Fluent Bit Batching
Capturing All HTTP Traffic with Fluent Bit
Overview
Why Fluent Bit?
Architecture
┌──────────┐ forward ┌──────────────┐ parse ┌──────────┐
│ Qtap │──────────▸│ Fluent Bit │─────────▸│ Filter & │
│ (eBPF) │ port │ (Batching) │ │ Route │
└──────────┘ 24224 └──────────────┘ └────┬─────┘
│
┌──────────────┴──────────────┐
▼ ▼
┌──────────┐ ┌──────────┐
│ S3 │ │ Stdout / │
│ (MinIO, │ │ Other │
│ AWS, GCS)│ └──────────┘
└──────────┘Docker Deployment
Step 1: Create Qtap Configuration
Step 2: Create Fluent Bit Configuration
Step 3: Create Docker Compose
Step 4: Start and Validate
Production Outputs
AWS S3
MinIO (S3-Compatible)
AWS CloudWatch Logs
Multiple Destinations
Filtering and Optimization
Capture Only Errors (4xx/5xx)
Filter by Domain
Exclude Noisy Processes
Filter in Fluent Bit
Monitoring and Troubleshooting
Verify Qtap is Capturing Traffic
Verify Fluent Bit is Processing
Common Issues
Alternative: File Tailing Approach
Best Practices
Summary
Last updated