You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudWatch Agent无法采集EC2的/var/log/secure日志求助

问题根源与解决方案

核心问题:配置文件未被正确加载

你的fetch-config命令存在两处关键错误,导致CloudWatch Agent没有读取到JSON配置中的日志采集规则:

  1. 文件路径格式错误:本地文件路径的file协议需要以file:///(三个斜杠)开头,你使用的file://opt/...缺少一个斜杠,Agent无法定位到配置文件。
  2. 参数顺序错误:-c(指定配置源)参数需紧跟在-m ec2之后,你之前的命令把配置路径直接放在-m ec2后,导致参数解析异常。

另外,配置文件里的日志组名存在拼写错误:test/sercure应改为test/secure,避免后续日志组名称不匹配。


修复步骤

1. 执行正确的配置加载命令

运行以下命令重新加载配置:

sudo ./amazon-cloudwatch-agent-ctl -a fetch-config -m ec2 -c file:///opt/aws/amazon-cloudwatch-agent/bin/config.json -s

2. 修正配置文件的拼写错误

编辑config.json,修正日志组名的拼写:

{
  "agent": {
    "metrics_collection_interval": 10,
    "logfile": "/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log",
    "run_as_user": "root"
  },
  "logs": {
      "logs_collected": {
        "files": {
         "collect_list": [
            {
              "file_path": "/var/log/secure",
              "log_group_name": "test/secure", // 修正拼写错误
              "log_stream_name": "{instance_id}"
            }
          ]
        }
      }
    },
  "metrics": {
    "namespace": "test",
    "metrics_collected": {
     "swap": {
       "measurement": [
         "swap_used",
         "swap_free",
         "swap_used_percent"
       ]
     },
     "mem": {
       "measurement": [
         "mem_used",
         "mem_cached",
         "mem_total"
       ],
       "metrics_collection_interval": 1
     }
   },
   "append_dimensions": {
     "ImageId": "${aws:ImageId}",
     "InstanceId": "${aws:InstanceId}",
     "InstanceType": "${aws:InstanceType}"
   }
 }
}

3. 验证配置是否生效

重新加载配置后,查看生成的/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.toml,确认其中包含日志采集相关配置段,示例如下:

[[inputs.tail]]
  file_path = "/var/log/secure"
  from_beginning = false
  log_group_name = "test/secure"
  log_stream_name = "{instance_id}"
  tag_keys = []
  [inputs.tail.tags]
    metricPath = "logs"

4. 检查Agent运行状态

执行以下命令确认Agent运行正常:

sudo ./amazon-cloudwatch-agent-ctl -m ec2 -a status

如果仍有问题,可在config.json的agent部分添加"debug": true,重新加载配置后查看/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log获取详细调试信息。


额外说明

你安装的collectd与本次日志采集问题无关,无需保留。你的IAM权限已覆盖日志采集所需的logs:PutLogEvents等操作,权限部分无需调整。

内容的提问来源于stack exchange,提问作者P Lli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 03:39:54