使用Fluentd将GKE特定JSON日志路由至Pub/Sub时过滤失效问题
问题解决:Fluentd过滤规则不生效的修复方案
你的过滤规则不生效的核心原因是日志未被解析为JSON结构,导致grep过滤器无法直接访问key字段。当前配置中<parse>部分用了@type none,日志会被当作纯字符串存在message字段里,而非结构化的JSON数据。
修复步骤:
- 修改日志解析配置:将source中的
<parse>类型改为json,让Fluentd自动解析日志为JSON结构,这样才能直接访问key字段。 - 调整日志路径:针对两个服务的容器日志,修改
path字段匹配对应日志文件,用逗号分隔多个路径即可。
修改后的完整配置:
<source> @type tail path /var/log/containers/service1-*.log,/var/log/containers/service2-*.log pos_file /var/log/fluentd-containers.log.pos tag test.log read_from_head true <parse> @type json </parse> </source> <filter test.log> @type grep <regexp> key key pattern /^abc$/ </regexp> </filter> <match test.log> @type gcloud_pubsub project_id gcp-project-id topic gcp-topic flush_interval 10s num_threads 1 </match>
额外说明:
- 过滤规则里的
pattern /^abc$/是精确匹配key字段值为abc,如果需要模糊匹配可保留原来的/abc/。 - 确保
path字段正确匹配两个服务的容器日志文件路径,GKE容器日志文件名通常格式为[pod-name]_[namespace]_[container-name]-[hash].log,可根据实际情况调整通配符。
内容的提问来源于stack exchange,提问作者Abhinav
相关产品推荐
相关产品推荐

