如何使用OpenTelemetry处理器处理日志body.str属性中的信息?
处理OpenTelemetry中body.str字段的日志过滤方案
要对body.str中的内容执行操作(比如删除entryPointName为特定值的日志),需要先将该字符串字段解析为结构化属性,再使用过滤处理器筛选日志,具体步骤和配置如下:
1. 解析body.str为结构化属性
使用json_parser处理器,将非标准JSON格式的body.str字符串解析为结构化的body对象。该处理器支持宽松解析模式,适配你日志中无引号键、单引号值的格式:
processors: json_parser/parse_body: parse_from: body.str # 从body.str读取待解析的字符串 parse_to: body # 将解析结果写入body字段 allow_unquoted_field_names: true # 允许键不带引号 allow_single_quotes: true # 允许值使用单引号
2. 过滤指定entryPointName的日志
使用filter处理器,根据解析后的body.entryPointName字段排除目标日志:
filter/entrypoint_filter: error_mode: ignore # 解析失败的日志不丢弃,继续处理 logs: exclude: match_type: strict record_attributes: - key: body.entryPointName value: 'traefik' # 要删除的entryPointName值
3. 整合原有处理器并调整执行顺序
处理器的执行顺序至关重要,必须先完成解析,再过滤,最后执行你原有的属性处理逻辑。完整的Helm配置示例如下:
processors: json_parser/parse_body: parse_from: body.str parse_to: body allow_unquoted_field_names: true allow_single_quotes: true filter/entrypoint_filter: error_mode: ignore logs: exclude: match_type: strict record_attributes: - key: body.entryPointName value: 'traefik' attributes/example: actions: - key: log.file.path action: hash - key: time action: hash - key: body.str # 可选:解析完成后删除原body.str字段 action: delete resource: attributes: - key: k8s.container.name action: hash service: pipelines: logs: receivers: [filelog] processors: [json_parser/parse_body, filter/entrypoint_filter, attributes/example, resource] exporters: [your_exporter_name] # 替换为你的实际导出器
关键说明
- 解析后的日志会生成结构化的
body字段,你可以基于其中的任意字段(如RequestPath、DownstreamStatus等)执行更多过滤或属性操作。 - 如果不需要保留原始的
body.str字段,可在attributes/example处理器中添加delete动作移除它。 error_mode: ignore确保解析失败的日志不会被误丢弃,可根据实际需求调整为drop或propagate。
内容的提问来源于stack exchange,提问作者everspader
相关产品推荐
相关产品推荐

