Skip to content

Logs duplicated when fluentbit read from mountvolume  #9460

Closed as not planned


Bug Report

Describe the bug

Pods of fluentbit duplicate the same log from the same path with the tail plugin

To Reproduce

  • kubernetes

  • fluentbit helm chart (daemonset)

  • elastic search

  • Steps to reproduce the problem:
    In my kubernetes cluster are 3 nodes. So i have 3 fluentbit pods that are running

In the values.yaml of the fluentbit chart, i configured a volume and volumemount

In that path are logs.
When I read with fluentbit the logs, with tail plugin, and output them with es.

I have the replication of logs (as number of pods of fluentbit)

if is 2 pods - duplicated. I tried with only 1 fluentbit pod, and they did not duplicated!

Expected behavior
The logs will not be duplicated in the elasticsearch/,kibana



  • name: volume
    claimName: x-pvc


  • name: volume
    subPath: /logs/x/
    mountPath: /logs/x/
  • name: volume
    subPath: l/ogs/y/
    mountPath: /logs/y/

service: |

    Daemon Off
    Flush x
    Log_Level x
    Parsers_File /fluent-bit/etc/parsers.conf
    Parsers_File /fluent-bit/etc/conf/custom_parsers.conf
    HTTP_Server On
    HTTP_Listen x
    HTTP_Port x
    Health_Check On

inputs: |

    Name tail
    Path /logs/y*
    Tag logs
    Mem_Buf_Limit 100MB
    Skip_Long_Lines Off
    Refresh_Interval 30
    Path_Key filename
    Skip_Empty_Lines On

    Name tail
    Path /logs/x/*
    Tag logs
    Mem_Buf_Limit 100MB
    Skip_Long_Lines Off
    Refresh_Interval 30
    Path_Key filename
    Skip_Empty_Lines On

filters: |

    name multiline
    match *
    multiline.key_content log
    multiline.parser java

    Name modify
    Match *
    Add cluster_name $var
    Add cluster_id $var

outputs: |

    Name es
    Match logs
    Host ip
    http_user     x
    http_passwd   y
    tls On
    tls.verify off
    Logstash_Format off
    Index logs
    Logstash_DateFormat %Y.%m
    Suppress_Type_Name On

customParsers: |

    Name docker_no_time
    Format json
    Time_Keep Off
    Time_Key time
    Time_Format %Y-%m-%dT%H:%M:%S.%L

    Name log_parser
    Format regex
    Regex \[(?<timestamp>.*)\]\[(?<correlationID>.*)\]\[(?<severity>.*)\]\[(?<class>.*)\]\[(?<thread>.*)\] (?<text>.*)

    Name equipment_parser
    Format regex
    Regex ^(?<log>.*)$

    Name kafka_parser
    Format regex
    Regex \[(?<timestamp>.*)\] (?<severity>FATAL|ERROR|WARN|INFO|DEBUG|TRACE) (?<text>.*)

    Name postgres_parser
    Format regex
    Regex ^(?<timestamp>.{23}).*(?<severity>FATAL|ERROR|WARN|INFO|DEBUG|TRACE|LOG|DETAIL): (?<text>.*)

Additional context
I try to show the logs from a specifc path from a volume!



No one assigned


    No type


    No projects


    No milestone


    None yet


    No branches or pull requests

    Issue actions