You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Fluentd将GKE特定JSON日志路由至Pub/Sub时过滤失效问题

问题解决:Fluentd过滤规则不生效的修复方案

你的过滤规则不生效的核心原因是日志未被解析为JSON结构,导致grep过滤器无法直接访问key字段。当前配置中<parse>部分用了@type none,日志会被当作纯字符串存在message字段里,而非结构化的JSON数据。

修复步骤:

  1. 修改日志解析配置:将source中的<parse>类型改为json,让Fluentd自动解析日志为JSON结构,这样才能直接访问key字段。
  2. 调整日志路径:针对两个服务的容器日志,修改path字段匹配对应日志文件,用逗号分隔多个路径即可。

修改后的完整配置:

<source>
  @type tail
  path /var/log/containers/service1-*.log,/var/log/containers/service2-*.log
  pos_file /var/log/fluentd-containers.log.pos
  tag test.log
  read_from_head true
  <parse>
    @type json
  </parse>
</source>

<filter test.log>
  @type grep
  <regexp>
    key key
    pattern /^abc$/
  </regexp>
</filter>

<match test.log>
  @type gcloud_pubsub
  project_id gcp-project-id
  topic gcp-topic
  flush_interval 10s
  num_threads 1
</match>

额外说明:

  • 过滤规则里的pattern /^abc$/是精确匹配key字段值为abc,如果需要模糊匹配可保留原来的/abc/。
  • 确保path字段正确匹配两个服务的容器日志文件路径,GKE容器日志文件名通常格式为[pod-name]_[namespace]_[container-name]-[hash].log,可根据实际情况调整通配符。

内容的提问来源于stack exchange,提问作者Abhinav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 18:15:11