深色模式
Vector 高性能管道
Vector 用 Rust 编写,单进程即可完成采集、解析、转换、路由,性能远超传统 Agent。本文搭建一条「读 nginx 日志 → 加字段 → 发 ES」的管道。
适用环境
bash
# 确认架构
uname -m
# 下载并安装 Vector(以 x86_64 为例)
curl -sSfL https://sh.vector.dev | sh1
2
3
4
2
3
4
操作步骤
1. 生成并编辑配置(/etc/vector/vector.toml)
toml
[sources.nginx]
type = "file"
include = ["/var/log/nginx/access.log"]
read_from = "beginning"
[transforms.parse]
type = "remap"
inputs = ["nginx"]
source = '''
. |= parse_nginx_log!(.message, "combined")
.env = "production"
'''
[sinks.elasticsearch]
type = "elasticsearch"
inputs = ["parse"]
endpoints = ["http://es-host:9200"]
index = "vector-%Y-%m-%d"1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
2. 启动
bash
sudo systemctl enable --now vector1
DANGER
Vector 的 remap 使用 VRL 语言,语法与 JSON 不同。写错会导致整条管道丢弃事件,务必先 vector vrl --syntax 校验。
验证
bash
# 校验配置语法
vector validate --config /etc/vector/vector.toml
# 查看内部指标
curl -s http://localhost:9001/metrics | grep vector_events1
2
3
4
5
2
3
4
5
常见坑
WARNING
file source 默认从文件末尾读(read_from = "end"),调试历史日志时要显式设 read_from = "beginning",否则看不到数据。
WARNING
ES sink 的 index 不支持动态模板时,确保日期格式与 ILM 别名一致,否则索引不会被生命周期策略接管。