Pramod Sharma
03/09/2024, 7:09 PMreceivers:
filelog:
include: [ /var/log/audit/aks.log ]
start_at: end
operators:
- type: json_parser
service:
pipelines:
logs:
receivers: [otlp, filelog, httplogreceiver/heroku, httplogreceiver/json]
processors: [batch]
exporters: [clickhouselogsexporter]
extraVolumeMounts:
- mountPath: /var/log/audit/audit.log
name: audit-log
- mountPath: /var/log/audit/aks.log
name: aks-log
- mountPath: /mnt/blob
name: blob-log
extraVolumes:
- hostPath:
path: /var/log/audit/audit.log
type: FileOrCreate
name: audit-log
- hostPath:
path: /var/log/audit/aks.log
type: FileOrCreate
name: aks-log
- name: blob-log
persistentVolumeClaim:
claimName: pvc-blob-fuse
See I am trying to search for newlog file name but it's still shows old file name. No result on file aks.log which I have configured above.
I can see the file in the pod
Pod: default/signoz-otel-collector-8cc98f667-b9grm | Container: signoz-otel-collector
~ $ ls /var/log/audit/
aks.log audit.log
cat conf/otel-collector-config.yaml
receivers:
filelog:
include:
- /var/log/audit/aks.log
operators:
- type: json_parser
start_at: end
nitya-signoz
03/11/2024, 3:35 AMPramod Sharma
03/11/2024, 3:35 AMPramod Sharma
03/11/2024, 3:36 AMPramod Sharma
03/11/2024, 3:36 AMnitya-signoz
03/11/2024, 3:37 AMstart_at: end
will only read new log lines, are new logs continiously written to the file ? else you can try start_at: beginning
Pramod Sharma
03/11/2024, 3:38 AMPramod Sharma
03/11/2024, 3:39 AMnitya-signoz
03/11/2024, 3:40 AMPramod Sharma
03/11/2024, 3:42 AMnitya-signoz
03/11/2024, 3:43 AM/var/log/audit/aks.log
file actually exists inside the container and is readable, sometimes there are permission issues.Pramod Sharma
03/11/2024, 3:47 AMnitya-signoz
03/11/2024, 3:47 AMcan you check the collector logs, it will print the name of files which it has started to watch.
can you check this ?
try restarting before checking, it prints in during the startPramod Sharma
03/11/2024, 3:51 AM"logs", "component": "fileconsumer", "path": "/var/log/audit/audit.log"}
{"level":"info","timestamp":"2024-03-11T03:48:08.778Z","caller":"service/service.go:73","msg":"Client started successfully"}
{"level":"info","timestamp":"2024-03-11T03:48:08.778Z","caller":"opamp/client.go:49","msg":"Ensuring collector is running","component":"opamp-server-client"}
Pramod Sharma
03/11/2024, 3:52 AMconfig:
receivers:
filelog:
include: [ /var/log/audit/audit.log, /mnt/PT1H.json ]
start_at: end
service:
pipelines:
logs:
receivers: [otlp, filelog, httplogreceiver/heroku]
processors: [batch]
exporters: [clickhouselogsexporter]
Pramod Sharma
03/11/2024, 3:53 AMreceivers:
filelog:
include:
- /var/log/audit/audit.log
- /mnt/PT1H.json
Pramod Sharma
03/11/2024, 3:54 AM/conf $ ls -l /mnt/PT1H.json/
total 20693
-rw-r--r-- 1 1000 nobody 146615851 Mar 9 07:27 PT1H.json
nitya-signoz
03/11/2024, 3:55 AM- /var/log/audit/audit.log
and try ?Pramod Sharma
03/11/2024, 3:55 AMstart_at: end
for the other file which is continuously writing.Pramod Sharma
03/11/2024, 3:56 AMPramod Sharma
03/11/2024, 3:56 AMnitya-signoz
03/11/2024, 3:57 AMPramod Sharma
03/11/2024, 3:58 AMnitya-signoz
03/11/2024, 3:59 AMPramod Sharma
03/11/2024, 4:00 AMPramod Sharma
03/11/2024, 4:00 AM~ $ ls -l /var/log/audit/audit.log
-rw-r--r-- 1 root root 3733586 Mar 11 03:59 /var/log/audit/audit.log
nitya-signoz
03/11/2024, 4:02 AMPramod Sharma
03/11/2024, 4:02 AMPramod Sharma
03/11/2024, 4:02 AMnitya-signoz
03/11/2024, 4:03 AMPramod Sharma
03/11/2024, 4:04 AMconfig:
receivers:
filelog:
include: [ /mnt/PT1H.json ]
start_at: end
Pramod Sharma
03/11/2024, 4:07 AM2024-03-11T04:04:54.026Z warn fileconsumer/file.go:61 finding files: no files match the configured criteria {"kind": "receiver", "name": "filelog", "data_type": "logs", "component": "fileconsumer"}
Pramod Sharma
03/11/2024, 4:08 AMPramod Sharma
03/11/2024, 4:08 AMnitya-signoz
03/11/2024, 4:10 AMPramod Sharma
03/11/2024, 4:11 AMPramod Sharma
03/11/2024, 4:20 AMPramod Sharma
03/11/2024, 4:20 AMPramod Sharma
03/11/2024, 4:21 AMnitya-signoz
03/14/2024, 1:37 PMPramod Sharma
03/15/2024, 12:46 AMPramod Sharma
03/15/2024, 12:47 AMAnurag Vishwakarma
06/03/2024, 8:38 AMfilelog/app:
include: [ /home/anuragvishwakarma/signoz/docker-container-logs/animals.log ]
start_at: beginning
---
pipelines:
logs:
receivers: [tcplog/docker, otlp, filelog/app, syslog]
processors: [batch]
exporters: [otlp, otlp/log]
nitya-signoz
06/03/2024, 9:25 AM/home/anuragvishwakarma/signoz/docker-container-logs/animals.log
file.Anurag Vishwakarma
06/03/2024, 9:52 AMnitya-signoz
06/03/2024, 9:57 AMAnurag Vishwakarma
06/03/2024, 10:01 AMnitya-signoz
06/03/2024, 10:06 AM