You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何直接将ECS Fargate容器日志推送至S3并通过Athena查询?

解决方案:用Firelens将ECS Fargate日志直接推送至S3并通过Athena查询

一、关于Firelens是否为最佳方案

Firelens(基于Fluent Bit/Fluentd)是这个场景下的最优选择之一:它是AWS ECS原生集成的日志路由工具,能直接将容器日志投递到S3,省去先推CloudWatch再中转的链路,降低成本;同时支持日志预处理(过滤、格式化、字段提取),完全适配你的需求。相比其他方案(比如CloudWatch订阅过滤器转S3),它的链路更短、灵活性更强。

二、具体实施步骤

1. 配置IAM权限

为ECS任务执行角色添加S3写入权限,同时确保角色能拉取AWS托管的Firelens镜像:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:PutObject"
            ],
            "Resource": "arn:aws:s3:::你的S3桶名/*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ecr:GetDownloadUrlForLayer",
                "ecr:BatchGetImage",
                "ecr:BatchCheckLayerAvailability"
            ],
            "Resource": "arn:aws:ecr:::aws/aws-for-fluent-bit:*"
        }
    ]
}

2. 修改ECS任务定义,启用Firelens

在任务定义的容器配置中,替换原有的awslogs驱动为awsfirelens,并配置S3输出参数:

"logConfiguration": {
    "logDriver": "awsfirelens",
    "options": {
        "Name": "s3",
        "region": "你的AWS区域",
        "bucket": "你的S3桶名",
        "prefix": "ecs-logs/year=%Y/month=%m/day=%d/",
        "log_key": "log_content",
        "time_key": "log_time",
        "time_format": "%Y-%m-%dT%H:%M:%S%z",
        "utc": "true"
    }
}
  • prefix用时间分区命名,后续Athena查询时可通过分区裁剪提升性能
  • log_key指定日志内容的字段名,time_key定义日志时间戳字段

3. 可选:日志预处理配置

如果需要过滤特定日志、提取字段,可通过自定义Fluent Bit配置实现。在任务定义中添加firelensConfiguration指向S3中的配置文件:

"firelensConfiguration": {
    "type": "fluentbit",
    "options": {
        "config-file-type": "s3",
        "config-file-value": "s3://你的S3桶名/fluentbit-config/fluent-bit.conf"
    }
}

示例fluent-bit.conf(过滤INFO级别日志):

[INPUT]
    Name                forward
    Port                24224

[FILTER]
    Name                grep
    Match               *
    Exclude             log_level INFO

[OUTPUT]
    Name                s3
    Match               *
    Region              你的AWS区域
    Bucket              你的S3桶名
    Prefix              ecs-logs/year=%Y/month=%m/day=%d/
    Log_Key             log_content
    Time_Key            log_time
    Time_Format         %Y-%m-%dT%H:%M:%S%z
    UTC                 On

4. 验证日志投递

更新ECS任务后,查看S3桶中是否生成对应路径的日志文件,确认内容格式符合预期。

5. 配置Athena查询

5.1 创建外部表

在Athena控制台执行SQL,创建映射S3日志的外部表(假设日志为JSON格式):

CREATE EXTERNAL TABLE IF NOT EXISTS ecs_fargate_logs (
    log_content string,
    log_time timestamp,
    container_name string,
    source string
)
PARTITIONED BY (year string, month string, day string)
ROW FORMAT SERDE 'org.openx.data.jsonserde.JsonSerDe'
LOCATION 's3://你的S3桶名/ecs-logs/'
TBLPROPERTIES (
    'projection.enabled'='true',
    'projection.year.type'='integer',
    'projection.year.range'='2024,2030',
    'projection.month.type'='integer',
    'projection.month.range'='1,12',
    'projection.month.digits'='2',
    'projection.day.type'='integer',
    'projection.day.range'='1,31',
    'projection.day.digits'='2',
    'storage.location.template'='s3://你的S3桶名/ecs-logs/year=${year}/month=${month}/day=${day}'
);
  • 开启投影分区后,Athena会自动识别路径中的时间分区,无需手动添加

5.2 执行查询

示例查询某天的错误日志:

SELECT *
FROM ecs_fargate_logs
WHERE year = '2024' AND month = '05' AND day = '20'
AND log_content LIKE '%ERROR%';

内容的提问来源于stack exchange,提问作者sam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 08:50:30