123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352 |
- kind: ConfigMap
- apiVersion: v1
- metadata:
- name: fluentd-es-config-v0.2.1
- namespace: logging
- labels:
- addonmanager.kubernetes.io/mode: Reconcile
- data:
- system.conf: |-
- <system>
- root_dir /tmp/fluentd-buffers/
- </system>
- containers.input.conf: |-
- <source>
- @id fluentd-containers.log
- @type tail
- path /var/log/containers/*.log
- pos_file /var/log/es-containers.log.pos
- tag raw.kubernetes.*
- read_from_head true
- <parse>
- @type multi_format
- <pattern>
- format json
- time_key time
- time_format %Y-%m-%dT%H:%M:%S.%NZ
- </pattern>
- <pattern>
- format /^(?<time>.+) (?<stream>stdout|stderr) [^ ]* (?<log>.*)$/
- time_format %Y-%m-%dT%H:%M:%S.%N%:z
- </pattern>
- </parse>
- </source>
- # Detect exceptions in the log output and forward them as one log entry.
- <match raw.kubernetes.**>
- @id raw.kubernetes
- @type detect_exceptions
- remove_tag_prefix raw
- message log
- stream stream
- multiline_flush_interval 5
- max_bytes 500000
- max_lines 1000
- </match>
- # Concatenate multi-line logs
- <filter **>
- @id filter_concat
- @type concat
- key message
- multiline_end_regexp /\n$/
- separator ""
- </filter>
- # Enriches records with Kubernetes metadata
- <filter kubernetes.**>
- @id filter_kubernetes_metadata
- @type kubernetes_metadata
- </filter>
- # Fixes json fields in Elasticsearch
- <filter kubernetes.**>
- @id filter_parser
- @type parser
- key_name log
- reserve_data true
- remove_key_name_field true
- <parse>
- @type multi_format
- <pattern>
- format json
- </pattern>
- <pattern>
- format none
- </pattern>
- </parse>
- </filter>
- system.input.conf: |-
- # Example:
- # 2015-12-21 23:17:22,066 [salt.state ][INFO ] Completed state [net.ipv4.ip_forward] at time 23:17:22.066081
- <source>
- @id minion
- @type tail
- format /^(?<time>[^ ]* [^ ,]*)[^\[]*\[[^\]]*\]\[(?<severity>[^ \]]*) *\] (?<message>.*)$/
- time_format %Y-%m-%d %H:%M:%S
- path /var/log/salt/minion
- pos_file /var/log/salt.pos
- tag salt
- </source>
- # Example:
- # Dec 21 23:17:22 gke-foo-1-1-4b5cbd14-node-4eoj startupscript: Finished running startup script /var/run/google.startup.script
- <source>
- @id startupscript.log
- @type tail
- format syslog
- path /var/log/startupscript.log
- pos_file /var/log/es-startupscript.log.pos
- tag startupscript
- </source>
- # Examples:
- # time="2016-02-04T06:51:03.053580605Z" level=info msg="GET /containers/json"
- # time="2016-02-04T07:53:57.505612354Z" level=error msg="HTTP Error" err="No such image: -f" statusCode=404
- # TODO(random-liu): Remove this after cri container runtime rolls out.
- <source>
- @id docker.log
- @type tail
- format /^time="(?<time>[^"]*)" level=(?<severity>[^ ]*) msg="(?<message>[^"]*)"( err="(?<error>[^"]*)")?( statusCode=($<status_code>\d+))?/
- path /var/log/docker.log
- pos_file /var/log/es-docker.log.pos
- tag docker
- </source>
- # Example:
- # 2016/02/04 06:52:38 filePurge: successfully removed file /var/etcd/data/member/wal/00000000000006d0-00000000010a23d1.wal
- <source>
- @id etcd.log
- @type tail
- # Not parsing this, because it doesn't have anything particularly useful to
- # parse out of it (like severities).
- format none
- path /var/log/etcd.log
- pos_file /var/log/es-etcd.log.pos
- tag etcd
- </source>
- # Multi-line parsing is required for all the kube logs because very large log
- # statements, such as those that include entire object bodies, get split into
- # multiple lines by glog.
- # Example:
- # I0204 07:32:30.020537 3368 server.go:1048] POST /stats/container/: (13.972191ms) 200 [[Go-http-client/1.1] 10.244.1.3:40537]
- <source>
- @id kubelet.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kubelet.log
- pos_file /var/log/es-kubelet.log.pos
- tag kubelet
- </source>
- # Example:
- # I1118 21:26:53.975789 6 proxier.go:1096] Port "nodePort for kube-system/default-http-backend:http" (:31429/tcp) was open before and is still needed
- <source>
- @id kube-proxy.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-proxy.log
- pos_file /var/log/es-kube-proxy.log.pos
- tag kube-proxy
- </source>
- # Example:
- # I0204 07:00:19.604280 5 handlers.go:131] GET /api/v1/nodes: (1.624207ms) 200 [[kube-controller-manager/v1.1.3 (linux/amd64) kubernetes/6a81b50] 127.0.0.1:38266]
- <source>
- @id kube-apiserver.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-apiserver.log
- pos_file /var/log/es-kube-apiserver.log.pos
- tag kube-apiserver
- </source>
- # Example:
- # I0204 06:55:31.872680 5 servicecontroller.go:277] LB already exists and doesn't need update for service kube-system/kube-ui
- <source>
- @id kube-controller-manager.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-controller-manager.log
- pos_file /var/log/es-kube-controller-manager.log.pos
- tag kube-controller-manager
- </source>
- # Example:
- # W0204 06:49:18.239674 7 reflector.go:245] pkg/scheduler/factory/factory.go:193: watch of *api.Service ended with: 401: The event in requested index is outdated and cleared (the requested history has been cleared [2578313/2577886]) [2579312]
- <source>
- @id kube-scheduler.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-scheduler.log
- pos_file /var/log/es-kube-scheduler.log.pos
- tag kube-scheduler
- </source>
- # Example:
- # I0603 15:31:05.793605 6 cluster_manager.go:230] Reading config from path /etc/gce.conf
- <source>
- @id glbc.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/glbc.log
- pos_file /var/log/es-glbc.log.pos
- tag glbc
- </source>
- # Example:
- # I0603 15:31:05.793605 6 cluster_manager.go:230] Reading config from path /etc/gce.conf
- <source>
- @id cluster-autoscaler.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/cluster-autoscaler.log
- pos_file /var/log/es-cluster-autoscaler.log.pos
- tag cluster-autoscaler
- </source>
- # Logs from systemd-journal for interesting services.
- # TODO(random-liu): Remove this after cri container runtime rolls out.
- <source>
- @id journald-docker
- @type systemd
- matches [{ "_SYSTEMD_UNIT": "docker.service" }]
- <storage>
- @type local
- persistent true
- path /var/log/journald-docker.pos
- </storage>
- read_from_head true
- tag docker
- </source>
- <source>
- @id journald-container-runtime
- @type systemd
- matches [{ "_SYSTEMD_UNIT": "{{ fluentd_container_runtime_service }}.service" }]
- <storage>
- @type local
- persistent true
- path /var/log/journald-container-runtime.pos
- </storage>
- read_from_head true
- tag container-runtime
- </source>
- <source>
- @id journald-kubelet
- @type systemd
- matches [{ "_SYSTEMD_UNIT": "kubelet.service" }]
- <storage>
- @type local
- persistent true
- path /var/log/journald-kubelet.pos
- </storage>
- read_from_head true
- tag kubelet
- </source>
- <source>
- @id journald-node-problem-detector
- @type systemd
- matches [{ "_SYSTEMD_UNIT": "node-problem-detector.service" }]
- <storage>
- @type local
- persistent true
- path /var/log/journald-node-problem-detector.pos
- </storage>
- read_from_head true
- tag node-problem-detector
- </source>
- <source>
- @id kernel
- @type systemd
- matches [{ "_TRANSPORT": "kernel" }]
- <storage>
- @type local
- persistent true
- path /var/log/kernel.pos
- </storage>
- <entry>
- fields_strip_underscores true
- fields_lowercase true
- </entry>
- read_from_head true
- tag kernel
- </source>
- forward.input.conf: |-
- # Takes the messages sent over TCP
- <source>
- @id forward
- @type forward
- </source>
- monitoring.conf: |-
- # Prometheus Exporter Plugin
- # input plugin that exports metrics
- <source>
- @id prometheus
- @type prometheus
- </source>
- <source>
- @id monitor_agent
- @type monitor_agent
- </source>
- # input plugin that collects metrics from MonitorAgent
- <source>
- @id prometheus_monitor
- @type prometheus_monitor
- <labels>
- host ${hostname}
- </labels>
- </source>
- # input plugin that collects metrics for output plugin
- <source>
- @id prometheus_output_monitor
- @type prometheus_output_monitor
- <labels>
- host ${hostname}
- </labels>
- </source>
- # input plugin that collects metrics for in_tail plugin
- <source>
- @id prometheus_tail_monitor
- @type prometheus_tail_monitor
- <labels>
- host ${hostname}
- </labels>
- </source>
- output.conf: |-
- <match **>
- @id elasticsearch
- @type elasticsearch
- @log_level info
- type_name _doc
- include_tag_key true
- host elasticsearch-logging
- port 9200
- logstash_format true
- <buffer>
- @type file
- path /var/log/fluentd-buffers/kubernetes.system.buffer
- flush_mode interval
- retry_type exponential_backoff
- flush_thread_count 2
- flush_interval 5s
- retry_forever
- retry_max_interval 30
- chunk_limit_size 2M
- total_limit_size 500M
- overflow_action block
- </buffer>
- </match>
|