|
@@ -0,0 +1,271 @@
|
|
|
+kind: ConfigMap
|
|
|
+apiVersion: v1
|
|
|
+metadata:
|
|
|
+ name: fluentd-es-config-v0.1.4
|
|
|
+ namespace: logging
|
|
|
+ labels:
|
|
|
+ addonmanager.kubernetes.io/mode: Reconcile
|
|
|
+data:
|
|
|
+ system.conf: |-
|
|
|
+ <system>
|
|
|
+ root_dir /tmp/fluentd-buffers/
|
|
|
+ </system>
|
|
|
+ containers.input.conf: |-
|
|
|
+ <source>
|
|
|
+ @id fluentd-containers.log
|
|
|
+ @type tail
|
|
|
+ path /var/log/containers/*.log
|
|
|
+ pos_file /var/log/es-containers.log.pos
|
|
|
+ time_format %Y-%m-%dT%H:%M:%S.%NZ
|
|
|
+ tag raw.kubernetes.*
|
|
|
+ read_from_head true
|
|
|
+ <parse>
|
|
|
+ @type multi_format
|
|
|
+ <pattern>
|
|
|
+ format json
|
|
|
+ time_key time
|
|
|
+ time_format %Y-%m-%dT%H:%M:%S.%NZ
|
|
|
+ </pattern>
|
|
|
+ <pattern>
|
|
|
+ format /^(?<time>.+) (?<stream>stdout|stderr) [^ ]* (?<log>.*)$/
|
|
|
+ time_format %Y-%m-%dT%H:%M:%S.%N%:z
|
|
|
+ </pattern>
|
|
|
+ </parse>
|
|
|
+ </source>
|
|
|
+ # Detect exceptions in the log output and forward them as one log entry.
|
|
|
+ <match raw.kubernetes.**>
|
|
|
+ @id raw.kubernetes
|
|
|
+ @type detect_exceptions
|
|
|
+ remove_tag_prefix raw
|
|
|
+ message log
|
|
|
+ stream stream
|
|
|
+ multiline_flush_interval 5
|
|
|
+ max_bytes 500000
|
|
|
+ max_lines 1000
|
|
|
+ </match>
|
|
|
+ system.input.conf: |-
|
|
|
+ # Examples:
|
|
|
+ # time="2016-02-04T06:51:03.053580605Z" level=info msg="GET /containers/json"
|
|
|
+ # time="2016-02-04T07:53:57.505612354Z" level=error msg="HTTP Error" err="No such image: -f" statusCode=404
|
|
|
+ # TODO(random-liu): Remove this after cri container runtime rolls out.
|
|
|
+ <source>
|
|
|
+ @id docker.log
|
|
|
+ @type tail
|
|
|
+ format /^time="(?<time>[^)]*)" level=(?<severity>[^ ]*) msg="(?<message>[^"]*)"( err="(?<error>[^"]*)")?( statusCode=($<status_code>\d+))?/
|
|
|
+ path /var/log/docker.log
|
|
|
+ pos_file /var/log/es-docker.log.pos
|
|
|
+ tag docker
|
|
|
+ </source>
|
|
|
+ # Multi-line parsing is required for all the kube logs because very large log
|
|
|
+ # statements, such as those that include entire object bodies, get split into
|
|
|
+ # multiple lines by glog.
|
|
|
+ # Example:
|
|
|
+ # I0204 07:32:30.020537 3368 server.go:1048] POST /stats/container/: (13.972191ms) 200 [[Go-http-client/1.1] 10.244.1.3:40537]
|
|
|
+ <source>
|
|
|
+ @id kubelet.log
|
|
|
+ @type tail
|
|
|
+ format multiline
|
|
|
+ multiline_flush_interval 5s
|
|
|
+ format_firstline /^\w\d{4}/
|
|
|
+ format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
|
|
|
+ time_format %m%d %H:%M:%S.%N
|
|
|
+ path /var/log/kubelet.log
|
|
|
+ pos_file /var/log/es-kubelet.log.pos
|
|
|
+ tag kubelet
|
|
|
+ </source>
|
|
|
+ # Example:
|
|
|
+ # I1118 21:26:53.975789 6 proxier.go:1096] Port "nodePort for kube-system/default-http-backend:http" (:31429/tcp) was open before and is still needed
|
|
|
+ <source>
|
|
|
+ @id kube-proxy.log
|
|
|
+ @type tail
|
|
|
+ format multiline
|
|
|
+ multiline_flush_interval 5s
|
|
|
+ format_firstline /^\w\d{4}/
|
|
|
+ format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
|
|
|
+ time_format %m%d %H:%M:%S.%N
|
|
|
+ path /var/log/kube-proxy.log
|
|
|
+ pos_file /var/log/es-kube-proxy.log.pos
|
|
|
+ tag kube-proxy
|
|
|
+ </source>
|
|
|
+ # Example:
|
|
|
+ # I0204 07:00:19.604280 5 handlers.go:131] GET /api/v1/nodes: (1.624207ms) 200 [[kube-controller-manager/v1.1.3 (linux/amd64) kubernetes/6a81b50] 127.0.0.1:38266]
|
|
|
+ <source>
|
|
|
+ @id kube-apiserver.log
|
|
|
+ @type tail
|
|
|
+ format multiline
|
|
|
+ multiline_flush_interval 5s
|
|
|
+ format_firstline /^\w\d{4}/
|
|
|
+ format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
|
|
|
+ time_format %m%d %H:%M:%S.%N
|
|
|
+ path /var/log/kube-apiserver.log
|
|
|
+ pos_file /var/log/es-kube-apiserver.log.pos
|
|
|
+ tag kube-apiserver
|
|
|
+ </source>
|
|
|
+ # Example:
|
|
|
+ # I0204 06:55:31.872680 5 servicecontroller.go:277] LB already exists and doesn't need update for service kube-system/kube-ui
|
|
|
+ <source>
|
|
|
+ @id kube-controller-manager.log
|
|
|
+ @type tail
|
|
|
+ format multiline
|
|
|
+ multiline_flush_interval 5s
|
|
|
+ format_firstline /^\w\d{4}/
|
|
|
+ format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
|
|
|
+ time_format %m%d %H:%M:%S.%N
|
|
|
+ path /var/log/kube-controller-manager.log
|
|
|
+ pos_file /var/log/es-kube-controller-manager.log.pos
|
|
|
+ tag kube-controller-manager
|
|
|
+ </source>
|
|
|
+ # Example:
|
|
|
+ # W0204 06:49:18.239674 7 reflector.go:245] pkg/scheduler/factory/factory.go:193: watch of *api.Service ended with: 401: The event in requested index is outdated and cleared (the requested history has been cleared [2578313/2577886]) [2579312]
|
|
|
+ <source>
|
|
|
+ @id kube-scheduler.log
|
|
|
+ @type tail
|
|
|
+ format multiline
|
|
|
+ multiline_flush_interval 5s
|
|
|
+ format_firstline /^\w\d{4}/
|
|
|
+ format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
|
|
|
+ time_format %m%d %H:%M:%S.%N
|
|
|
+ path /var/log/kube-scheduler.log
|
|
|
+ pos_file /var/log/es-kube-scheduler.log.pos
|
|
|
+ tag kube-scheduler
|
|
|
+ </source>
|
|
|
+ # Example:
|
|
|
+ # I1104 10:36:20.242766 5 rescheduler.go:73] Running Rescheduler
|
|
|
+ <source>
|
|
|
+ @id rescheduler.log
|
|
|
+ @type tail
|
|
|
+ format multiline
|
|
|
+ multiline_flush_interval 5s
|
|
|
+ format_firstline /^\w\d{4}/
|
|
|
+ format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
|
|
|
+ time_format %m%d %H:%M:%S.%N
|
|
|
+ path /var/log/rescheduler.log
|
|
|
+ pos_file /var/log/es-rescheduler.log.pos
|
|
|
+ tag rescheduler
|
|
|
+ </source>
|
|
|
+ # Logs from systemd-journal for interesting services.
|
|
|
+ # TODO(random-liu): Remove this after cri container runtime rolls out.
|
|
|
+ <source>
|
|
|
+ @id journald-docker
|
|
|
+ @type systemd
|
|
|
+ filters [{ "_SYSTEMD_UNIT": "docker.service" }]
|
|
|
+ <storage>
|
|
|
+ @type local
|
|
|
+ persistent true
|
|
|
+ </storage>
|
|
|
+ read_from_head true
|
|
|
+ tag docker
|
|
|
+ </source>
|
|
|
+ <source>
|
|
|
+ @id journald-container-runtime
|
|
|
+ @type systemd
|
|
|
+ filters [{ "_SYSTEMD_UNIT": "{{ container_runtime }}.service" }]
|
|
|
+ <storage>
|
|
|
+ @type local
|
|
|
+ persistent true
|
|
|
+ </storage>
|
|
|
+ read_from_head true
|
|
|
+ tag container-runtime
|
|
|
+ </source>
|
|
|
+ <source>
|
|
|
+ @id journald-kubelet
|
|
|
+ @type systemd
|
|
|
+ filters [{ "_SYSTEMD_UNIT": "kubelet.service" }]
|
|
|
+ <storage>
|
|
|
+ @type local
|
|
|
+ persistent true
|
|
|
+ </storage>
|
|
|
+ read_from_head true
|
|
|
+ tag kubelet
|
|
|
+ </source>
|
|
|
+ <source>
|
|
|
+ @id journald-node-problem-detector
|
|
|
+ @type systemd
|
|
|
+ filters [{ "_SYSTEMD_UNIT": "node-problem-detector.service" }]
|
|
|
+ <storage>
|
|
|
+ @type local
|
|
|
+ persistent true
|
|
|
+ </storage>
|
|
|
+ read_from_head true
|
|
|
+ tag node-problem-detector
|
|
|
+ </source>
|
|
|
+
|
|
|
+ <source>
|
|
|
+ @id kernel
|
|
|
+ @type systemd
|
|
|
+ filters [{ "_TRANSPORT": "kernel" }]
|
|
|
+ <storage>
|
|
|
+ @type local
|
|
|
+ persistent true
|
|
|
+ </storage>
|
|
|
+ <entry>
|
|
|
+ fields_strip_underscores true
|
|
|
+ fields_lowercase true
|
|
|
+ </entry>
|
|
|
+ read_from_head true
|
|
|
+ tag kernel
|
|
|
+ </source>
|
|
|
+ forward.input.conf: |-
|
|
|
+ # Takes the messages sent over TCP
|
|
|
+ <source>
|
|
|
+ @type forward
|
|
|
+ </source>
|
|
|
+ monitoring.conf: |-
|
|
|
+ # Prometheus Exporter Plugin
|
|
|
+ # input plugin that exports metrics
|
|
|
+ <source>
|
|
|
+ @type prometheus
|
|
|
+ </source>
|
|
|
+ <source>
|
|
|
+ @type monitor_agent
|
|
|
+ </source>
|
|
|
+ # input plugin that collects metrics from MonitorAgent
|
|
|
+ <source>
|
|
|
+ @type prometheus_monitor
|
|
|
+ <labels>
|
|
|
+ host ${hostname}
|
|
|
+ </labels>
|
|
|
+ </source>
|
|
|
+ # input plugin that collects metrics for output plugin
|
|
|
+ <source>
|
|
|
+ @type prometheus_output_monitor
|
|
|
+ <labels>
|
|
|
+ host ${hostname}
|
|
|
+ </labels>
|
|
|
+ </source>
|
|
|
+ # input plugin that collects metrics for in_tail plugin
|
|
|
+ <source>
|
|
|
+ @type prometheus_tail_monitor
|
|
|
+ <labels>
|
|
|
+ host ${hostname}
|
|
|
+ </labels>
|
|
|
+ </source>
|
|
|
+ output.conf: |-
|
|
|
+ # Enriches records with Kubernetes metadata
|
|
|
+ <filter kubernetes.**>
|
|
|
+ @type kubernetes_metadata
|
|
|
+ </filter>
|
|
|
+ <match **>
|
|
|
+ @id elasticsearch
|
|
|
+ @type elasticsearch
|
|
|
+ @log_level info
|
|
|
+ include_tag_key true
|
|
|
+ host elasticsearch-logging
|
|
|
+ port 9200
|
|
|
+ logstash_format true
|
|
|
+ logstash_prefix fluentd-k8s
|
|
|
+ logstash_dateformat %Y.%m.%d
|
|
|
+ <buffer>
|
|
|
+ @type file
|
|
|
+ path /var/log/fluentd-buffers/kubernetes.system.buffer
|
|
|
+ flush_mode interval
|
|
|
+ retry_type exponential_backoff
|
|
|
+ flush_thread_count 2
|
|
|
+ flush_interval 5s
|
|
|
+ retry_forever
|
|
|
+ retry_max_interval 30
|
|
|
+ chunk_limit_size 2M
|
|
|
+ queue_limit_length 8
|
|
|
+ overflow_action block
|
|
|
+ </buffer>
|
|
|
+ </match>
|