You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fluent Bit CRI多行日志解析配置失效,如何正确提取合并日志?

问题描述

在Kubernetes中部署Fluent Bit,计划将日志转发至Loki与Grafana。本地测试时需要先通过CRI解析器处理CRI格式日志,提取核心日志内容后再合并多行日志。配置了自定义多行解析器后,发现CRI解析器未生效,日志仍保留CRI前缀(时间戳、stdout标识等);若直接将multiline.parser设为cri,虽能正常解析CRI日志,但无法实现多行合并。

当前配置文件

fluent-bit.conf

[SERVICE]
    flush        1
    log_level    info
    parsers_file parsers_multiline.conf
[INPUT]
    Name                tail
    Tag                 kube.*
    Path                test.log
    multiline.parser    multiline_atlas
[OUTPUT]
    name             stdout
    match            *

parsers_multiline.conf

[MULTILINE_PARSER]
    name          multiline_atlas
    type          regex
    parser        cri
    key_content   log
    flush_timeout 2000
    rule          "start_state"   "/^START .+/"      "cont"
    rule          "cont"          "/^(?!^START).+/"    "cont"

[PARSER]
    Name cri
    Format regex
    Regex ^(?<time>[^ ]+) (?<stream>stdout|stderr) (?<logtag>[^ ]*) (?<message>.*)$
    Time_Key    time
    Time_Format %Y-%m-%dT%H:%M:%S.%L%z
    Time_Keep   On

测试日志(test.log)

2025-08-07T07:10:16.421971894Z stdout F START ERROR 2025-07-18 08:47:39 Exception: System.IndexOutOfRangeException: Index was outside the bounds of the array.
2025-08-07T07:10:16.422018515Z stdout F    at Test.Module.Service.Test.LogServiceTest.<>c.<<StartAsync_ShouldReturnFailure_WhenExceptionIsThrown>b__6_0>d.MoveNext() in /home/abcdef/core-module/module-test/Test.Module.Service.Test/LogServiceTest.cs:line151
2025-08-07T07:10:16.422022754Z stdout F --- End of stack trace from previous location ---
2025-08-07T07:10:16.422026373Z stdout F    at Test.Module.Service.Implements.LogServiceBase.StartAsync(String logAction, Func1 func, String scope, Action onEndHook) in /home/abcdef/core-module/module/Test.Module.Service/ServiceImpl
2025-08-07T07:10:11.421029029Z stdout F START INFO 2025-07-18 08:47:18 [Test Log String Scope] Log String Success

测试结果

执行fluent-bit -c fluent-bit.conf后,日志未被CRI解析器处理,仍保留CRI前缀;若将multiline.parser改为cri,可正常解析CRI日志但无法合并多行。期望得到无CRI前缀的合并后日志:

START ERROR 2025-07-18 08:47:39 Exception: System.IndexOutOfRangeException: Index was outside the bounds of the array.
   at Test.Module.Service.Test.LogServiceTest.<>c.<<StartAsync_ShouldReturnFailure_WhenExceptionIsThrown>b__6_0>d.MoveNext() in /home/abcdef/core-module/module-test/Test.Module.Service.Test/LogServiceTest.cs:line151
--- End of stack trace from previous location ---
   at Test.Module.Service.Implements.LogServiceBase.StartAsync(String logAction, Func1 func, String scope, Action onEndHook) in /home/abcdef/core-module/module/Test.Module.Service/ServiceImpl

错误原因与解决方案

错误分析

  1. CRI解析时机错误:自定义多行解析器中的parser cri配置逻辑错误,该参数是用来解析多行规则的匹配内容,而非先处理原始CRI日志。此时原始日志未经过CRI解析,解析器无法识别格式。
  2. 目标字段错误:key_content log指定的字段不存在,原始CRI日志解析后才会生成message字段(即核心日志内容),而非log字段。

修正后的配置

fluent-bit.conf

[SERVICE]
    flush        1
    log_level    info
    parsers_file parsers_multiline.conf
[INPUT]
    Name                tail
    Tag                 kube.*
    Path                test.log
    parser              cri          # 先完成CRI格式解析,提取核心日志到message字段
    multiline.parser    multiline_atlas  # 对解析后的message字段执行多行合并
[OUTPUT]
    name             stdout
    match            *

parsers_multiline.conf

[MULTILINE_PARSER]
    name          multiline_atlas
    type          regex
    key_content   message  # 针对CRI解析后的message字段进行多行合并
    flush_timeout 2000
    rule          "start_state"   "/^START .+/"      "cont"
    rule          "cont"          "/^(?!^START).+/"  "cont"

[PARSER]
    Name cri
    Format regex
    Regex ^(?<time>[^ ]+) (?<stream>stdout|stderr) (?<logtag>[^ ]*) (?<message>.*)$
    Time_Key    time
    Time_Format %Y-%m-%dT%H:%M:%S.%L%z
    Time_Keep   On

效果说明

修正后,Fluent Bit会先通过parser cri解析原始CRI日志,剥离前缀并将核心日志内容存入message字段;随后通过自定义多行解析器对message字段进行合并,最终输出符合预期的无CRI前缀的合并日志。

内容的提问来源于stack exchange,提问作者Llyod

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 13:54:50