You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch log4j2配置后旧.gz日志未按规则删除排查求助

Elasticsearch 7.17.11 log4j2旧日志删除规则未生效排查方案

核心问题点排查

1. 配置笔误(最关键)

你的rolling_old appender的删除策略配置存在前缀错误:原配置中rolling_old的Delete Action部分仍使用了appender.rolling.strategy.action前缀,而非appender.rolling_old.strategy.action,导致该appender的删除规则完全未被加载。

错误配置片段:

appender.rolling_old.strategy.action.type = Delete
appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling.strategy.action.condition.type = IfFileName
...

修正后应为:

appender.rolling_old.strategy.action.type = Delete
appender.rolling_old.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling_old.strategy.action.condition.type = IfFileName
appender.rolling_old.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*-*.log.gz
appender.rolling_old.strategy.action.condition.nested_condition.type = IfLastModified
appender.rolling_old.strategy.action.condition.nested_condition.age = 1D

2. Glob模式配置错误

IfFileName的glob参数存在两个问题:

  • 无需在glob中重复basepath路径(已由basepath字段指定,glob仅需匹配basepath下的文件名)
  • 不能使用log4j的日期占位符%d{yyyy-MM-dd},需使用标准文件通配符匹配文件名

正确的glob写法示例:

  • 匹配json.gz日志:${sys:es.logs.cluster_name}-*-*.json.gz
  • 匹配log.gz日志:${sys:es.logs.cluster_name}-*-*.log.gz

3. Delete Action触发时机误解

log4j2的DefaultRolloverStrategy下的Delete Action仅在日志滚动事件发生时执行,并非定时后台清理。如果测试期间未触发滚动(比如日志大小未达100MB、时间未到滚动周期),删除逻辑不会运行。

测试建议:

  • 临时将SizeBasedTriggeringPolicy的size改为1MB,快速触发滚动
  • 手动重启Elasticsearch触发初始滚动

4. 权限与文件属性验证

  • 确认elasticsearch用户对/var/log/elasticsearch目录有删除权限:
    su - elasticsearch -c "touch /var/log/elasticsearch/test-delete && rm /var/log/elasticsearch/test-delete"
    
  • 检查旧日志的LastModified时间,确认确实超过1天:
    ls -l /var/log/elasticsearch/*.gz
    

5. 配置加载有效性验证

查看Elasticsearch启动日志(如/var/log/elasticsearch/asa-test.log),确认无log4j2配置解析错误的ERROR级日志,比如类似Could not create component of type class org.apache.logging.log4j.core.appender.rolling.action.DeleteAction的报错。

修正后的完整配置片段示例

######## Server JSON ############################
appender.rolling.type = RollingFile
appender.rolling.name = plain_rolling
appender.rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_server.json
appender.rolling.layout.type = ESJsonLayout
appender.rolling.layout.type_name = server

appender.rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.json.gz
appender.rolling.policies.type = Policies
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval = 1
appender.rolling.policies.time.modulate = true
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 100MB
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.fileIndex = nomax
appender.rolling.strategy.action.type = Delete
appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling.strategy.action.condition.type = IfFileName
appender.rolling.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*-*.json.gz
appender.rolling.strategy.action.condition.nested_condition.type = IfLastModified
appender.rolling.strategy.action.condition.nested_condition.age = 1D
################################################
######## Server -  old style pattern ###########
appender.rolling_old.type = RollingFile
appender.rolling_old.name = rolling_old
appender.rolling_old.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}.log
appender.rolling_old.layout.type = PatternLayout
appender.rolling_old.layout.pattern = [%d{ISO8601}][%-5p][%-25c{1.}] [%node_name]%marker %m%n

appender.rolling_old.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.log.gz
appender.rolling_old.policies.type = Policies
appender.rolling_old.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling_old.policies.time.interval = 1
appender.rolling_old.policies.time.modulate = true
appender.rolling_old.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling_old.policies.size.size = 100MB
appender.rolling_old.strategy.type = DefaultRolloverStrategy
appender.rolling_old.strategy.fileIndex = nomax
appender.rolling_old.strategy.action.type = Delete
appender.rolling_old.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling_old.strategy.action.condition.type = IfFileName
appender.rolling_old.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*-*.log.gz
appender.rolling_old.strategy.action.condition.nested_condition.type = IfLastModified
appender.rolling_old.strategy.action.condition.nested_condition.age = 1D
################################################

内容的提问来源于stack exchange,提问作者Shane

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 03:47:11