GCP Windows Server 2016实例Event Viewer日志无法同步Cloud Logging咨询
配置调整及排查步骤
1. 补充OpsAgent日志采集规则
官方默认的config.yaml仅采集OpsAgent自身运行日志,未默认开启Windows事件日志、IIS日志的采集规则,需要手动修改配置文件:
logging: receivers: # 采集Windows Event Viewer日志 windows_events: type: windows_event_log channels: - name: System - name: Application - name: Security # 采集IIS写入事件查看器的日志 - name: Microsoft-Windows-IIS-Logging/Logs disabled: false # 采集IIS本地访问日志文件(若需要) iis_access_log: type: files include_paths: # 替换为你实际IIS站点的日志存储路径 - C:\inetpub\logs\LogFiles\W3SVC1\u_ex*.log record_log_file_path: true service: pipelines: default_pipeline: receivers: - windows_events - iis_access_log
修改完成后执行PowerShell命令重启OpsAgent服务:Restart-Service google-cloud-ops-agent
2. 验证实例访问权限配置
除了IAM服务账号权限外,需要确认GCE实例的访问范围配置未限制Logging写入:
- 进入GCE实例详情页,找到访问范围板块
- 确认Cloud Logging的访问权限为
写入,或直接选择允许完全访问所有Cloud API - 若修改了访问范围,需要重启实例生效
3. 排查OpsAgent运行异常
- 执行命令
Get-Service google-cloud-ops-agent确认服务状态为Running,若启动失败优先检查配置文件YAML格式是否合法 - 查看Agent运行日志排查报错,日志路径为
C:\ProgramData\Google\Cloud Operations\Ops Agent\log\logging-module.log,重点排查权限不足、日志路径不存在类报错
4. 验证Cloud Logging查询规则
进入Cloud Logging日志浏览器,使用以下查询条件过滤日志:
- 资源类型选择
gce_instance,并选中对应Windows实例ID - 日志名称筛选
windows_event_log(对应事件查看器日志)或iis_access_log(对应IIS本地文件日志) - 确认查询时间范围覆盖IIS重启后的时间点
内容的提问来源于stack exchange,提问作者DagaReiN
相关产品推荐
相关产品推荐

