1.创建配置文件目录
mkdir -p /usr/local/logstash/etc/conf.d
2.编写配置文件
input {
file{
path => ["/var/log/nginx/access.log"]
type => "test"
}
#syslog、redis、filebeats
}
#filter
output {
file{
path => ["/logstash/nginx"] #存放日志位置
}
elasticsearch {
hosts => ["192.168.89.150","192.168.89.151","192.168.89.152"] #集群ip
index => ["%{type}-%{+YYYY.MM.dd}"]
}
}
3.启动
cd /usr/local/logstash/ && nohup bin/logstash -f etc/conf.d/ --config.reload.automatic &