深色模式
Fluent Bit 轻量采集
Fluent Bit 用 C 编写,内存占用通常只有几 MB,是 Kubernetes 节点级采集的首选。本文演示在容器环境采集 stdout 并转发到 ES/Loki。
适用环境
bash
# 确认 Docker 守护进程日志驱动(默认 json-file)
docker info | grep -i 'Logging Driver'
# 容器日志默认落盘位置
sudo ls /var/lib/docker/containers/*/*-json.log | head1
2
3
4
5
2
3
4
5
操作步骤
1. 用容器方式快速跑一个 Fluent Bit
bash
docker run -d --name fluent-bit \
-p 2020:2020 \
-v $(pwd)/fluent-bit.conf:/fluent-bit/etc/fluent-bit.conf \
cr.fluentbit.io/fluent/fluent-bit:latest1
2
3
4
2
3
4
2. 配置文件 fluent-bit.conf
ini
[INPUT]
Name tail
Path /var/lib/docker/containers/*/*-json.log
Parser docker
Tag docker.*
[OUTPUT]
Name es
Match *
Host es-host
Port 9200
Index fluentbit
Logstash_Format On1
2
3
4
5
6
7
8
9
10
11
12
13
2
3
4
5
6
7
8
9
10
11
12
13
3. 在 Kubernetes 中以 DaemonSet 部署(官方清单)
bash
kubectl apply -f https://raw.githubusercontent.com/fluent/fluent-bit-kubernetes-logging/main/fluent-bit-ds.yaml
kubectl -n logging logs -l app=fluent-bit --tail=201
2
2
验证
bash
# 本地 HTTP 监控端口
curl -s http://localhost:2020/api/v1/metrics | head
# 确认 ES 有 fluentbit 索引写入
curl -s 'http://es-host:9200/_cat/indices/fluentbit*?v'1
2
3
4
5
2
3
4
5
常见坑
WARNING
tail 输入需要正确配置 Parser,否则整行当字符串存,后期无法按字段查询。先用 fluent-bit -c fluent-bit.conf -e parser.conf 本地试跑。
DANGER
Fluent Bit 默认不带磁盘缓冲,后端不可用时可能丢日志。高可靠场景开启 storage.type filesystem 缓冲。