使用Fluent Bit解析Tomcat多行异常日志遇实时采集问题
Tomcat日志多行异常合并问题:静态读取正常,实时Tail失效
使用Fluent Bit解析Tomcat日志,目标是将多行异常合并为单条日志条目。开启read_from_head true读取静态文件时解析正常,能成功合并异常;但实时tail日志文件时,Fluent Bit仅返回log字段,解析后的字段全部丢失,推测是流式写入导致正则规则失效。
日志样例
09-Aug-2022 06:36:45.901 INFO [main] org.apache.catalina.startup.Catalina.start Server startup in 18109 ms 09-Aug-2022 06:43:04.787 SEVERE [http-nio-8080-exec-2] com.sun.jersey.spi.container.ContainerResponse.mapMappableContainerException The exception contained within MappableContainerException could not be mapped to a response, re-throwing to the HTTP container java.io.EOFException: No content to map to Object due to end of input at org.codehaus.jackson.map.ObjectMapper._initForReading(ObjectMapper.java:2766) ... 09-Aug-2022 06:43:07.060 SEVERE [http-nio-8080-exec-3] com.sun.jersey.spi.container.ContainerResponse.mapMappableContainerException The exception contained within MappableContainerException could not be mapped to a response, re-throwing to the HTTP container
Fluent Bit配置
[SERVICE] flush 5 daemon Off log_level debug parsers_file parsers.conf [INPUT] name tail tag tomcat path /opt/tomcat/catalina.out multiline on parser_firstline java_multiline mem_buf_limit 5MB skip_long_lines on #read_from_head true refresh_interval 10 [FILTER] Name record_modifier Match * Record hostname ${HOSTNAME} [OUTPUT] name http match * host somelocation
解析器配置(parsers.conf)
[PARSER] Name java_multiline Format regex Regex (?<timestamp>([012][0-9])-(Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec)-\d\d\d\d [012]\d:[0-6]\d:[0-6]\d\.\d\d\d)\s(?<severity>[^\s]+)\s\[(?<thread>[^\]]+)\]\s(?<msg>[^*]+)
尝试过的多行解析器
[MULTILINE_PARSER] name multiline-regex-test type regex flush_timeout 1000 rule "start_state" "/([012][0-9])-(Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec)-\d\d\d\d [012]\d:[0-6]\d:[0-6]\d\.\d\d\d/" "cont" rule "cont" "/[^\t].+/" "cont"
问题原因与解决办法
1. 多行解析器参数误用
当前配置用parser_firstline指向普通正则解析器,这是旧版多行模式的用法,在实时流式场景下无法正确触发多行合并。Fluent Bit开启multiline on后,必须用multiline_parser参数指定专门的多行解析器。
2. 多行解析规则错误
尝试的多行解析器第二条规则/[^\t].+/完全不符合异常行特征——异常行是以空白字符(空格/制表符)开头的,这条规则反而会排除异常行,导致合并失败。
3. 字段解析正则缺陷
原正则中(?<msg>[^*]+)限制了消息只能匹配不含*的内容,且无法覆盖合并后的多行异常内容,需要调整为匹配所有字符(包括换行)的规则。
修正后的完整配置
第一步:更新parsers.conf的多行解析器
[MULTILINE_PARSER] name tomcat_multiline type regex flush_timeout 1000 # 匹配日志起始行(日期开头) rule "start_state" "/^([012][0-9])-(Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec)-\d{4} [012]\d:[0-5]\d:[0-5]\d\.\d{3}/" "cont" # 匹配异常行(以空白字符开头) rule "cont" "/^\s+/" "cont"
第二步:更新Fluent Bit的INPUT配置
替换参数,区分多行合并和字段解析的职责:
[INPUT] name tail tag tomcat path /opt/tomcat/catalina.out multiline on multiline_parser tomcat_multiline # 负责多行合并 parser java_multiline # 负责合并后解析字段 mem_buf_limit 5MB skip_long_lines on #read_from_head true refresh_interval 10
第三步:修正字段解析正则
[PARSER] Name java_multiline Format regex Regex (?<timestamp>([012][0-9])-(Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec)-\d{4} [012]\d:[0-5]\d:[0-5]\d\.\d{3})\s(?<severity>[^\s]+)\s\[(?<thread>[^\]]+)\]\s(?<msg>[\s\S]+)
实时场景额外注意事项
flush_timeout设为1000ms,确保异常行写完后能及时合并输出,避免延迟过高- 确认Fluent Bit对目标日志文件有读取权限
refresh_interval保持10秒即可,无需调整
内容的提问来源于stack exchange,提问作者Kevin
相关产品推荐
相关产品推荐

