You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Windows Server 2016实例Event Viewer日志无法同步Cloud Logging咨询

配置调整及排查步骤

1. 补充OpsAgent日志采集规则

官方默认的config.yaml仅采集OpsAgent自身运行日志,未默认开启Windows事件日志、IIS日志的采集规则,需要手动修改配置文件:

logging:
  receivers:
    # 采集Windows Event Viewer日志
    windows_events:
      type: windows_event_log
      channels:
      - name: System
      - name: Application
      - name: Security
      # 采集IIS写入事件查看器的日志
      - name: Microsoft-Windows-IIS-Logging/Logs
        disabled: false
    # 采集IIS本地访问日志文件(若需要)
    iis_access_log:
      type: files
      include_paths:
      # 替换为你实际IIS站点的日志存储路径
      - C:\inetpub\logs\LogFiles\W3SVC1\u_ex*.log
      record_log_file_path: true
  service:
    pipelines:
      default_pipeline:
        receivers:
        - windows_events
        - iis_access_log

修改完成后执行PowerShell命令重启OpsAgent服务:
Restart-Service google-cloud-ops-agent

2. 验证实例访问权限配置

除了IAM服务账号权限外,需要确认GCE实例的访问范围配置未限制Logging写入:

  • 进入GCE实例详情页,找到访问范围板块
  • 确认Cloud Logging的访问权限为写入,或直接选择允许完全访问所有Cloud API
  • 若修改了访问范围,需要重启实例生效

3. 排查OpsAgent运行异常

  • 执行命令Get-Service google-cloud-ops-agent确认服务状态为Running,若启动失败优先检查配置文件YAML格式是否合法
  • 查看Agent运行日志排查报错,日志路径为C:\ProgramData\Google\Cloud Operations\Ops Agent\log\logging-module.log,重点排查权限不足、日志路径不存在类报错

4. 验证Cloud Logging查询规则

进入Cloud Logging日志浏览器,使用以下查询条件过滤日志:

  • 资源类型选择gce_instance,并选中对应Windows实例ID
  • 日志名称筛选windows_event_log(对应事件查看器日志)或iis_access_log(对应IIS本地文件日志)
  • 确认查询时间范围覆盖IIS重启后的时间点

内容的提问来源于stack exchange,提问作者DagaReiN

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 05:57:05