ELK版本 6.7
Getting Started With Filebeat
Configure FileBeat
filebeat.yml
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
#- c:\programdata\elasticsearch\logs\*
output.elasticsearch:
hosts: ["myEShost:9200"]
username: "filebeat_internal" #?
password: "YOUR_PASSWORD" #?
setup.kibana:
host: "mykibanahost:5601"
username: "my_kibana_user" #?
password: "YOUR_PASSWORD" #?
测试FileBeats With Logstash
filebeat.prospectors:
- type: log
paths:
- E:\ELK\logs\access.log
output.logstash:
hosts: ["localhost:5044"]
sudo ./filebeat -e -c filebeat-test.yml -d "publish"