如何通过unix sock将haproxy信息日志发送到rsyslog?

时间:2020-12-28 20:42:27

标签: linux haproxy rsyslog unix-socket

嗨,我正在尝试配置 haproxy/rsyslog,以便只有 haproxy info 日志通过 unix sock 发送到 ryslog。

这是我的配置:

haproxy 配置

frontend MY_FRONT_END
    log 127.0.0.1 /var/log/haproxy/dev/log info
    bind *:12080
    default_backend HTTP_BACKEND

rsyslog 配置

$ModLoad imuxsock
$InputUnixListenSocketCreatePath on
$InputUnixListenSocketHostName localhost
$AddUnixListenSocket /var/log/haproxy/dev/log
*.info /var/log/haproxy/access.log

然而,我在日志中看到的不仅仅是 haproxy 日志,日志包含所有与 haproxy 无关的信息(前三个日志行)

Dec 28 20:28:12 localhost sudo:   testaccount : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin/sh -c ip addr show
Dec 28 20:28:12 localhost sudo:   testaccount : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin/sh -c ip route
Dec 28 20:28:13 localhost sudo:   testaccount : TTY=pts/1 ; PWD=/var/log/haproxy ; USER=root ; COMMAND=/sbin/service haproxy restart
Dec 28 20:28:13 localhost polkitd[59350]: Registered Authentication Agent for unix-process:32995:43061437 (system bus name :1.28346 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_CA.UTF-8)
Dec 28 20:28:13 localhost systemd: Stopping HAProxy Load Balancer...
Dec 28 20:28:13 localhost haproxy: [WARNING] 362/202813 (30706) : Exiting Master process...
Dec 28 20:28:13 localhost haproxy: [NOTICE] 362/202813 (30706) : haproxy version is 2.2.6
Dec 28 20:28:13 localhost haproxy: [NOTICE] 362/202813 (30706) : path to executable is /usr/local/sbin/haproxy
Dec 28 20:28:13 localhost haproxy: [ALERT] 362/202813 (30706) : Current worker #1 (30708) exited with code 143 (Terminated)
Dec 28 20:28:13 localhost haproxy: [WARNING] 362/202813 (30706) : All workers exited. Exiting... (0)
Dec 28 20:28:13 localhost systemd: Starting HAProxy Load Balancer...
Dec 28 20:28:13 localhost haproxy[33016]: Proxy MY_FRONT_END started.
Dec 28 20:28:13 localhost haproxy[33016]: Proxy HTTP_BACKEND started.
Dec 28 20:28:13 localhost haproxy: [NOTICE] 362/202813 (33016) : New worker #1 (33018) forked
Dec 28 20:28:13 localhost systemd: Started HAProxy Load Balancer.
Dec 28 20:28:13 localhost polkitd[59350]: Unregistered Authentication Agent for unix-process:32995:43061437 (system bus name :1.28346, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_CA.UTF-8) (disconnected from bus)
Dec 28 20:28:13 localhost sudo:   testaccount : TTY=pts/1 ; PWD=/var/log/haproxy ; USER=root ; COMMAND=/sbin/service rsyslog restart

我如何配置以实现此目的(仅通过 unix sock 将 haproxy 信息日志发送到 rsyslog)?

1 个答案:

答案 0 :(得分:1)

正确的答案可能是使用规则集只包含 imuxsock 部分,但我不知道如何在旧语法中做到这一点。

一个更简单但不太理想的解决方案是检查日志项中的程序名。还匹配严重性级别 0 到 6(紧急到信息)给出结果:

if $programname=="haproxy" and $syslogseverity<=6 then /var/log/haproxy/access.log

我不确定,但您也可以尝试在文件中更早的位置,在标准日志代码之前移动您的配置,但是您的 haproxy 日志也会出现在标准日志中,除非您使用类似

*.info /var/log/haproxy/access.log
*.* stop

其中 stop 停止对该输入的进一步处理。

相关问题