Td-agent未发送历史缓存日志求助:重命名缓存文件是否可行?
Fluentd历史缓存文件未发送问题处理咨询
问题背景
主Fluentd聚合实例被误重建,导致td-agent缓冲实例与其断连约12小时,积累了大量日志。修复连接并重启td-agent后,功能在2天后恢复,但5月9日至11日的日志未被发送至聚合端。
当前td-agent配置
<source> # legacy trackevent schema: missing field1-field7 type tail log_level error path /var/log/php-fpm/track_access_hlog pos_file /var/log/php-fpm/legacy-trackevent.pos time_format %d/%b/%Y:%H:%M:%S format /^\[(?<dateday>[^ ]+) .+\] (?:\S+) \/(?<event>(?!(.*PING)|(PUSH_ALL)|(PUSH_ARRIVAL)|(PUSH_MUTE)|(PUSH_NOT)|(PUSH_RECEIVED)|(PUSH_SENT)|(VIDEO.*))[^\/]+)\/(?:[^\/]*)\/(?<userid>[^\/]*)\/(?<session>[^\/]*)\/(?<broadcastid>[^\/]*)\/(?<doorid>[^\/]*)\/(?<userlevel>[^\/]*)\/(?<broadcastscount>[^\/]*)\/(?<unspentcoins>[^\/]*)\/(?:[^\/]*)\/(?<extradata>[^\/]*)\/(?<coins>[^\/]*)\/(?<points>[^\/]*)\/(?<platform>[^\/]*)\/(?<sourceid>[^\/]*)\/(?<domain>[^\/]*)\/trpxl\.gif.*$/ time_key dateday tag tracklive.ip </source> <source> # "current" trackevent schema: requires field1-field7 type tail log_level error path /var/log/php-fpm/track_access_hlog pos_file /var/log/php-fpm/track-access.log.pos # This is where you record file position time_format %d/%b/%Y:%H:%M:%S format /^\[(?<dateday>[^ ]+) .+\] (?:\S+) \/(?<event>(?!(.*PING)|(PUSH_ALL)|(PUSH_ARRIVAL)|(PUSH_MUTE)|(PUSH_NOT)|(PUSH_RECEIVED)|(PUSH_SENT)|(VIDEO.*))[^\/]+)\/(?:[^\/]*)\/(?<userid>[^\/]*)\/(?<session>[^\/]*)\/(?<broadcastid>[^\/]*)\/(?<doorid>[^\/]*)\/(?<userlevel>[^\/]*)\/(?<broadcastscount>[^\/]*)\/(?<unspentcoins>[^\/]*)\/(?:[^\/]*)\/(?<extradata>[^\/]*)\/(?<coins>[^\/]*)\/(?<points>[^\/]*)\/(?<platform>[^\/]*)\/(?<sourceid>[^\/]*)\/(?<domain>[^\/]*)\/(?<field1>[^\/]*)\/(?<field2>[^\/]*)\/(?<field3>[^\/]*)\/(?<field4>[^\/]*)\/(?<field5>[^\/]*)\/(?<field6>[^\/]*)\/(?<field7>[^\/]*)\/trpxl\.gif.*$/ time_key dateday tag tracklive.ip </source> <match tracklive.**> @type forward @id forward_output phi_failure_detector false send_timeout 10s expire_dns_cache 60s buffer_queue_limit 256 buffer_chunk_limit 16m buffer_type file buffer_path /var/log/td-agent/buffer/ <server> name fluentd-aggregator-box host fluentd.ourdomainxxxx.com </server> </match> <source> type tail log_level error format /^\[(?<dateday>[^ ]+) .+\][^\/]+\/(?<event>PUSH[^\/]*)\/[^\/]*\/(?<userid>[^\/]*)\/(?<session>[^\/]*)\/(?<broadcastid>[^\/]*)\/(?<doorid>[^\/]*)\/(?<userlevel>[^\/]*)\/[^\/]*\/(?<unspentcoins>[^\/]*)\/[^\/]*\/(?<push_origin>[^\/]*)\/[^\/]*\/[^\/]*\/(?<platform>[^\/]*)\/(?<sourceid>[^\/]*)\/(?<deviceid>[^\/]*)\/(?<push_type>[^\/]*)\/(?<channel_id>[^\/]*)\/(?<reserved128>[^\/]*)\/(?<reserved256>[^\/]*)\/(?<mobile_app_version>[^\/]*)\/(?<language>[^\/]*)\/(?<legacy_app_version>[^\/]*)\/trpxl.gif.*/ path /var/log/php-fpm/track_access_hlog pos_file /var/log/php-fpm/push-event.pos time_format %d/%b/%Y:%H:%M:%S # nginx default tag push_events.ip </source> <match push_events.**> type forward phi_failure_detector false send_timeout 36000s expire_dns_cache 60s buffer_queue_limit 1800 buffer_chunk_limit 20M buffer_type file buffer_path /var/log/td-agent/buffer_push_events/ <server> host fluentd.ourdomainxxxx.com </server> </match>
已尝试操作
- 修改配置并重启td-agent
- 执行命令
kill -USR1 $(cat /var/run/td-agent/td-agent.pid)强制处理缓存
咨询问题
- 将历史缓存文件重命名为更高序号是否能让td-agent拾取发送?
- 该操作是否会引发后续问题?
问题解答
重命名缓存文件的有效性
Fluentd的文件缓冲系统依赖**缓冲目录下的元数据文件(如buffer.*.meta)**追踪缓冲块状态,而非单纯的文件名序号。元数据记录了缓冲块的待发送、已发送、失败等状态:
- 如果历史缓存对应的元数据已被标记为"已处理"或"过期",仅重命名日志文件无效。
- 若元数据完好且状态正确,可尝试以下步骤:
- 停止td-agent服务:
systemctl stop td-agent - 将历史缓存文件的序号修改为当前最新缓冲文件序号之后的数值(保持十六进制格式,比如当前最新是
buffer.000000123.log,改为buffer.000000456.log) - 同步重命名对应的
.meta文件(如buffer.000000123.meta改为buffer.000000456.meta) - 重启td-agent:
systemctl start td-agent
这种操作可能让Fluentd重新识别并发送这些缓冲块。
- 停止td-agent服务:
潜在风险与后续问题
- 数据重复:若历史缓存已部分发送,重命名后可能导致重复日志流入聚合端,需提前确认下游系统能否处理重复数据。
- 队列阻塞:大量历史缓存加入队列会占用
buffer_queue_limit资源,可能导致新日志无法写入,需临时调大该参数,待数据发送完成后恢复原值。 - 元数据损坏:操作失误(如漏改元数据、文件名格式错误)可能导致Fluentd无法识别缓冲文件,甚至服务启动失败,操作前务必备份整个缓冲目录。
- 性能影响:发送大量历史数据会占用网络带宽和聚合端资源,建议在低峰时段操作,避免影响正常业务。
替代方案
若重命名无效,更可靠的方式是手动发送:
- 备份历史缓存文件
- 使用
fluent-cat工具发送,根据缓存对应的tag替换参数:# 发送tracklive类缓存 cat /var/log/td-agent/buffer/old_buffer_file.log | fluent-cat -t tracklive.ip -f none # 发送push_events类缓存 cat /var/log/td-agent/buffer_push_events/old_buffer_file.log | fluent-cat -t push_events.ip -f none
内容的提问来源于stack exchange,提问作者user3248750
相关产品推荐
相关产品推荐

