You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fluentd集成EKS时运行数秒的短周期Job日志无法上报CloudWatch故障

问题根因

Fluentd的tail输入插件默认参数对生命周期极短的K8s Job日志适配性不足,这类Job的日志文件在生成后很快会被kubelet清理,Fluentd刚识别到文件就收到文件删除的inotify事件,误判为日志轮转,触发默认5秒的等待逻辑,等待结束后文件已被清理,因此无法读取到日志内容。

解决方案

  • 调整tail插件核心参数,将你的source配置修改为如下内容:
<source>
    @type tail
    @label @container
    path /var/log/containers/*.log
    exclude_path ["/var/log/containers/cloudwatch-agent*", "/var/log/containers/fluentd*"]
    pos_file /var/log/fluentd-containers.log.pos
    tag container.*
    read_from_head true
    follow_inodes true
    # 新增/调整适配短生命周期Job的参数
    enable_stat_watcher false # 关闭inotify事件监听,改用主动轮询避免快速消失的文件被漏读
    stat_interval 1 # 每1秒轮询一次日志目录,快速识别新生成的短生命周期日志文件
    rotate_wait 1 # 轮转等待时间从默认5秒改为1秒,避免等待期间文件被清理
    read_lines_limit 2000 # 提升单次读取最大行数,小文件可一次性读完所有内容
    pos_file_compaction_interval 1h # 每小时清理一次pos文件中已不存在的日志文件的偏移记录,避免同文件名的新Job日志被跳过
    <parse>
        @type multi_format
        <pattern>
            format cri
            time_format %Y-%m-%dT%H:%M:%S.%NZ
        </pattern>
        <pattern>
            format json
            time_format %Y-%m-%dT%H:%M:%S.%NZ
        </pattern>
    </parse>
</source>
  • 若使用Fluentd 1.14及以上版本,可额外添加ignore_old_files false参数,避免刚生成的小文件因为创建时间判定被误判为旧文件跳过。
  • 确认Fluentd运行账号对/var/log/containers/目录和pos文件路径有完整读写权限,避免因为权限问题无法读取刚生成的日志文件。

配置修改完成后重启Fluentd即可生效,短生命周期Job的日志会被正常读取转发。

内容的提问来源于stack exchange,提问作者Heron Rossi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 10:15:06