-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Not parsing, but regex is matching #1203
Comments
Please share your Fluent Bit configuration file or configmap. |
This my entire configmap with all configs:
|
@simonwh Not sure if this helps but for me, I've been struggling with similar issue when I was using fluent-bit sidecar in kubernetes to forward to another fluent-bit that runs on our nodes as Daemonsets which then sends to our Splunk - I was never able to see my logs even though my regex in rubular matched it perfectly. In the end, when I increased the As for
I was also doing this via the docker container and passing my log files and fluent-bit conf where I was able to see it was matching it fine which made me think my regex is fine in fluent-bit also. FYI the issue i had was #1214 I suspect my issue was something to do with me sending the output to another fluent-bit and then to Splunk so not sure if that was affecting it. |
Ah though after seeing the result picture, it looks like it is picking up your logs but not matching it so probably the |
@simonwh I had the same issue as long as I was using the following config:
it's actually missing an extra line at the end:
compared to the https://raw.githubusercontent.com/fluent/fluent-bit/master/conf/parsers.conf Additionally as I was getting compaints about multiple @timestamp fields, I had to add an extra filter: [FILTER] |
This issue is stale because it has been open 90 days with no activity. Remove stale label or comment or this will be closed in 5 days. Maintainers can add the |
This issue was closed because it has been stalled for 5 days with no activity. |
Bug Report
My nginx ingress controller logs are not getting parsed, even though they match the regex defined.
Rubular: https://rubular.com/r/KCWlI2X95tabLI
Log message
Parser
Result
Expected behavior
Expected parser to extract data from the log string.
Your Environment
Followed https://fluentbit.io/documentation/0.14/installation/kubernetes.html
I've been trying to make this work for hours on end... :-)
Is there anything I can do to:
Any hints appreciated!
The text was updated successfully, but these errors were encountered: