Fluent Bit CRI多行日志解析配置失效,如何正确提取合并日志?
问题描述
在Kubernetes中部署Fluent Bit,计划将日志转发至Loki与Grafana。本地测试时需要先通过CRI解析器处理CRI格式日志,提取核心日志内容后再合并多行日志。配置了自定义多行解析器后,发现CRI解析器未生效,日志仍保留CRI前缀(时间戳、stdout标识等);若直接将multiline.parser设为cri,虽能正常解析CRI日志,但无法实现多行合并。
当前配置文件
fluent-bit.conf
[SERVICE] flush 1 log_level info parsers_file parsers_multiline.conf [INPUT] Name tail Tag kube.* Path test.log multiline.parser multiline_atlas [OUTPUT] name stdout match *
parsers_multiline.conf
[MULTILINE_PARSER] name multiline_atlas type regex parser cri key_content log flush_timeout 2000 rule "start_state" "/^START .+/" "cont" rule "cont" "/^(?!^START).+/" "cont" [PARSER] Name cri Format regex Regex ^(?<time>[^ ]+) (?<stream>stdout|stderr) (?<logtag>[^ ]*) (?<message>.*)$ Time_Key time Time_Format %Y-%m-%dT%H:%M:%S.%L%z Time_Keep On
测试日志(test.log)
2025-08-07T07:10:16.421971894Z stdout F START ERROR 2025-07-18 08:47:39 Exception: System.IndexOutOfRangeException: Index was outside the bounds of the array. 2025-08-07T07:10:16.422018515Z stdout F at Test.Module.Service.Test.LogServiceTest.<>c.<<StartAsync_ShouldReturnFailure_WhenExceptionIsThrown>b__6_0>d.MoveNext() in /home/abcdef/core-module/module-test/Test.Module.Service.Test/LogServiceTest.cs:line151 2025-08-07T07:10:16.422022754Z stdout F --- End of stack trace from previous location --- 2025-08-07T07:10:16.422026373Z stdout F at Test.Module.Service.Implements.LogServiceBase.StartAsync(String logAction, Func1 func, String scope, Action onEndHook) in /home/abcdef/core-module/module/Test.Module.Service/ServiceImpl 2025-08-07T07:10:11.421029029Z stdout F START INFO 2025-07-18 08:47:18 [Test Log String Scope] Log String Success
测试结果
执行fluent-bit -c fluent-bit.conf后,日志未被CRI解析器处理,仍保留CRI前缀;若将multiline.parser改为cri,可正常解析CRI日志但无法合并多行。期望得到无CRI前缀的合并后日志:
START ERROR 2025-07-18 08:47:39 Exception: System.IndexOutOfRangeException: Index was outside the bounds of the array. at Test.Module.Service.Test.LogServiceTest.<>c.<<StartAsync_ShouldReturnFailure_WhenExceptionIsThrown>b__6_0>d.MoveNext() in /home/abcdef/core-module/module-test/Test.Module.Service.Test/LogServiceTest.cs:line151 --- End of stack trace from previous location --- at Test.Module.Service.Implements.LogServiceBase.StartAsync(String logAction, Func1 func, String scope, Action onEndHook) in /home/abcdef/core-module/module/Test.Module.Service/ServiceImpl
错误原因与解决方案
错误分析
- CRI解析时机错误:自定义多行解析器中的
parser cri配置逻辑错误,该参数是用来解析多行规则的匹配内容,而非先处理原始CRI日志。此时原始日志未经过CRI解析,解析器无法识别格式。 - 目标字段错误:
key_content log指定的字段不存在,原始CRI日志解析后才会生成message字段(即核心日志内容),而非log字段。
修正后的配置
fluent-bit.conf
[SERVICE] flush 1 log_level info parsers_file parsers_multiline.conf [INPUT] Name tail Tag kube.* Path test.log parser cri # 先完成CRI格式解析,提取核心日志到message字段 multiline.parser multiline_atlas # 对解析后的message字段执行多行合并 [OUTPUT] name stdout match *
parsers_multiline.conf
[MULTILINE_PARSER] name multiline_atlas type regex key_content message # 针对CRI解析后的message字段进行多行合并 flush_timeout 2000 rule "start_state" "/^START .+/" "cont" rule "cont" "/^(?!^START).+/" "cont" [PARSER] Name cri Format regex Regex ^(?<time>[^ ]+) (?<stream>stdout|stderr) (?<logtag>[^ ]*) (?<message>.*)$ Time_Key time Time_Format %Y-%m-%dT%H:%M:%S.%L%z Time_Keep On
效果说明
修正后,Fluent Bit会先通过parser cri解析原始CRI日志,剥离前缀并将核心日志内容存入message字段;随后通过自定义多行解析器对message字段进行合并,最终输出符合预期的无CRI前缀的合并日志。
内容的提问来源于stack exchange,提问作者Llyod
相关产品推荐
相关产品推荐

