OpenTelemetry Collector提取Docker日志指定字段至Seq的配置问询
有效配置示例
以下是仅传输log字段和com.docker.swarm.service.name字段的完整OpenTelemetry Collector配置:
receivers: filelog: include: [/var/lib/docker/containers/*/*log] start_at: beginning operators: # 解析Docker日志的JSON行内容 - type: json_parser parse_from: $body output: move_service_name # 将Swarm服务名字段从attrs子节点迁移到根节点 - type: move id: move_service_name from: attrs.com.docker.swarm.service.name to: com.docker.swarm.service.name output: clean_fields # 仅保留指定字段,移除所有其他冗余字段 - type: remove id: clean_fields field: $body preserve: - log - com.docker.swarm.service.name processors: # 可选:当服务名字段缺失时填充默认值,避免日志无标识 attributes: actions: - action: insert key: com.docker.swarm.service.name value: "unknown-service" when: condition: not: exists: com.docker.swarm.service.name exporters: otlphttp/seq: endpoint: "http://<seq-host>:<seq-port>/ingest/otlp/v1/logs" headers: X-Seq-ApiKey: "<your-seq-api-key>" service: pipelines: logs: receivers: [filelog] processors: [attributes] exporters: [otlphttp/seq]
关键配置说明
filelog接收器
json_parser直接解析整个日志行($body),因为Docker容器日志的每行都是标准JSON结构。move操作解决字段嵌套问题:Docker Swarm的服务名字段默认嵌套在attrs节点下,通过迁移到根节点简化后续字段过滤逻辑。如果你的日志中服务名字段路径不同(比如labels.com.docker.swarm.service.name),修改from参数即可。remove操作的preserve列表严格限定仅保留目标字段,确保冗余数据不会被发送到Seq。
attributes处理器(可选)
当部分日志缺失服务名字段时,自动填充默认值unknown-service,避免日志失去业务标识。OTLP导出器
使用Seq官方支持的OTLP HTTP协议传输日志,替换配置中的<seq-host>、<seq-port>和<your-seq-api-key>为你的Seq实例信息。
内容的提问来源于stack exchange,提问作者Alexandr
相关产品推荐
相关产品推荐

