로그용 TCP Agent 프록시 (TCP Agent proxy for logs)
Datadog Agent가 로그를 TCP 및 SOCKS5 프록시를 통해 보내도록 구성하는 방법을 알려드릴게요. 상세한 HAProxy와 NGINX 구성 예시도 함께 살펴봐요.
출처: 문서
본문
참고(경고): TCP 로그 수집은 지원되지 않아요. TCP를 사용할 때 Datadog은 전달 또는 신뢰성 보장을 제공하지 않으며 로그 데이터가 공지 없이 손실될 수 있어요. 안정적인 수집을 위해서는 HTTP intake 엔드포인트, 공식 Datadog Agent 또는 forwarder 통합을 대신 사용하세요. 자세한 내용은 로그 수집을 참고하세요.
us3.datadoghq.com, us5.datadoghq.com, app.ddog-gov.com, us2.ddog-gov.com, ap1.datadoghq.com, ap2.datadoghq.com, uk1.datadoghq.com Datadog 사이트를 사용하는 사용자를 위한 중요 참고사항
선택한 Datadog 사이트({% placeholder "user-datadog-site-name" /%})에서는 TCP를 사용할 수 없어요. 자세한 내용은 지원팀에 문의하세요.
app.datadoghq.com Datadog 사이트를 사용하는 사용자를 위한 중요 참고사항
개요 (Overview)
로그 수집에는 Datadog Agent v6.0+가 필요해요. 이전 버전의 Agent에는 log collection 인터페이스가 포함되어 있지 않아요.
Agent v6.14/v7.14부터 Datadog은 HTTPS 전송을 사용하고 강제할 것을 권장해요(참고: 로그 전송을 위한 Agent). 로그에 HTTPS 전송을 사용한다면 agent proxy 문서를 참고해 다른 데이터 유형과 동일한 프록시 설정 집합을 사용하세요.
TCP — TCP 전송에 프록시를 사용한다면 datadog.yaml 구성 파일에서 다음 파라미터로 Datadog Agent가 TCP를 통해 프록시로 로그를 보내도록 구성하세요:
logs_config:
logs_dd_url: "<PROXY_ENDPOINT>:<PROXY_PORT>"
logs_no_ssl: true
위 파라미터는 다음 환경 변수로도 설정할 수 있어요:
DD_LOGS_CONFIG_LOGS_DD_URLDD_LOGS_CONFIG_LOGS_NO_SSL
참고: logs_no_ssl 파라미터는 Agent가 SSL 인증서의 호스트네임(<YOUR_TCP_ENDPOINT>)과 프록시 호스트네임 간의 불일치를 무시하도록 하는 데 필요해요. 프록시와 Datadog intake 엔드포인트 사이에는 SSL 암호화 연결을 사용하는 것이 좋아요.
-
그런 다음 프록시가
<PROXY_PORT>에서 수신하고 받은 로그를 전달하도록 구성하세요. <YOUR_DATADOG_SITE>의 경우 포트 <YOUR_TCP_ENDPOINT_PORT>에서 <YOUR_TCP_ENDPOINT>를 사용하고 SSL 암호화를 활성화하세요. -
SSL 암호화를 위한 TLS 암호화용
CA certificates를 다음 명령어로 다운로드하세요:sudo apt-get install ca-certificates(Debian, Ubuntu)yum install ca-certificates(CentOS, Redhat)
그리고 /etc/ssl/certs/ca-certificates.crt(Debian, Ubuntu) 또는 /etc/ssl/certs/ca-bundle.crt(CentOS, Redhat)에 있는 인증서 파일을 사용하세요.
SOCKS5 — SOCKS5 프록시 서버로 Datadog 계정에 로그인 로그를 보내려면 datadog.yaml 구성 파일에서 다음 설정을 사용하세요:
logs_config:
socks5_proxy_address: "<MY_SOCKS5_PROXY_URL>:<MY_SOCKS5_PROXY_PORT>"
위 파라미터는 다음 환경 변수로도 설정할 수 있어요:
DD_LOGS_CONFIG_SOCKS5_PROXY_ADDRESS
TCP 프록시 예시 (Examples of TCP proxy)
HAProxy를 로그용 TCP 프록시로 사용하기
이 예시는 HAProxy가 설치되고 포트 10514에서 수신하는 서버에 Agent가 로그를 TCP로 보내고, 다시 Datadog으로 로그를 전달하도록 구성하는 방법을 설명해요.
agent ---> haproxy ---> Datadog
Agent와 HAProxy 사이에서는 암호화가 비활성화되며, HAProxy는 데이터를 Datadog으로 보내기 전에 암호화하도록 구성돼요.
Agent 구성
datadog.yaml Agent 구성 파일을 편집하고 logs_no_ssl을 true로 설정하세요. HAProxy가 트래픽을 전달하지 않고 Datadog 백엔드가 아니므로 동일한 인증서를 사용할 수 없기 때문에 이 설정이 필요해요.
참고: HAProxy가 데이터를 암호화하도록 구성되어 있으므로 logs_no_ssl이 true로 설정될 수 있어요. 그 외의 경우에는 이 파라미터를 true로 설정하지 마세요.
logs_config:
force_use_tcp: true
logs_dd_url: "<PROXY_SERVER_DOMAIN>:10514"
logs_no_ssl: true
HAProxy 구성
HAProxy는 Datadog에 연결이 가능한 호스트에 설치해야 해요. 아직 구성하지 않았다면 다음 구성 파일을 사용하세요.
app.datadoghq.com Datadog 사이트를 사용하는 사용자를 위한 중요 참고사항
# Basic configuration
global
log 127.0.0.1 local0
maxconn 4096
stats socket /tmp/haproxy
# Some sane defaults
defaults
log global
option dontlognull
retries 3
option redispatch
timeout client 5s
timeout server 5s
timeout connect 5s
# This declares a view into HAProxy statistics, on port 3833
# You do not need credentials to view this page and you can
# turn it off once you are done with setup.
listen stats
bind *:3833
mode http
stats enable
stats uri /
# This section is to reload DNS Records
# Replace <DNS_SERVER_IP> and <DNS_SECONDARY_SERVER_IP> with your DNS Server IP addresses.
# For HAProxy 1.8 and newer
resolvers my-dns
nameserver dns1 <DNS_SERVER_IP>:53
nameserver dns2 <DNS_SECONDARY_SERVER_IP>:53
resolve_retries 3
timeout resolve 2s
timeout retry 1s
accepted_payload_size 8192
hold valid 10s
hold obsolete 60s
# This declares the endpoint where your Agents connects for
# sending Logs (e.g the value of "logs.config.logs_dd_url")
frontend logs_frontend
bind *:10514
mode tcp
option tcplog
default_backend datadog-logs
# This is the Datadog server. In effect any TCP request coming
# to the forwarder frontends defined above are proxied to
# Datadog's public endpoints.
backend datadog-logs
balance roundrobin
mode tcp
option tcplog
server datadog agent-intake.logs.datadoghq.com:10516 ssl verify required ca-file /etc/ssl/certs/ca-certificates.crt check port 10516
참고: 다음 명령어로 인증서를 다운로드하세요:
sudo apt-get install ca-certificates(Debian, Ubuntu)yum install ca-certificates(CentOS, Redhat)
성공하면 파일은 CentOS, Redhat에서 /etc/ssl/certs/ca-bundle.crt에 위치해요.
HAProxy 구성이 준비되면 HAProxy를 리로드하거나 재시작할 수 있어요. app.datadoghq.com이 다른 IP로 장애 조치되는 경우를 대비해 HAProxy의 DNS 캐시를 강제로 새로고침하도록 10분마다 HAProxy를 리로드하는 cron 작업을 두는 것을 권장해요(예: service haproxy reload).
app.datadoghq.eu Datadog 사이트를 사용하는 사용자를 위한 중요 참고사항
# Basic configuration
global
log 127.0.0.1 local0
maxconn 4096
stats socket /tmp/haproxy
# Some sane defaults
defaults
log global
option dontlognull
retries 3
option redispatch
timeout client 5s
timeout server 5s
timeout connect 5s
# This declares a view into HAProxy statistics, on port 3833
# You do not need credentials to view this page and you can
# turn it off once you are done with setup.
listen stats
bind *:3833
mode http
stats enable
stats uri /
# This section is to reload DNS Records
# Replace <DNS_SERVER_IP> and <DNS_SECONDARY_SERVER_IP> with your DNS Server IP addresses.
# For HAProxy 1.8 and newer
resolvers my-dns
nameserver dns1 <DNS_SERVER_IP>:53
nameserver dns2 <DNS_SECONDARY_SERVER_IP>:53
resolve_retries 3
timeout resolve 2s
timeout retry 1s
accepted_payload_size 8192
hold valid 10s
hold obsolete 60s
# This declares the endpoint where your Agents connects for
# sending Logs (e.g the value of "logs.config.logs_dd_url")
frontend logs_frontend
bind *:10514
mode tcp
default_backend datadog-logs
# This is the Datadog server. In effect any TCP request coming
# to the forwarder frontends defined above are proxied to
# Datadog's public endpoints.
backend datadog-logs
balance roundrobin
mode tcp
option tcplog
server datadog agent-intake.logs.datadoghq.eu:443 ssl verify required ca-file /etc/ssl/certs/ca-bundle.crt check port 443
다음 명령어로 인증서를 다운로드하세요:
sudo apt-get install ca-certificates(Debian, Ubuntu)yum install ca-certificates(CentOS, Redhat)
성공하면 파일은 CentOS, Redhat에서 /etc/ssl/certs/ca-bundle.crt에 위치해요.
HAProxy 구성이 준비되면 HAProxy를 리로드하거나 재시작할 수 있어요. app.datadoghq.eu이 다른 IP로 장애 조치되는 경우를 대비해 HAProxy의 DNS 캐시를 강제로 새로고침하도록 10분마다 HAProxy를 리로드하는 cron 작업을 두는 것을 권장해요(예: service haproxy reload).
NGINX를 로그용 TCP 프록시로 사용하기
Agent 구성
datadog.yaml Agent 구성 파일을 편집하고 logs_config.logs_dd_url을 Datadog에 직접 연결하는 대신 새로 만든 프록시를 사용하도록 설정하세요:
logs_config:
force_use_tcp: true
logs_dd_url: myProxyServer.myDomain:10514
참고: NGINX가 트래픽을 Datadog으로 전달하고 트래픽을 복호화하거나 암호화하지 않으므로 logs_no_ssl 파라미터는 변경하지 마세요.
NGINX 구성
이 예시에서 nginx.conf는 Agent 트래픽을 Datadog으로 프록시하는 데 사용할 수 있어요. 이 구성의 마지막 server 블록은 내부 평문 로그가 프록시와 Datadog의 로그 intake API 엔드포인트 사이에서 암호화되도록 TLS 래핑을 수행해요:
app.datadoghq.com Datadog 사이트를 사용하는 사용자를 위한 중요 참고사항
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;
events {
worker_connections 1024;
}
# TCP Proxy for Datadog Agent
stream {
server {
listen 10514; #listen for logs
proxy_ssl on;
proxy_pass agent-intake.logs.datadoghq.com:10516;
}
}
app.datadoghq.eu Datadog 사이트를 사용하는 사용자를 위한 중요 참고사항
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;
events {
worker_connections 1024;
}
# TCP Proxy for Datadog Agent
stream {
server {
listen 10514; #listen for logs
proxy_ssl on;
proxy_pass agent-intake.logs.datadoghq.eu:443;
}
}
더 알아보기 (Learn more)
도움이 되는 추가 문서, 링크, 글: