安装filebeat
[root@node03 ~]# yum localinstall filebeat-7.4.1-x86_64.rpm -y
配置手机脚本
[root@node03 ~]# vim /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
enabled: true
backoff: "1s"
tail_files: true
paths:
- /var/log/messages
tags: ["system-log"]
- type: log
enabled: true
backoff: "1s"
tail_files: true
paths:
- /var/log/secure
# multiline.pattern: '^\['
# multiline.negate: true
# multiline.match: after
# 为每个项目标识,或者分组,可区分不同格式的日志
tags: ["secure-log"]
# 日志多行合并采集
output.logstash:
hosts: ["192.168.255.11:5044"]