|
- kind: ConfigMap
- apiVersion: v1
- metadata:
- name: fluentd-es-config-v0.1.4
- namespace: logging
- labels:
- addonmanager.kubernetes.io/mode: Reconcile
- data:
- system.conf: |-
- <system>
- root_dir /tmp/fluentd-buffers/
- </system>
- containers.input.conf: |-
- <source>
- @id fluentd-containers.log
- @type tail
- path /var/log/containers/*.log
- pos_file /var/log/es-containers.log.pos
- time_format %Y-%m-%dT%H:%M:%S.%NZ
- tag raw.kubernetes.*
- read_from_head true
- <parse>
- @type multi_format
- <pattern>
- format json
- time_key time
- time_format %Y-%m-%dT%H:%M:%S.%NZ
- </pattern>
- <pattern>
- format /^(?<time>.+) (?<stream>stdout|stderr) [^ ]* (?<log>.*)$/
- time_format %Y-%m-%dT%H:%M:%S.%N%:z
- </pattern>
- </parse>
- </source>
- # Detect exceptions in the log output and forward them as one log entry.
- <match raw.kubernetes.**>
- @id raw.kubernetes
- @type detect_exceptions
- remove_tag_prefix raw
- message log
- stream stream
- multiline_flush_interval 5
- max_bytes 500000
- max_lines 1000
- </match>
- system.input.conf: |-
- # Examples:
- # time="2016-02-04T06:51:03.053580605Z" level=info msg="GET /containers/json"
- # time="2016-02-04T07:53:57.505612354Z" level=error msg="HTTP Error" err="No such image: -f" statusCode=404
- # TODO(random-liu): Remove this after cri container runtime rolls out.
- <source>
- @id docker.log
- @type tail
- format /^time="(?<time>[^)]*)" level=(?<severity>[^ ]*) msg="(?<message>[^"]*)"( err="(?<error>[^"]*)")?( statusCode=($<status_code>\d+))?/
- path /var/log/docker.log
- pos_file /var/log/es-docker.log.pos
- tag docker
- </source>
- # Multi-line parsing is required for all the kube logs because very large log
- # statements, such as those that include entire object bodies, get split into
- # multiple lines by glog.
- # Example:
- # I0204 07:32:30.020537 3368 server.go:1048] POST /stats/container/: (13.972191ms) 200 [[Go-http-client/1.1] 10.244.1.3:40537]
- <source>
- @id kubelet.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kubelet.log
- pos_file /var/log/es-kubelet.log.pos
- tag kubelet
- </source>
- # Example:
- # I1118 21:26:53.975789 6 proxier.go:1096] Port "nodePort for kube-system/default-http-backend:http" (:31429/tcp) was open before and is still needed
- <source>
- @id kube-proxy.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-proxy.log
- pos_file /var/log/es-kube-proxy.log.pos
- tag kube-proxy
- </source>
- # Example:
- # I0204 07:00:19.604280 5 handlers.go:131] GET /api/v1/nodes: (1.624207ms) 200 [[kube-controller-manager/v1.1.3 (linux/amd64) kubernetes/6a81b50] 127.0.0.1:38266]
- <source>
- @id kube-apiserver.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-apiserver.log
- pos_file /var/log/es-kube-apiserver.log.pos
- tag kube-apiserver
- </source>
- # Example:
- # I0204 06:55:31.872680 5 servicecontroller.go:277] LB already exists and doesn't need update for service kube-system/kube-ui
- <source>
- @id kube-controller-manager.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-controller-manager.log
- pos_file /var/log/es-kube-controller-manager.log.pos
- tag kube-controller-manager
- </source>
- # Example:
- # W0204 06:49:18.239674 7 reflector.go:245] pkg/scheduler/factory/factory.go:193: watch of *api.Service ended with: 401: The event in requested index is outdated and cleared (the requested history has been cleared [2578313/2577886]) [2579312]
- <source>
- @id kube-scheduler.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/kube-scheduler.log
- pos_file /var/log/es-kube-scheduler.log.pos
- tag kube-scheduler
- </source>
- # Example:
- # I1104 10:36:20.242766 5 rescheduler.go:73] Running Rescheduler
- <source>
- @id rescheduler.log
- @type tail
- format multiline
- multiline_flush_interval 5s
- format_firstline /^\w\d{4}/
- format1 /^(?<severity>\w)(?<time>\d{4} [^\s]*)\s+(?<pid>\d+)\s+(?<source>[^ \]]+)\] (?<message>.*)/
- time_format %m%d %H:%M:%S.%N
- path /var/log/rescheduler.log
- pos_file /var/log/es-rescheduler.log.pos
- tag rescheduler
- </source>
- # Logs from systemd-journal for interesting services.
- # TODO(random-liu): Remove this after cri container runtime rolls out.
- <source>
- @id journald-docker
- @type systemd
- filters [{ "_SYSTEMD_UNIT": "docker.service" }]
- <storage>
- @type local
- persistent true
- </storage>
- read_from_head true
- tag docker
- </source>
- <source>
- @id journald-container-runtime
- @type systemd
- filters [{ "_SYSTEMD_UNIT": "{{ container_runtime }}.service" }]
- <storage>
- @type local
- persistent true
- </storage>
- read_from_head true
- tag container-runtime
- </source>
- <source>
- @id journald-kubelet
- @type systemd
- filters [{ "_SYSTEMD_UNIT": "kubelet.service" }]
- <storage>
- @type local
- persistent true
- </storage>
- read_from_head true
- tag kubelet
- </source>
- <source>
- @id journald-node-problem-detector
- @type systemd
- filters [{ "_SYSTEMD_UNIT": "node-problem-detector.service" }]
- <storage>
- @type local
- persistent true
- </storage>
- read_from_head true
- tag node-problem-detector
- </source>
-
- <source>
- @id kernel
- @type systemd
- filters [{ "_TRANSPORT": "kernel" }]
- <storage>
- @type local
- persistent true
- </storage>
- <entry>
- fields_strip_underscores true
- fields_lowercase true
- </entry>
- read_from_head true
- tag kernel
- </source>
- forward.input.conf: |-
- # Takes the messages sent over TCP
- <source>
- @type forward
- </source>
- monitoring.conf: |-
- # Prometheus Exporter Plugin
- # input plugin that exports metrics
- <source>
- @type prometheus
- </source>
- <source>
- @type monitor_agent
- </source>
- # input plugin that collects metrics from MonitorAgent
- <source>
- @type prometheus_monitor
- <labels>
- host ${hostname}
- </labels>
- </source>
- # input plugin that collects metrics for output plugin
- <source>
- @type prometheus_output_monitor
- <labels>
- host ${hostname}
- </labels>
- </source>
- # input plugin that collects metrics for in_tail plugin
- <source>
- @type prometheus_tail_monitor
- <labels>
- host ${hostname}
- </labels>
- </source>
- output.conf: |-
- # Enriches records with Kubernetes metadata
- <filter kubernetes.**>
- @type kubernetes_metadata
- </filter>
- <match **>
- @id elasticsearch
- @type elasticsearch
- @log_level info
- include_tag_key true
- host elasticsearch-logging
- port 9200
- logstash_format true
- logstash_prefix fluentd-k8s
- logstash_dateformat %Y.%m.%d
- <buffer>
- @type file
- path /var/log/fluentd-buffers/kubernetes.system.buffer
- flush_mode interval
- retry_type exponential_backoff
- flush_thread_count 2
- flush_interval 5s
- retry_forever
- retry_max_interval 30
- chunk_limit_size 2M
- queue_limit_length 8
- overflow_action block
- </buffer>
- </match>
|