搭建 logstash-7.4.1
安装logstash
[root@node01 ~]# yum localinstall logstash-7.4.1.rpm -y
配置启动参数
[root@node01 ~]# cd /etc/logstash/
[root@node01 logstash]# vim jvm.options
-Xms1g
-Xmx1g
-XX:+UseG1GC
[root@node01 logstash]# vim logstash.yml
path.data: /etc/logstash/data
path.logs: /etc/logstash/logs
创建数据跟日志存放目录
[root@node01 logstash]# mkdir data logs
写个简单的调用日志进行测试
[root@node01 logstash]# cp logstash-sample.conf conf.d/logstash.conf
[root@node01 logstash]# vim conf.d/logstash.conf
input {
file {
path => "/var/log/messages"
start_position => beginning
sincedb_path => "/dev/null"
}
}
filter {
}
output {
elasticsearch {
hosts => ["http://192.168.255.11:9200"]
index => "logst-test-%{+YYYY.MM.dd}"
}
}
[root@node01 logstash]# chown -R logstash:logstash /etc/logstash
[root@node01 logstash]# systemctl restart logstash.service