使用Logback SSLSocketAppender时,Splunk日志显示为十六进制

时间:2019-03-02 09:10:04

标签: java ssl logback splunk

我正在尝试使用Splunk收集我的应用程序的日志。我在端口6514上设置了TCP数据输入(在此端口上启用了SSL)。从Java应用程序,我可以连接到端口并发送日志。但是,当我在Splunk网站上检查这些日志时,它显示为十六进制格式。

登录配置

<configuration debug="true">

 <appender name="console" class="ch.qos.logback.core.ConsoleAppender">
    <encoder>
        <pattern>%date{ISO8601} [%thread] [%cyan(%C.%M\(\))] [%highlight(%level)] : %msg - %ex{short} %n</pattern>
    </encoder>
</appender>

<appender name="sslsocket" class="ch.qos.logback.classic.net.SSLSocketAppender">
    <remoteHost>127.0.0.1</remoteHost>
    <port>6514</port>
    <queueSize>20</queueSize>
    <reconnectionDelay>20</reconnectionDelay>
    <ssl>
        <trustStore>
            <location>file:///path/to/truststore.jks</location>
            <password>truststorepassword</password>
        </trustStore>
    </ssl>
</appender>

<logger name="splunk.secure.logger" additivity="false" level="INFO">
    <appender-ref ref="sslsocket"/>
</logger>

<root level="DEBUG">
    <appender-ref ref="console" />
</root>
</configuration>

用法

公共课程入门版{

private final static org.slf4j.Logger logger = LoggerFactory.getLogger("splunk.secure.logger");


public static void main(String[] args) {
    logger.info("Testing SSL Socket Appender Log");
}

}

将调试输出登录回控制台

11:00:04,701 |-INFO in ch.qos.logback.core.joran.action.AppenderAction - 
About to instantiate appender of type 
[ch.qos.logback.classic.net.SSLSocketAppender]
11:00:04,720 |-INFO in ch.qos.logback.core.joran.action.AppenderAction - 
Naming appender as [sslsocket]
11:00:04,763 |-INFO in 
ch.qos.logback.core.joran.action.NestedComplexPropertyIA - Assuming default type 
[ch.qos.logback.core.net.ssl.SSLConfiguration] for [ssl] property
11:00:04,776 |-INFO in ch.qos.logback.core.joran.action.NestedComplexPropertyIA - Assuming default type [ch.qos.logback.core.net.ssl.KeyStoreFactoryBean] for 
[trustStore] property
11:00:06,035 |-INFO in ch.qos.logback.classic.net.SSLSocketAppender[sslsocket] - SSL protocol 'SSL' provider 'SunJSSE version 1.8'
11:00:06,045 |-INFO in ch.qos.logback.classic.net.SSLSocketAppender[sslsocket] - trust store of type 'JKS' provider 'SUN version 1.8': file:///path/to/truststore.jks
11:00:06,046 |-INFO in ch.qos.logback.classic.net.SSLSocketAppender[sslsocket] - trust manager algorithm 'PKIX' provider 'SunJSSE version 1.8'
11:00:06,063 |-INFO in ch.qos.logback.classic.net.SSLSocketAppender[sslsocket] - secure random algorithm 'SHA1PRNG' provider 'SUN version 1.8'
11:00:06,556 |-INFO in ch.qos.logback.classic.joran.action.LoggerAction - Setting level of logger [splunk.secure.logger] to INFO
11:00:06,557 |-INFO in ch.qos.logback.classic.joran.action.LoggerAction - Setting additivity of logger [splunk.secure.logger] to false
11:00:06,564 |-INFO in ch.qos.logback.core.joran.action.AppenderRefAction - 
Attaching appender named [sslsocket] to Logger[splunk.secure.logger]

SPLUNK WEB接收到什么

Time    Event

19年3月2日 9:48:45.000 AM
\ xAC \ xED \ x00 host = 127.0.0.1 source = tcp:6514 sourcetype = logback

摘要

从上面看来,这似乎不是连接问题,因为Splunk正在侦听端口6514并能够捕获输入,但是捕获的输入显示为十六进制,而不是正常显示。

当我使用普通的com.splunk.logging.TcpAppender时,我的日志会正确显示在splunk上。

  1. 还有其他可能错过的配置
  2. 使用com.splunk.logging.TcpAppender时是否可以启用SSL
  3. 是否有专用的Splunk SSL附加程序可代替ch.qos.logback.classic.net.SSLSocketAppender
  4. 欢迎其他任何建议。

1 个答案:

答案 0 :(得分:0)

我必须切换到log4j才能解决此问题。使用log4j中的以下配置,日志可以正确显示在splunk网站上。

    public static async Task<ExceptionResponse> ExceptionResponse(this HttpResponseMessage httpResponseMessage)
    {
        string responseContent = await httpResponseMessage.Content.ReadAsStringAsync();
        ExceptionResponse exceptionResponse = JsonConvert.DeserializeObject<ExceptionResponse>(responseContent);
        return exceptionResponse;
    }
}

public class ExceptionResponse
{
    public string Message { get; set; }
    public string ExceptionMessage { get; set; }
    public string ExceptionType { get; set; }
    public string StackTrace { get; set; }
    public ExceptionResponse InnerException { get; set; }
}