You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置OpenTelemetry filterprocessor过滤发送至Coralogix的日志

配置OpenTelemetry filterprocessor过滤发送至Coralogix的日志

嘿,我来帮你搞定这个filterprocessor的配置问题!看起来你已经在minikube里搭好了日志生成环境,并且集成了OpenTelemetry到Coralogix,现在就差用filterprocessor筛选日志这一步了。

首先,filterprocessor的核心逻辑就是通过字段匹配规则来决定哪些日志保留、哪些丢弃,你只需要在OpenTelemetry Collector的配置里添加这个处理器,然后把它加入日志处理流水线就行。

先结合你给出的日志示例(带level、error、msg等字段的JSON日志),给你几个常见场景的配置参考:

场景1:只发送Error级别的日志到Coralogix

如果你只想把level为error的日志传给Coralogix,可以这么配置:

processors:
  filter:
    logs:
      include:
        # 匹配方式:strict是完全匹配,regexp是正则匹配
        match_type: strict
        # 注意:如果你的日志字段已经被解析成了Collector的attributes(比如用了json_parser处理器),就用attributes;如果还在body里,就用body
        body:
          - key: level
            value: "error"

场景2:排除包含特定错误信息的日志

要是你想丢弃那些error字段是expected header is undefined的日志,配置可以改成这样:

processors:
  filter:
    logs:
      exclude:
        match_type: strict
        body:
          - key: error
            value: "expected header is undefined"

场景3:匹配包含特定关键词的日志内容

如果想保留msg里包含Set Am的日志,可以用正则匹配:

processors:
  filter:
    logs:
      include:
        match_type: regexp
        body:
          - key: msg
            value: ".*Set Am.*"

最后一步:把filterprocessor加入日志流水线

配置好处理器后,一定要把它加到Collector的日志处理流水线里,放在接收器(比如filelog)之后,Coralogix exporter之前,比如:

service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [filter, batch]  # 这里加上filter
      exporters: [coralogix]

另外提醒一句:如果你的日志还没被解析成结构化字段,记得先加个json_parser处理器把JSON日志解析成可匹配的字段,不然filterprocessor找不到对应的key哦。修改完Collector的配置(一般是通过ConfigMap管理)后,记得重启minikube里的OpenTelemetry Collector Pod,让新配置生效~

备注:内容来源于stack exchange,提问作者Anatoly

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 11:33:19