You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac M2上Fluent Bit读取KubeApi日志无输出问题求助

Fluent Bit tail输入K8s API日志无输出问题排查

我在Mac M2设备上运行Fluent Bit 2.1.7版本,尝试处理包含10条记录的KubeApi Server日志文件,但运行后输出为空;将INPUT替换为dummy输入时则能正常输出。

当前配置

[SERVICE]
    Daemon Off
    Flush 1

[INPUT]
    Name tail
    Path /Users/me/temp/fluentbit/source/*.log

[OUTPUT]
    Name file
    Match *
    File out.log
    Path /Users/me/temp/fluentbit/target

运行日志

[2023/07/20 21:56:11] [ info] [fluent bit] version=2.1.7, commit=, pid=494
[2023/07/20 21:56:11] [debug] [engine] coroutine stack size: 24576 bytes (24.0K)
[2023/07/20 21:56:11] [ info] [storage] ver=1.4.0, type=memory, sync=normal, checksum=off, max_chunks_up=128
[2023/07/20 21:56:11] [ info] [cmetrics] version=0.6.3
[2023/07/20 21:56:11] [ info] [ctraces ] version=0.3.1
[2023/07/20 21:56:11] [ info] [input:tail:tail.0] initializing
[2023/07/20 21:56:11] [ info] [input:tail:tail.0] storage_strategy='memory' (memory only)
[2023/07/20 21:56:11] [debug] [tail:tail.0] created event channels: read=21 write=22
[2023/07/20 21:56:11] [ info] [input:tail:tail.0] multiline core started
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] flb_tail_fs_stat_init() initializing stat tail input
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] scanning path /Users/me/temp/fluentbit/source/*.log
[2023/07/20 21:56:11] [ info] [output:file:file.0] worker #0 started
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] inode=81899958 with offset=2843 appended as /Users/me/temp/fluentbit/source/kube-apiserver-kube-master_kube-system_kube-apiserver-67b2090d83e1f84c52f2c0fd516828d723fb26d6272b039739cdcc0c39604fe4.log
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] scan_glob add(): /Users/me/temp/fluentbit/source/kube-apiserver-kube-master_kube-system_kube-apiserver-67b2090d83e1f84c52f2c0fd516828d723fb26d6272b039739cdcc0c39604fe4.log, inode 81899958
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] 1 new files found on path '/Users/me/temp/fluentbit/source/*.log'
[2023/07/20 21:56:11] [debug] [file:file.0] created event channels: read=29 write=30
[2023/07/20 21:56:11] [ info] [sp] stream processor started
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] inode=81899958 file=/Users/me/temp/fluentbit/source/kube-apiserver-kube-master_kube-system_kube-apiserver-67b2090d83e1f84c52f2c0fd516828d723fb26d6272b039739cdcc0c39604fe4.log promote to TAIL_EVENT
[2023/07/20 21:56:11] [debug] [input:tail:tail.0] [static files] processed 0b, done
^C[2023/07/20 21:56:33] [engine] caught signal (SIGINT)
[2023/07/20 21:56:33] [ info] [input] pausing tail.0
[2023/07/20 21:56:33] [debug] [input:tail:tail.0] inode=81899958 removing file name /Users/me/temp/fluentbit/source/kube-apiserver-kube-master_kube-system_kube-apiserver-67b2090d83e1f84c52f2c0fd516828d723fb26d6272b039739cdcc0c39604fe4.log
[2023/07/20 21:56:33] [ info] [output:file:file.0] thread worker #0 stopping...
[2023/07/20 21:56:33] [ info] [output:file:file.0] thread worker #0 stopped

可能的原因及解决办法

  • 文件偏移量问题:从日志看,Fluent Bit加载文件时记录的offset是2843,说明它认为这个文件已经读到了2843字节的位置,不会再读取之前的内容。tail插件默认只追踪文件新增内容,对于已存在的静态文件,需要配置read_from_head true来从头读取。
  • 多行日志未正确拼接:KubeApi Server日志是多行格式,默认的tail配置可能没有正确处理多行,导致日志被当成不完整的记录而被缓存,没有输出。需要添加多行解析配置,示例:
    [INPUT]
        Name tail
        Path /Users/me/temp/fluentbit/source/*.log
        read_from_head true
        multiline.parser docker, cri
    
  • 文件权限问题:虽然日志显示文件被找到,但Mac M2的系统隐私设置可能限制了Fluent Bit读取文件的内容。可以检查Fluent Bit是否有访问该目录的权限,或者用sudo运行测试。
  • 内存存储的偏移记录:因为用了storage_strategy='memory',如果之前运行过Fluent Bit读取过这个文件,内存中会保留偏移量。可以重启Fluent Bit时加上read_from_head true强制从头读取,或者指定持久化存储路径来管理偏移记录。

内容的提问来源于stack exchange,提问作者Pavel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 17:16:11