Fluentular正则测试通过但Fluentd无法匹配Spring Boot异常日志
解决Fluentd Tail插件无法捕获Java异常栈完整内容的问题
核心原因
Fluentd tail插件默认逐行处理日志,异常栈的后续行(比如at xxx.xxx、Caused by:开头的行)不符合你定义的首行正则格式,因此被标记为pattern not matched。
解决方案1:配置Multiline解析器
启用Fluentd的multiline解析器,将连续的异常栈行合并到同一条日志的message字段中。
配置示例(Fluentd配置文件)
<source> @type tail path /path/to/your/spring-boot.log pos_file /var/log/td-agent/spring-boot.log.pos tag springboot.app <parse> @type multiline # 匹配Spring Boot日志首行的时间格式,根据实际日志调整 format_firstline /^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}\.\d{3}/ # 解析首行并捕获核心字段与初始message内容 format1 /^(?<time>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}\.\d{3}) (?<level>[A-Z]+) (?<pid>\d+) --- \[(?<thread>[^\]]+)\] (?<logger>[^\s]+) : (?<message>[\s\S]*)/ # 匹配异常栈后续行特征,追加到message字段 format2 /^(\s+at|Caused by:|^\s+\.\.\.) (?<message_continue>[\s\S]*)/ # 确保超长异常栈被完整合并,不截断 merge_overflow_log true </parse> </source>
关键配置说明
format_firstline:指定日志首行的匹配规则,需和你的Spring Boot日志首行格式完全匹配。format1:解析首行结构,捕获时间、日志级别、进程ID等核心字段,同时提取初始的message内容。format2:匹配异常栈后续行的典型特征——以空格+at、Caused by:或...开头的行,将这些内容追加到message字段。merge_overflow_log:开启后,即使异常栈行数过多,也不会截断内容,保证日志完整性。
解决方案2:使用detect_exceptions过滤器
如果不想修改tail插件的解析规则,可在tail插件之后添加detect_exceptions过滤器,自动识别并合并Java异常栈:
<source> @type tail path /path/to/your/spring-boot.log pos_file /var/log/td-agent/spring-boot.log.pos tag springboot.app <parse> @type regexp expression /^(?<time>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}\.\d{3}) (?<level>[A-Z]+) (?<pid>\d+) --- \[(?<thread>[^\]]+)\] (?<logger>[^\s]+) : (?<message>.*)/ </parse> </source> <filter springboot.app> @type detect_exceptions languages java message_key message # 设置合并超时,避免异常栈拆分 multiline_flush_interval 1s </filter>
该过滤器内置Java异常栈识别规则,会自动将后续异常行合并到message字段,配置更简洁。
内容的提问来源于stack exchange,提问作者Huy Hà Quang
相关产品推荐
相关产品推荐

