You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用OpenTelemetry处理器处理日志body.str属性中的信息?

处理OpenTelemetry中body.str字段的日志过滤方案

要对body.str中的内容执行操作(比如删除entryPointName为特定值的日志),需要先将该字符串字段解析为结构化属性,再使用过滤处理器筛选日志,具体步骤和配置如下:

1. 解析body.str为结构化属性

使用json_parser处理器,将非标准JSON格式的body.str字符串解析为结构化的body对象。该处理器支持宽松解析模式,适配你日志中无引号键、单引号值的格式:

processors:
  json_parser/parse_body:
    parse_from: body.str  # 从body.str读取待解析的字符串
    parse_to: body        # 将解析结果写入body字段
    allow_unquoted_field_names: true  # 允许键不带引号
    allow_single_quotes: true         # 允许值使用单引号

2. 过滤指定entryPointName的日志

使用filter处理器,根据解析后的body.entryPointName字段排除目标日志:

filter/entrypoint_filter:
  error_mode: ignore  # 解析失败的日志不丢弃,继续处理
  logs:
    exclude:
      match_type: strict
      record_attributes:
        - key: body.entryPointName
          value: 'traefik'  # 要删除的entryPointName值

3. 整合原有处理器并调整执行顺序

处理器的执行顺序至关重要,必须先完成解析,再过滤,最后执行你原有的属性处理逻辑。完整的Helm配置示例如下:

processors:
  json_parser/parse_body:
    parse_from: body.str
    parse_to: body
    allow_unquoted_field_names: true
    allow_single_quotes: true
  filter/entrypoint_filter:
    error_mode: ignore
    logs:
      exclude:
        match_type: strict
        record_attributes:
          - key: body.entryPointName
            value: 'traefik'
  attributes/example:
    actions:
    - key: log.file.path
      action: hash
    - key: time
      action: hash
    - key: body.str  # 可选:解析完成后删除原body.str字段
      action: delete
  resource:
    attributes:
    - key: k8s.container.name
      action: hash

service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [json_parser/parse_body, filter/entrypoint_filter, attributes/example, resource]
      exporters: [your_exporter_name]  # 替换为你的实际导出器

关键说明

  • 解析后的日志会生成结构化的body字段,你可以基于其中的任意字段(如RequestPath、DownstreamStatus等)执行更多过滤或属性操作。
  • 如果不需要保留原始的body.str字段,可在attributes/example处理器中添加delete动作移除它。
  • error_mode: ignore确保解析失败的日志不会被误丢弃,可根据实际需求调整为drop或propagate。

内容的提问来源于stack exchange,提问作者everspader

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 01:47:41