深色模式
Promtail 发送日志到 Loki
Promtail 是 Loki 官方采集端,像 Prometheus 一样通过
scrape_configs抓取日志并加标签。本文配置抓取/var/log下的文件发到 Loki。
适用环境
bash
# 确认 Loki 可达
curl -s http://localhost:3100/ready
# 确认日志文件存在
ls -l /var/log/nginx/ /var/log/syslog1
2
3
4
2
3
4
操作步骤
1. 编写 promtail-config.yaml
yaml
server:
http_listen_port: 9080
clients:
- url: http://localhost:3100/loki/api/v1/push
scrape_configs:
- job_name: system
static_configs:
- targets: [localhost]
labels:
job: varlogs
app: nginx
__path__: /var/log/nginx/*.log
- job_name: syslog
static_configs:
- targets: [localhost]
labels:
job: syslog
__path__: /var/log/syslog1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
2. 启动
bash
docker run -d --name promtail \
-v $(pwd)/promtail-config.yaml:/etc/promtail/config.yml \
-v /var/log:/var/log:ro \
grafana/promtail:latest -config.file=/etc/promtail/config.yml1
2
3
4
2
3
4
DANGER
__path__ 是 Promtail 的特殊字段,指向要抓的文件;写错路径会导致采集不到且无报错,先 docker logs promtail 确认 targets 已加载。
验证
bash
# 确认 Promtail 已发现 target
curl -s http://localhost:9080/targets | head
# 在 Loki 查询刚打的标签
curl -s 'http://localhost:3100/loki/api/v1/label/job/values'1
2
3
4
5
2
3
4
5
常见坑
WARNING
标签一旦定下就影响索引成本。app、job 用低基数值;避免用路径中的动态部分(如日期)作标签。
WARNING
多行日志(如 Java 堆栈)需要 pipeline_stages 里的 multiline 配置,否则每行被当独立事件,堆栈被打散。