使用Fluentd采集Nginx日志推送到Prometheus时匹配失败求助
Nginx访问日志Fluentd正则解析不匹配问题解决
问题现象
在Kubernetes环境中,Nginx Deployment以Sidecar方式运行Fluentd容器,Nginx已配置自定义Prometheus格式的访问日志,但Fluentd日志持续出现「pattern not matched」警告,无法正确解析日志内容。警告日志示例:
[warn]: #0 pattern not matched: "10.121.1.4 - - [08/Feb/2023:22:23:30 +0000] "GET / HTTP/1.1" 304 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" -"
现有配置
Nginx配置
data: nginx.conf: | events { worker_connections 1024; } http { log_format prometheus '$remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $upstream_response_time'; server { access_log /var/log/nginx/access.log prometheus; listen 80; server_name localhost; location / { root /usr/share/nginx/html; index index.html; } } }
原Fluentd配置
data: fluent.conf: | <source> @type prometheus_tail_monitor </source> <source> @type tail <parse> @type regexp expression /^(?<timestamp>.+) (?<stream>stdout|stderr)( (.))? (?<remote>[^ ]*) (?<host>[^ ]*) (?<user>[^ ]*) \[(?<time>[^\]]*)\] \"(?<method>\w+)(?:\s+(?<path>[^\"]*?)(?:\s+\S*)?)?\" (?<status_code>[^ ]*) (?<size>[^ ]*)(?:\s"(?<referer>[^\"]*)") "(?<agent>[^\"]*)" (?<urt>[^ ]*)$/ time_format %d/%b/%Y:%H:%M:%S %z keep_time_key true types size:integer,reqtime:float,uct:float,uht:float,urt:float </parse> tag nginx path /var/log/nginx/access.log pos_file /tmp/fluent_nginx.pos </source> <filter nginx> @type prometheus </filter>
问题分析
- 正则前缀冗余:原正则开头包含容器stdout日志的前缀字段,但Fluentd直接读取Nginx本地
access.log,日志无该前缀,导致匹配失败。 - 字段结构不匹配:Nginx日志格式为
$remote_addr - $remote_user [...],原正则额外定义了host字段,与实际结构不符。 - 请求字段解析逻辑错误:原正则拆分
method和path,但Nginx日志中$request是完整请求行,拆分逻辑不匹配实际内容。 - 冗余类型定义:
types字段包含当前日志不存在的reqtime、uct、uht字段,无实际作用。
修正后的Fluentd配置
data: fluent.conf: | <source> @type prometheus_tail_monitor </source> <source> @type tail <parse> @type regexp expression /^(?<remote>[^ ]*) - (?<user>[^ ]*) \[(?<time>[^\]]*)\] \"(?<request>[^\"]*)\" (?<status_code>[^ ]*) (?<size>[^ ]*) \"(?<referer>[^\"]*)\" \"(?<agent>[^\"]*)\" (?<urt>[^ ]*)$/ time_format %d/%b/%Y:%H:%M:%S %z keep_time_key true types size:integer,urt:float </parse> tag nginx path /var/log/nginx/access.log pos_file /tmp/fluent_nginx.pos </source> <filter nginx> @type prometheus </filter>
修正说明
- 移除正则开头的容器日志前缀字段,直接匹配Nginx日志起始结构。
- 删除冗余的
host字段定义,匹配Nginx日志$remote_addr - $remote_user的格式。 - 将请求内容统一匹配为
request字段,避免拆分逻辑导致的不匹配(若需拆分method和path,可后续通过filter处理)。 - 清理
types字段,仅保留日志中实际存在的size和urt(upstream_response_time)字段的类型定义。
内容的提问来源于stack exchange,提问作者Rohith
相关产品推荐
相关产品推荐

