FluentD无法解析CRI-O容器日志,如何调整配置完成采集?
解决方案
核心原因
你当前遇到的pattern not match报错,是因为cri-o输出的容器日志为CRI标准纯文本格式,而非Docker默认的每行JSON结构,原有配置使用json解析器无法匹配纯文本日志行。
推荐方案1:使用内置CRI解析器(优先选择)
Fluentd 1.10及以上版本内置了专门适配CRI标准日志(cri-o/containerd通用)的解析器,无需手写正则,兼容性更高,仅需修改source段的parse配置即可:
<source> @type tail @id tail_container_logs path /var/log/containers/*.log pos_file /var/fluent/log/containers.log.pos tag kubernetes.* exclude_path "/var/log/containers/my-fluent*.log" read_from_head true <parse> @type cri </parse> </source>
该解析器会自动拆分出以下字段:
time:日志产生时间,自动匹配CRI格式的时间戳stream:日志输出流,值为stdout/stderrlogtag:CRI日志标识,F代表完整日志行,P代表分片日志行(处理多行日志时使用)message:原始日志内容
方案2:手写正则解析器
如果你的Fluentd版本较低无法使用内置CRI解析器,可以手动写正则匹配CRI日志格式,配置如下:
<source> @type tail @id tail_container_logs path /var/log/containers/*.log pos_file /var/fluent/log/containers.log.pos tag kubernetes.* exclude_path "/var/log/containers/my-fluent*.log" read_from_head true <parse> @type regexp expression /^(?<time>[^ ]+) (?<stream>stdout|stderr) (?<logtag>[^ ]*) (?<message>.*)$/ time_format %Y-%m-%dT%H:%M:%S.%NZ </parse> </source>
扩展配置:兼容多运行时日志
如果集群同时存在Docker(JSON格式日志)和cri-o运行时,可以使用multi_format解析器自动适配两种格式:
<parse> @type multi_format <pattern> format json time_key time time_format %Y-%m-%dT%H:%M:%S.%NZ </pattern> <pattern> format cri </pattern> </parse>
扩展配置:处理多行日志
如果业务有Java堆栈、异常栈这类多行日志,可以新增concat filter合并分片日志:
<filter kubernetes.**> @type concat key message # 匹配日志行开头的CRI时间戳作为新日志的起始标识 multiline_start_regexp /^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+Z/ stream_identity_key stream flush_interval 5 </filter>
内容的提问来源于stack exchange,提问作者Jason Nanay
相关产品推荐
相关产品推荐

