You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Fluentd采集Nginx日志推送到Prometheus时匹配失败求助

Nginx访问日志Fluentd正则解析不匹配问题解决

问题现象

在Kubernetes环境中,Nginx Deployment以Sidecar方式运行Fluentd容器,Nginx已配置自定义Prometheus格式的访问日志,但Fluentd日志持续出现「pattern not matched」警告,无法正确解析日志内容。警告日志示例:

[warn]: #0 pattern not matched: "10.121.1.4 - - [08/Feb/2023:22:23:30 +0000] "GET / HTTP/1.1" 304 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" -"

现有配置

Nginx配置

data:
  nginx.conf: |
    events {
      worker_connections  1024;
    }
    http {
        log_format prometheus '$remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $upstream_response_time';
        server {
            access_log /var/log/nginx/access.log prometheus;
            listen 80;
            server_name localhost;
            location / {
                root /usr/share/nginx/html;
                index index.html;
            }
        }
    }

原Fluentd配置

data:
  fluent.conf: |
    <source>
        @type prometheus_tail_monitor
    </source>
    <source>
        @type tail
        <parse>
        @type regexp
        expression /^(?<timestamp>.+) (?<stream>stdout|stderr)( (.))? (?<remote>[^ ]*) (?<host>[^ ]*) (?<user>[^ ]*) \[(?<time>[^\]]*)\] \&quot;(?<method>\w+)(?:\s+(?<path>[^\&quot;]*?)(?:\s+\S*)?)?\&quot; (?<status_code>[^ ]*) (?<size>[^ ]*)(?:\s&quot;(?<referer>[^\&quot;]*)&quot;) &quot;(?<agent>[^\&quot;]*)&quot; (?<urt>[^ ]*)$/
            time_format %d/%b/%Y:%H:%M:%S %z
            keep_time_key true
            types size:integer,reqtime:float,uct:float,uht:float,urt:float
        </parse>
        tag nginx
        path /var/log/nginx/access.log
        pos_file /tmp/fluent_nginx.pos
    </source>
    <filter nginx>
        @type prometheus
    </filter>

问题分析

  1. 正则前缀冗余:原正则开头包含容器stdout日志的前缀字段,但Fluentd直接读取Nginx本地access.log,日志无该前缀,导致匹配失败。
  2. 字段结构不匹配:Nginx日志格式为$remote_addr - $remote_user [...],原正则额外定义了host字段,与实际结构不符。
  3. 请求字段解析逻辑错误:原正则拆分method和path,但Nginx日志中$request是完整请求行,拆分逻辑不匹配实际内容。
  4. 冗余类型定义:types字段包含当前日志不存在的reqtime、uct、uht字段,无实际作用。

修正后的Fluentd配置

data:
  fluent.conf: |
    <source>
        @type prometheus_tail_monitor
    </source>
    <source>
        @type tail
        <parse>
        @type regexp
        expression /^(?<remote>[^ ]*) - (?<user>[^ ]*) \[(?<time>[^\]]*)\] \"(?<request>[^\"]*)\" (?<status_code>[^ ]*) (?<size>[^ ]*) \"(?<referer>[^\"]*)\" \"(?<agent>[^\"]*)\" (?<urt>[^ ]*)$/
            time_format %d/%b/%Y:%H:%M:%S %z
            keep_time_key true
            types size:integer,urt:float
        </parse>
        tag nginx
        path /var/log/nginx/access.log
        pos_file /tmp/fluent_nginx.pos
    </source>
    <filter nginx>
        @type prometheus
    </filter>

修正说明

  • 移除正则开头的容器日志前缀字段,直接匹配Nginx日志起始结构。
  • 删除冗余的host字段定义,匹配Nginx日志$remote_addr - $remote_user的格式。
  • 将请求内容统一匹配为request字段,避免拆分逻辑导致的不匹配(若需拆分method和path,可后续通过filter处理)。
  • 清理types字段,仅保留日志中实际存在的size和urt(upstream_response_time)字段的类型定义。

内容的提问来源于stack exchange,提问作者Rohith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 07:25:39