CloudWatch Agent无法采集EC2的/var/log/secure日志求助
问题根源与解决方案
核心问题:配置文件未被正确加载
你的fetch-config命令存在两处关键错误,导致CloudWatch Agent没有读取到JSON配置中的日志采集规则:
- 文件路径格式错误:本地文件路径的
file协议需要以file:///(三个斜杠)开头,你使用的file://opt/...缺少一个斜杠,Agent无法定位到配置文件。 - 参数顺序错误:
-c(指定配置源)参数需紧跟在-m ec2之后,你之前的命令把配置路径直接放在-m ec2后,导致参数解析异常。
另外,配置文件里的日志组名存在拼写错误:test/sercure应改为test/secure,避免后续日志组名称不匹配。
修复步骤
1. 执行正确的配置加载命令
运行以下命令重新加载配置:
sudo ./amazon-cloudwatch-agent-ctl -a fetch-config -m ec2 -c file:///opt/aws/amazon-cloudwatch-agent/bin/config.json -s
2. 修正配置文件的拼写错误
编辑config.json,修正日志组名的拼写:
{ "agent": { "metrics_collection_interval": 10, "logfile": "/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log", "run_as_user": "root" }, "logs": { "logs_collected": { "files": { "collect_list": [ { "file_path": "/var/log/secure", "log_group_name": "test/secure", // 修正拼写错误 "log_stream_name": "{instance_id}" } ] } } }, "metrics": { "namespace": "test", "metrics_collected": { "swap": { "measurement": [ "swap_used", "swap_free", "swap_used_percent" ] }, "mem": { "measurement": [ "mem_used", "mem_cached", "mem_total" ], "metrics_collection_interval": 1 } }, "append_dimensions": { "ImageId": "${aws:ImageId}", "InstanceId": "${aws:InstanceId}", "InstanceType": "${aws:InstanceType}" } } }
3. 验证配置是否生效
重新加载配置后,查看生成的/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.toml,确认其中包含日志采集相关配置段,示例如下:
[[inputs.tail]] file_path = "/var/log/secure" from_beginning = false log_group_name = "test/secure" log_stream_name = "{instance_id}" tag_keys = [] [inputs.tail.tags] metricPath = "logs"
4. 检查Agent运行状态
执行以下命令确认Agent运行正常:
sudo ./amazon-cloudwatch-agent-ctl -m ec2 -a status
如果仍有问题,可在config.json的agent部分添加"debug": true,重新加载配置后查看/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log获取详细调试信息。
额外说明
你安装的collectd与本次日志采集问题无关,无需保留。你的IAM权限已覆盖日志采集所需的logs:PutLogEvents等操作,权限部分无需调整。
内容的提问来源于stack exchange,提问作者P Lli
相关产品推荐
相关产品推荐

