加载有效性验证
查看Elasticsearch启动日志(如/var/log/elasticsearch/asa-test.log),确认无log4j2配置解析错误的ERROR级日志,比如类似Could not create component of type class org.apache.logging.log4j.core.appender.rolling.action.DeleteAction的报错。
修正后的完整配置片段示例
######## Server JSON ############################ appender.rolling.type = RollingFile appender.rolling.name = plain_rolling appender.rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_server.json appender.rolling.layout.type = ESJsonLayout appender.rolling.layout.type_name = server appender.rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.json.gz appender.rolling.policies.type = Policies appender.rolling.policies.time.type = TimeBasedTriggeringPolicy appender.rolling.policies.time.interval = 1 appender.rolling.policies.time.modulate = true appender.rolling.policies.size.type = SizeBasedTriggeringPolicy appender.rolling.policies.size.size = 100MB appender.rolling.strategy.type = DefaultRolloverStrategy appender.rolling.strategy.fileIndex = nomax appender.rolling.strategy.action.type = Delete appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path} appender.rolling.strategy.action.condition.type = IfFileName appender.rolling.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*-*.json.gz appender.rolling.strategy.action.condition.nested_condition.type = IfLastModified appender.rolling.strategy.action.condition.nested_condition.age = 1D ################################################ ######## Server - old style pattern ########### appender.rolling_old.type = RollingFile appender.rolling_old.name = rolling_old appender.rolling_old.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}.log appender.rolling_old.layout.type = PatternLayout appender.rolling_old.layout.pattern = [%d{ISO8601}][%-5p][%-25c{1.}] [%node_name]%marker %m%n appender.rolling_old.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.log.gz appender.rolling_old.policies.type = Policies appender.rolling_old.policies.time.type = TimeBasedTriggeringPolicy appender.rolling_old.policies.time.interval = 1 appender.rolling_old.policies.time.modulate = true appender.rolling_old.policies.size.type = SizeBasedTriggeringPolicy appender.rolling_old.policies.size.size = 100MB appender.rolling_old.strategy.type = DefaultRolloverStrategy appender.rolling_old.strategy.fileIndex = nomax appender.rolling_old.strategy.action.type = Delete appender.rolling_old.strategy.action.basepath = ${sys:es.logs.base_path} appender.rolling_old.strategy.action.condition.type = IfFileName appender.rolling_old.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*-*.log.gz appender.rolling_old.strategy.action.condition.nested_condition.type = IfLastModified appender.rolling_old.strategy.action.condition.nested_condition.age = 1D ################################################
内容的提问来源于stack exchange,提问作者Shane
相关产品推荐
相关产品推荐

