使用Flume监听日志文件
使用Flume监听hive日志,并上传至HDFS中
实现步骤
- 在conf目录下创建flume-file-hdfs.conf文件
vim conf/flume-file-hdfs.conf
- 在flume-file-hdfs.conf写入如下内容
# Name the components on this agent
a2.sources = r2
a2.sinks = k2
a2.channels = c2
# Describe/configure the source
a2.sources.r2.type = exec
a2.sources.r2.command = tail -F /opt/hive-3.1.2/logs/hiveServer2.log
a2.sources.r2.shell = /bin/bash -c
# Describe the sink
a2.sinks.k2.type = hdfs
a2.sinks.k2.hdfs.path = hdfs://hadoop102:8020/flume/%Y%m%d/%H
#上传文件的前缀
a2.sinks.k2.hdfs.filePrefix = logs-
#是否按照时间滚动文件夹
a2.sinks.k2.hdfs.round = true
#多少时间单位创建一个新的文件夹
a2.sinks.k2.hdfs.roundValue = 1
#重新定义时间单位
a2.sinks.k2.hdfs.roundUnit = hour
#是否使用本地时间戳
a2.sinks.k2.hdfs.useLocalTimeStamp = true
#积攒多少个 Event 才 flush 到 HDFS 一次
a2.sinks.k2.hdfs.batchSize = 100
#设置文件类型,可支持压缩
a2.sinks.k2.hdfs.fileType = DataStream
#多久生成一个新的文件
a2.sinks.k2.hdfs.rollInterval = 30
#设置每个文件的滚动大小
a2.sinks.k2.hdfs.rollSize = 134217700
#文件的滚动与 Event 数量无关
a2.sinks.k2.hdfs.rollCount = 0
# Use a channel which buffers events in memory
a2.channels.c2.type = memory
a2.channels.c2.capacity = 1000
a2.channels.c2.transactionCapacity = 100
# Bind the source and sink to the channel
a2.sources.r2.channels = c2
a2.sinks.k2.channel = c2
- 运行flume
# 方法1
bin/flume-ng agent --conf conf/ --name a2 --conf-file conf/flume-file-hdfs.conf -Dflume.root.logger=INFO,console
# 方法2
bin/flume-ng agent -c conf/ -n a2 -f conf/flume-file-hdfs.conf -Dflume.root.logger=INFO,console
- 报错解决
错误详情:
[ERROR - org.apache.flume.sink.hdfs.HDFSEventSink.process(HDFSEventSink.java:459)] process failed
java.lang.NoSuchMethodError: com.google.common.base.Preconditions.checkArgument(ZLjava/lang/String;Ljava/lang/Object;)V
解决:
这是因为flume内依赖的guava.jar和hadoop内的版本不一致造成的。
- hive中guava.jar位置:/$HIVE_HOME/lib/
- hadoop中guava.jar位置:/$HADOOP_HOME/share/hadoop/common/lib/
rm -f /opt/flume-1.9.0/lib/guava-11.0.2.jar
cp -f /$HADOOP_HOME/share/hadoop/common/lib/guava-27.0-jre.jar /opt/flume-1.9.0/lib/
操作hive使其产生日志
查看hadoop的/flume目录下,是否有存储收集到的日志
