我设置了一个代理,用于接收 UDP 流量以平衡内部 DNS。它正确地将流量路由到我的后端 DNS 服务器,但我似乎无法使日志格式正常工作。
我收到的错误是:
nginx[32103]: nginx: [emerg] unknown log format "dns" in /etc/nginx/nginx.conf:23
我在 http 块中设置了日志格式,并在stream-->server
块中对其进行了定义。我尝试在块中设置 log_format stream-->server
,但所有变量都不起作用。
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;
events {
worker_connections 768;
# multi_accept on;
}
stream {
upstream dns_servers {
least_conn;
server 192.168.3.222:53 fail_timeout=10s;
server 192.168.70.80:53 fail_timeout=10s;
server 192.168.70.81:53 fail_timeout=10s;
}
server {
listen 53 udp;
proxy_pass dns_servers;
proxy_responses 1;
proxy_timeout 1s;
access_log /var/log/nginx/access.log dns;
}
}
http {
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
include /etc/nginx/mime.types;
default_type application/octet-stream;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
ssl_prefer_server_ciphers on;
log_format dns '[$time_local] | $remote_addr | $remote_user | $server_name $host to: $upstream_addr | '
'"$request" | $status | upstream_response_time $upstream_response_time msec '
'$msec | request_time $request_time';
access_log /var/log/nginx/access.log dns;
error_log /var/log/nginx/error.log;
}
我尝试将其放置log_format
在流块中,但是我开始得到unknown <variable name> variable
。
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;
events {
worker_connections 768;
# multi_accept on;
}
stream {
log_format dns '[$time_local] | $remote_addr | $remote_user | $server_name $host to: $upstream_addr | '
'"$request" | $status | upstream_response_time $upstream_response_time msec '
'$msec | request_time $request_time';
upstream dns_servers {
least_conn;
server 192.168.3.222:53 fail_timeout=10s;
server 192.168.70.80:53 fail_timeout=10s;
server 192.168.70.81:53 fail_timeout=10s;
}
server {
listen 53 udp;
proxy_pass dns_servers;
proxy_responses 1;
proxy_timeout 1s;
access_log /var/log/nginx/access.log dns;
}
}
这根本不是一个 Web 服务器。它仅充当 DNS 流量的代理。如何正确让日志记录正常运行?这是除流块之外的默认 nginx.conf 文件。
答案1
log_format
供 s使用的一个指令stream
server
必须在stream
块中声明,而不是在http
块中声明。这些指令彼此独立。请参阅文档stream
log_format
。
答案2
我找到了答案。我找到了正确的变量,并stream
按照以下方式将所有内容放入我的块中:本教程。
这是我的新stream
区块:
stream {
log_format dns '$remote_addr - - [$time_local] $protocol $status $bytes_sent $bytes_received $session_time "$upstream_addr"';
access_log /var/log/nginx/access.log dns;
error_log /var/log/nginx/error.log;
upstream dns_servers {
least_conn;
server 192.168.3.222:53 fail_timeout=10s;
server 192.168.70.80:53 fail_timeout=10s;
server 192.168.70.81:53 fail_timeout=10s;
}
server {
listen 53 udp;
proxy_pass dns_servers;
proxy_responses 1;
proxy_timeout 1s;
}
}
您可以看到它确实正在记录:
192.168.2.47 - - [11/Nov/2020:15:29:34 +0000] UDP 200 97 33 0.018 "192.168.3.222:53"
192.168.2.47 - - [11/Nov/2020:15:29:34 +0000] UDP 200 53 37 0.031 "192.168.70.80:53"
192.168.2.47 - - [11/Nov/2020:15:29:34 +0000] UDP 200 142 42 0.046 "192.168.3.222:53"
192.168.2.47 - - [11/Nov/2020:15:29:34 +0000] UDP 200 62 46 0.030 "192.168.70.80:53"
192.168.2.47 - - [11/Nov/2020:15:29:34 +0000] UDP 200 142 38 0.039 "192.168.70.81:53"