vim filebeat.yml
filebeat.prospectors:
- type: log
enabled: true
paths:
- /opt/zcsy/hbase/logs/hbase-hadoop-regionserver-cd-zcsy-164.log
fields:
source: "hbase-hadoop-regionserver-cd-zcsy" #创建第一个源数据区域
include_lines: '([eE][rR]{2}[Oo][Rr])'
paths:
- /opt/zcsy/hadoop/logs/hadoop-hadoop-journalnode-cd-zcsy-164.log
fields: #tags: ["xxx"]/type: xxx,在此用的是附件标识
source: "hadoop-hadoop-journalnode-cd-zcsy" #创建第二个源数据区域
include_lines: '([eE][rR]{2}[Oo][Rr])'
filebeat.config.modules:
path: ${path.config}/modules.d/*.yml
reload.enabled: false
setup.template.settings:
index.number_of_shards: 3
setup.kibana:
setup.template.name: "*-cd-zcsy-164" #设置模版
setup.template.pattern: "*-cd-zcsy-164-*"
setup.template.overwrite: true
setup.template.enabled: true
setup.ilm.enabled: false #filebeat自定义索引需要关闭
output.elasticsearch :
hosts: ["172.25.11.182:9200"]
index: "%{[fields.source]}-164-%{+yyyy.MM.dd}" #调用领域
indices: #指数
- index: "hbase-hadoop-regionserver-cd-zcsy-164-%{+yyyy.MM.dd}"
when.equals: #判断,当..等于
fields: #支持多种条件(fields.type: xxx),(fields.tags: "xxx")
source: "hbase-hadoop-regionserver-cd-zcsy"
- index: "hadoop-hadoop-journalnode-cd-zcsy-164-%{+yyyy.MM.dd}"
when.equals:
fields:
source: "hadoop-hadoop-journalnode-cd-zcsy"
filebeat多个日志输出多条索引
于 2021-06-09 18:59:11 首次发布