You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Td-agent未发送历史缓存日志求助:重命名缓存文件是否可行?

Fluentd历史缓存文件未发送问题处理咨询

问题背景

主Fluentd聚合实例被误重建,导致td-agent缓冲实例与其断连约12小时,积累了大量日志。修复连接并重启td-agent后,功能在2天后恢复,但5月9日至11日的日志未被发送至聚合端。

当前td-agent配置

<source>
  # legacy trackevent schema: missing field1-field7
  type tail
  log_level error
  path /var/log/php-fpm/track_access_hlog
  pos_file /var/log/php-fpm/legacy-trackevent.pos
  time_format %d/%b/%Y:%H:%M:%S
  format /^\[(?<dateday>[^ ]+) .+\] (?:\S+) \/(?<event>(?!(.*PING)|(PUSH_ALL)|(PUSH_ARRIVAL)|(PUSH_MUTE)|(PUSH_NOT)|(PUSH_RECEIVED)|(PUSH_SENT)|(VIDEO.*))[^\/]+)\/(?:[^\/]*)\/(?<userid>[^\/]*)\/(?<session>[^\/]*)\/(?<broadcastid>[^\/]*)\/(?<doorid>[^\/]*)\/(?<userlevel>[^\/]*)\/(?<broadcastscount>[^\/]*)\/(?<unspentcoins>[^\/]*)\/(?:[^\/]*)\/(?<extradata>[^\/]*)\/(?<coins>[^\/]*)\/(?<points>[^\/]*)\/(?<platform>[^\/]*)\/(?<sourceid>[^\/]*)\/(?<domain>[^\/]*)\/trpxl\.gif.*$/
  time_key dateday
  tag tracklive.ip
</source>
<source>
  # "current" trackevent schema: requires field1-field7
  type tail
  log_level error
  path /var/log/php-fpm/track_access_hlog
  pos_file /var/log/php-fpm/track-access.log.pos # This is where you record file position
  time_format %d/%b/%Y:%H:%M:%S
  format /^\[(?<dateday>[^ ]+) .+\] (?:\S+) \/(?<event>(?!(.*PING)|(PUSH_ALL)|(PUSH_ARRIVAL)|(PUSH_MUTE)|(PUSH_NOT)|(PUSH_RECEIVED)|(PUSH_SENT)|(VIDEO.*))[^\/]+)\/(?:[^\/]*)\/(?<userid>[^\/]*)\/(?<session>[^\/]*)\/(?<broadcastid>[^\/]*)\/(?<doorid>[^\/]*)\/(?<userlevel>[^\/]*)\/(?<broadcastscount>[^\/]*)\/(?<unspentcoins>[^\/]*)\/(?:[^\/]*)\/(?<extradata>[^\/]*)\/(?<coins>[^\/]*)\/(?<points>[^\/]*)\/(?<platform>[^\/]*)\/(?<sourceid>[^\/]*)\/(?<domain>[^\/]*)\/(?<field1>[^\/]*)\/(?<field2>[^\/]*)\/(?<field3>[^\/]*)\/(?<field4>[^\/]*)\/(?<field5>[^\/]*)\/(?<field6>[^\/]*)\/(?<field7>[^\/]*)\/trpxl\.gif.*$/
  time_key dateday
  tag tracklive.ip
</source>
<match tracklive.**>
  @type forward
  @id forward_output
  phi_failure_detector false
  send_timeout 10s
  expire_dns_cache 60s
  buffer_queue_limit  256
  buffer_chunk_limit  16m
  buffer_type  file
  buffer_path  /var/log/td-agent/buffer/
  <server>
    name fluentd-aggregator-box
    host fluentd.ourdomainxxxx.com
  </server>
</match>
<source>
  type tail
  log_level   error
  format      /^\[(?<dateday>[^ ]+) .+\][^\/]+\/(?<event>PUSH[^\/]*)\/[^\/]*\/(?<userid>[^\/]*)\/(?<session>[^\/]*)\/(?<broadcastid>[^\/]*)\/(?<doorid>[^\/]*)\/(?<userlevel>[^\/]*)\/[^\/]*\/(?<unspentcoins>[^\/]*)\/[^\/]*\/(?<push_origin>[^\/]*)\/[^\/]*\/[^\/]*\/(?<platform>[^\/]*)\/(?<sourceid>[^\/]*)\/(?<deviceid>[^\/]*)\/(?<push_type>[^\/]*)\/(?<channel_id>[^\/]*)\/(?<reserved128>[^\/]*)\/(?<reserved256>[^\/]*)\/(?<mobile_app_version>[^\/]*)\/(?<language>[^\/]*)\/(?<legacy_app_version>[^\/]*)\/trpxl.gif.*/
  path        /var/log/php-fpm/track_access_hlog
  pos_file    /var/log/php-fpm/push-event.pos
  time_format %d/%b/%Y:%H:%M:%S  # nginx default
  tag         push_events.ip
</source>
<match push_events.**>
  type forward
  phi_failure_detector false
  send_timeout 36000s
  expire_dns_cache 60s
  buffer_queue_limit  1800
  buffer_chunk_limit  20M
  buffer_type  file
  buffer_path  /var/log/td-agent/buffer_push_events/
  <server>
    host fluentd.ourdomainxxxx.com
  </server>
</match>

已尝试操作

  • 修改配置并重启td-agent
  • 执行命令 kill -USR1 $(cat /var/run/td-agent/td-agent.pid) 强制处理缓存

咨询问题

  1. 将历史缓存文件重命名为更高序号是否能让td-agent拾取发送?
  2. 该操作是否会引发后续问题?

问题解答

重命名缓存文件的有效性

Fluentd的文件缓冲系统依赖**缓冲目录下的元数据文件(如buffer.*.meta)**追踪缓冲块状态,而非单纯的文件名序号。元数据记录了缓冲块的待发送、已发送、失败等状态:

  • 如果历史缓存对应的元数据已被标记为"已处理"或"过期",仅重命名日志文件无效。
  • 若元数据完好且状态正确,可尝试以下步骤:
    1. 停止td-agent服务:systemctl stop td-agent
    2. 将历史缓存文件的序号修改为当前最新缓冲文件序号之后的数值(保持十六进制格式,比如当前最新是buffer.000000123.log,改为buffer.000000456.log)
    3. 同步重命名对应的.meta文件(如buffer.000000123.meta改为buffer.000000456.meta)
    4. 重启td-agent:systemctl start td-agent
      这种操作可能让Fluentd重新识别并发送这些缓冲块。

潜在风险与后续问题

  • 数据重复:若历史缓存已部分发送,重命名后可能导致重复日志流入聚合端,需提前确认下游系统能否处理重复数据。
  • 队列阻塞:大量历史缓存加入队列会占用buffer_queue_limit资源,可能导致新日志无法写入,需临时调大该参数,待数据发送完成后恢复原值。
  • 元数据损坏:操作失误(如漏改元数据、文件名格式错误)可能导致Fluentd无法识别缓冲文件,甚至服务启动失败,操作前务必备份整个缓冲目录。
  • 性能影响:发送大量历史数据会占用网络带宽和聚合端资源,建议在低峰时段操作,避免影响正常业务。

替代方案

若重命名无效,更可靠的方式是手动发送:

  1. 备份历史缓存文件
  2. 使用fluent-cat工具发送,根据缓存对应的tag替换参数:
    # 发送tracklive类缓存
    cat /var/log/td-agent/buffer/old_buffer_file.log | fluent-cat -t tracklive.ip -f none
    # 发送push_events类缓存
    cat /var/log/td-agent/buffer_push_events/old_buffer_file.log | fluent-cat -t push_events.ip -f none
    

内容的提问来源于stack exchange,提问作者user3248750

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 22:15:31