You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenTelemetry Collector提取Docker日志指定字段至Seq的配置问询

有效配置示例

以下是仅传输log字段和com.docker.swarm.service.name字段的完整OpenTelemetry Collector配置:

receivers:
  filelog:
    include: [/var/lib/docker/containers/*/*log]
    start_at: beginning
    operators:
      # 解析Docker日志的JSON行内容
      - type: json_parser
        parse_from: $body
        output: move_service_name
      # 将Swarm服务名字段从attrs子节点迁移到根节点
      - type: move
        id: move_service_name
        from: attrs.com.docker.swarm.service.name
        to: com.docker.swarm.service.name
        output: clean_fields
      # 仅保留指定字段,移除所有其他冗余字段
      - type: remove
        id: clean_fields
        field: $body
        preserve:
          - log
          - com.docker.swarm.service.name

processors:
  # 可选:当服务名字段缺失时填充默认值,避免日志无标识
  attributes:
    actions:
      - action: insert
        key: com.docker.swarm.service.name
        value: "unknown-service"
        when:
          condition:
            not:
              exists: com.docker.swarm.service.name

exporters:
  otlphttp/seq:
    endpoint: "http://<seq-host>:<seq-port>/ingest/otlp/v1/logs"
    headers:
      X-Seq-ApiKey: "<your-seq-api-key>"

service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [attributes]
      exporters: [otlphttp/seq]

关键配置说明

  1. filelog接收器

    • json_parser直接解析整个日志行($body),因为Docker容器日志的每行都是标准JSON结构。
    • move操作解决字段嵌套问题:Docker Swarm的服务名字段默认嵌套在attrs节点下,通过迁移到根节点简化后续字段过滤逻辑。如果你的日志中服务名字段路径不同(比如labels.com.docker.swarm.service.name),修改from参数即可。
    • remove操作的preserve列表严格限定仅保留目标字段,确保冗余数据不会被发送到Seq。
  2. attributes处理器(可选)
    当部分日志缺失服务名字段时,自动填充默认值unknown-service,避免日志失去业务标识。

  3. OTLP导出器
    使用Seq官方支持的OTLP HTTP协议传输日志,替换配置中的<seq-host>、<seq-port>和<your-seq-api-key>为你的Seq实例信息。

内容的提问来源于stack exchange,提问作者Alexandr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 01:42:46