采用架构 Nginx+Promtail+Loki+Grafana 做个简单的 Nginx 日志展示
本文无安装,简要点出配置需求。Nginx 用编译安装(本文不做叙述),Promtail 和 Loki 都选用二进制的方式进行安装,直接下载对应版本的二进制文件,解压后指定配置文件启动即可。
promtail 配置文件内容:
http_listen_port: 9080
grpc_listen_port: 0
filename: /tmp/positions.yaml
- url: http://localhost:3100/loki/api/v1/push
- job_name: nginx
- replace:
expression: '(?:[0-9]{1,3}\.){3}([0-9]{1,3})'
replace: '***'
- targets:
- localhost
job: nginx_access_log
host: expatsxxxxs
agent: promtail
__path__: /var/log/nginx/expatshxxxxs.access.log
日志收集工作完成后,在 Nginx 中需要修改日志格式,修改 Nginx 的日志格式为 Json 格式,配置如下:
log_format json_analytics escape=json '{'
'"msec": "$msec", ' # request unixtime in seconds with a milliseconds resolution
'"connection": "$connection", ' # connection serial number
'"connection_requests": "$connection_requests", ' # number of requests made in connection
'"pid": "$pid", ' # process pid
'"request_id": "$request_id", ' # the unique request id
'"request_length": "$request_length", ' # request length (including headers and body)
'"remote_addr": "$remote_addr", ' # client IP
'"remote_user": "$remote_user", ' # client HTTP username
'"remote_port": "$remote_port", ' # client port
'"time_local": "$time_local", '
'"time_iso8601": "$time_iso8601", ' # local time in the ISO 8601 standard format
'"request": "$request", ' # full path no arguments if the request
'"request_uri": "$request_uri", ' # full path and arguments if the request
'"args": "$args", ' # args
'"status": "$status", ' # response status code
'"body_bytes_sent": "$body_bytes_sent", ' # the number of body bytes exclude headers sent to a client
'"bytes_sent": "$bytes_sent", ' # the number of bytes sent to a client
'"http_referer": "$http_referer", ' # HTTP referer
'"http_user_agent": "$http_user_agent", ' # user agent
'"http_x_forwarded_for": "$http_x_forwarded_for", ' # http_x_forwarded_for
'"http_host": "$http_host", ' # the request Host: header
'"server_name": "$server_name", ' # the name of the vhost serving the request
'"request_time": "$request_time", ' # request processing time in seconds with msec resolution
'"upstream": "$upstream_addr", ' # upstream backend server for proxied requests
'"upstream_connect_time": "$upstream_connect_time", ' # upstream handshake time incl. TLS
'"upstream_header_time": "$upstream_header_time", ' # time spent receiving upstream headers
'"upstream_response_time": "$upstream_response_time", ' # time spend receiving upstream body
'"upstream_response_length": "$upstream_response_length", ' # upstream response length
'"upstream_cache_status": "$upstream_cache_status", ' # cache HIT/MISS where applicable
'"ssl_protocol": "$ssl_protocol", ' # TLS protocol
'"ssl_cipher": "$ssl_cipher", ' # TLS cipher
'"scheme": "$scheme", ' # http or https
'"request_method": "$request_method", ' # request method
'"server_protocol": "$server_protocol", ' # request protocol, like HTTP/1.1 or HTTP/2.0
'"pipe": "$pipe", ' # "p" if request was pipelined, "." otherwise
'"gzip_ratio": "$gzip_ratio", '
'"http_cf_ray": "$http_cf_ray",'
'"geoip_country_code": "$geoip_country_code"'
由于需要在 nginx 中添加 geoip 模块,所以我们要安装 geoip
yum -y install GeoIP GeoIP-data GeoIP-devel
重新编译 Nginx,通过 --with-http_geoip_module 添加 nginx 的 geoip 模块
编译完成后,在 objs 目录下生成新的 Nginx 可执行文件,替换原先的,通过 kill -USR2 信号,升级 Nginx。
此时配置的 log_format 不会再报错 geoip 指令找不到,配置完成后,配置网站的 access 日志,引用刚才配置的 json 格式的 log_format。
此时的日志格式已经转为 JSON 格式,接着安装 grafana,最快捷的方式,通过 docker 直接起一个
docker run -d -p 3000:3000 grafana/grafana
启动后,通过 admin/admin 默认用户名密码登录,登陆后提示重置密码,之后进入 grafana 界面直接添加数据源 loki
先通过 explore 查询,日志是否存入 loki
可以看到,日志已经存入 loki ,接着添加 Dashboard,通过 ID 导入
grafana-cli plugins install grafana-worldmap-panel
标签:http,展示,time,request,Nginx,upstream,日志 From: https://blog.51cto.com/u_15932009/6176461