You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AKS节点上监控OMS Agent并配置停止告警方案咨询

解决AKS节点OMS Agent停止的Azure Monitor告警配置问题

核心思路

通过Azure Monitor的日志查询检测Agent进程状态或心跳缺失,进而配置告警。


1. 明确节点上的Agent进程名

  • Linux AKS节点:OMS Agent进程固定为omsagent
  • Windows AKS节点:对应进程是HealthService.exe

2. 日志查询语句

检测进程停止(适用于Linux)

利用Perf日志表筛选进程ID为0的情况(ID为0表示进程未运行):

Perf
| where ObjectName == "Process" and CounterName == "ID Process" and InstanceName == "omsagent"
| summarize arg_max(TimeGenerated, *) by Computer
| where CounterValue == 0
| project Computer, TimeGenerated, InstanceName, CounterValue

检测进程停止(适用于Windows)

Perf
| where ObjectName == "Process" and CounterName == "ID Process" and InstanceName == "HealthService"
| summarize arg_max(TimeGenerated, *) by Computer
| where CounterValue == 0
| project Computer, TimeGenerated, InstanceName, CounterValue

备选:检测Agent心跳缺失

如果Agent完全停止导致不再上报日志,用Heartbeat表检测节点长时间无心跳:

Heartbeat
| where Computer in (
    Perf
    | where ObjectName == "Process" and CounterName == "ID Process" and InstanceName == "omsagent"
    | distinct Computer
)
| summarize LastHeartbeat = max(TimeGenerated) by Computer
| where LastHeartbeat < ago(15m)  # 可根据需求调整时间阈值
| project Computer, LastHeartbeat

3. 配置告警步骤

  1. 打开Azure Monitor的「日志」页面,运行上述查询后点击右上角「新建告警规则」
  2. 信号逻辑配置:选择「自定义日志搜索」,粘贴查询语句,设置触发条件为「返回行数大于0」
  3. 操作组配置:添加需要的通知方式(邮件、短信、Azure函数等)
  4. 告警详情设置:填写规则名称、描述、严重级别,保存规则

注意事项

  • 必须确保AKS集群已启用Azure Monitor容器见解,否则Perf和Heartbeat日志无法被采集
  • 根据实际监控需求调整查询中的时间阈值(比如把ago(15m)改成ago(5m))
  • 若AKS节点基于虚拟机规模集部署,确认所有节点均被纳入监控范围

内容的提问来源于stack exchange,提问作者ramesh reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 08:40:42