You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ops Agent仅采集指标不采集日志问题排查求助

问题排查:Ops Agent 仅采集指标无法采集指定日志

已配置Ops Agent采集/var/log/audit/audit.log但日志未上报,仅指标采集正常,服务状态无报错,版本为google-cloud-ops-agent 2.29.0 1.el7 x86_64,可从以下几点排查:


1. 修正配置文件结构

Ops Agent的日志配置必须嵌套在顶层logging节点下,原配置缺少该节点会导致日志模块忽略配置。正确配置格式如下:

logging:
  receivers:
    mylog:
      type: files
      include_paths:
      - /var/log/audit/audit.log
  service:
    pipelines:
      my_pipeline:
        receivers: [mylog]

修改后重启Agent:

sudo systemctl restart google-cloud-ops-agent

2. 验证文件读取权限

/var/log/audit/audit.log默认权限严格,Ops Agent日志进程以google-cloud-ops-agent-user用户运行,需确保该用户有读取权限:

  1. 查看文件权限和用户组:
    ls -l /var/log/audit/audit.log
    grep audit /etc/group
    
  2. 将Agent用户添加到audit组(如果文件属于audit组):
    sudo usermod -aG audit google-cloud-ops-agent-user
    sudo systemctl restart google-cloud-ops-agent
    

3. 确认配置已正确加载

执行诊断命令查看当前生效的日志配置,确认mylog接收器是否被加载:

sudo google-cloud-ops-agent diagnostics

重点查看输出中logging.receivers和logging.service.pipelines部分的内容。

4. 检查日志生成与采集范围

Ops Agent仅采集配置生效后的新日志,不会回溯历史内容。可触发审计日志生成(比如执行sudo ls),等待5-10分钟后再去Cloud Logging查询。

5. 核对Cloud Logging查询条件

在GCP控制台的Cloud Logging中,使用正确的过滤器定位日志,示例过滤器:

resource.type="gce_instance"
logName="projects/你的项目ID/logs/mylog"

替换你的项目ID为实际项目ID,确保未设置错误的过滤规则导致日志未显示。


内容的提问来源于stack exchange,提问作者ubsk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 03:22:49