将特定的MDC字段追加到logstash日志中

时间:2018-11-30 13:31:17

标签: spring logging log4j logstash logback

我正在尝试将自定义字段添加到logback-spring.xml中的logstash附加程序中,

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<appender name="stash" class="net.logstash.logback.appender.LogstashSocketAppender">
        <host>xx.xx.xx.xx</host>
        <port>xxxxx</port>
        <encoder class="net.logstash.logback.encoder.LogstashEncoder">
            <includeMdcKeyName>myField</includeMdcKeyName>
        </encoder>
</appender>

<root level="info">
    <appender-ref ref="stash" />
</root>

</configuration>

它给了我错误:

  

线程“主”中的异常java.lang.IllegalStateException:检测到Logback配置错误:   ch.qos.logback.core.joran.spi.Interpreter@34:71中发生错误-[编码器]没有适用的操作,当前ElementPath为[[configuration] [appender] [encoder]]

当我尝试控制台附加程序时,我尝试打印该字段,如下面的示例所示。

<layout>
      <Pattern>%-4r [%thread] %-5level My Field: [%X{myField:--}] %msg%n</Pattern>
</layout>

您能告诉我udp appender做错了什么吗?谢谢你的建议。

1 个答案:

答案 0 :(得分:7)

您正在使用UDP appender,但没有encoder。您应该使用TCP AppenderLogstashTcpSocketAppender而不是LogstashSocketAppender):

<appender name="stash" class="net.logstash.logback.appender.LogstashTcpSocketAppender">
    <destination>xx.xx.xx.xx:xxxxx</destination>
    <encoder class="net.logstash.logback.encoder.LogstashEncoder">
        <includeMdcKeyName>myField</includeMdcKeyName>
    </encoder>
</appender>

看一下我创建的演示项目here

This code(科特琳):

MDC.put("mdc", "so53558553")

LOG.warn("Warn")

使用这样的logback-spring.xml

<appender name="logstash" class="net.logstash.logback.appender.LogstashTcpSocketAppender">
    <destination>localhost:5000</destination>
    <encoder class="net.logstash.logback.encoder.LogstashEncoder">
        <includeMdcKeyName>mdc</includeMdcKeyName>
    </encoder>
</appender>

在Logstash中产生这样的记录:

{
    "level_value" => 30000,
            "mdc" => "so53558553",
           "port" => 35450,
    "logger_name" => "by.dev.madhead.playgrounds.so53558553.SpringBootConsoleApplication",
           "host" => "172.17.0.1",
       "@version" => "1",
     "@timestamp" => 2018-12-03T01:16:28.793Z,
    "thread_name" => "main",
        "message" => "Warn",
          "level" => "WARN"
}

<code>mdc</code> field

如您所见,Logstash将mdc值视为LoggingEvent中的一个字段。

编辑

由于ELK配置错误,您可能看不到Kibana中的字段。我将Logstash pipiline配置(/etc/logstash/conf.d/01-input.conf)粘贴仅供参考(这是非常基本的):

input {
    tcp {
        port => 5000
        codec => json_lines
    }
}

output {
    elasticsearch {
        hosts => [ "localhost:9200" ]
        index => "logback-%{+YYYY.MM.dd}"
    }
}

然后我以logback-*模式配置了Kibana登录:

Create index pattern-01 Create index pattern-02

还有,瞧!

MDC fields in Kibana