You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Elastic Beanstalk的IIS日志传输至CloudWatch?

正确将Elastic Beanstalk EC2实例的IIS日志传输到CloudWatch的方案

1. 通过.ebextensions配置文件实现日志采集

Elastic Beanstalk会统一管理EC2实例的生命周期,直接在实例上修改CloudWatch Agent配置会被EB的环境更新覆盖,必须通过应用根目录下的.ebextensions文件夹配置规则,让EB在实例初始化时自动完成日志采集配置。

2. 编写CloudWatch日志配置文件

在应用根目录创建.ebextensions文件夹,新建cloudwatch-iis-logs.config文件,内容如下(根据实际环境调整参数):

files:
  "C:\\Program Files\\Amazon\\AmazonCloudWatchAgent\\config.json":
    content: |
      {
        "logs": {
          "logs_collected": {
            "files": {
              "collect_list": [
                {
                  "file_path": "C:\\inetpub\\logs\\LogFiles\\W3SVC1\\*.log",
                  "log_group_name": "/aws/elasticbeanstalk/你的EB环境名称/IISLogs",
                  "log_stream_name": "{instance_id}",
                  "timestamp_format": "yyyy-MM-dd HH:mm:ss"
                }
              ]
            }
          }
        }
      }
container_commands:
  01_restart_cloudwatch_agent:
    command: "net stop AmazonCloudWatchAgent && net start AmazonCloudWatchAgent"
    ignoreErrors: true
  • 替换你的EB环境名称为实际的Elastic Beanstalk环境名
  • 若IIS日志存储路径非默认C:\inetpub\logs\LogFiles\W3SVC1\,需同步修改file_path
  • timestamp_format需匹配IIS日志的时间格式,默认IIS日志时间格式为yyyy-MM-dd HH:mm:ss

3. 配置实例IAM权限

确保Elastic Beanstalk的EC2实例角色(默认是aws-elasticbeanstalk-ec2-role)拥有CloudWatch日志操作权限,可附加CloudWatchLogsFullAccess策略,或使用自定义精细权限:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "logs:CreateLogGroup",
        "logs:CreateLogStream",
        "logs:PutLogEvents",
        "logs:DescribeLogStreams"
      ],
      "Resource": "arn:aws:logs:*:*:*"
    }
  ]
}

4. 部署应用到Elastic Beanstalk

将包含.ebextensions文件夹的应用代码打包(如zip格式),部署到目标EB环境。EB会在实例启动时自动安装、配置CloudWatch Agent,并按照规则将IIS日志上传到指定的CloudWatch日志组。

排查要点

  • 验证IIS日志路径:登录EC2实例确认日志实际存储位置与配置文件一致
  • 查看Agent运行日志:路径为C:\Program Files\Amazon\AmazonCloudWatchAgent\Logs\amazon-cloudwatch-agent.log,可定位采集失败原因
  • 检查IAM权限:确认实例角色已配置CloudWatch日志相关权限,避免因权限不足导致日志无法上传

内容的提问来源于stack exchange,提问作者krish0033

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 13:27:28