安装 Logstash
使用scrt工具把kibana的rpm包上传至elk-2节点的root的目录下(其他节点不需上传)
[root@elk-2 ~]# rpm -ivh logstash-6.0.0.rpm
Preparing... ################################# [100%]
Updating / installing...
1:logstash-1:6.0.0-1 ################################# [100%]
Using provided startup.options file: /etc/logstash/startup.options
Successfully created system startup script for Logstash
配置Logstash以及启动服务
配置/etc/logstash/logstash.yml,修改增加如下:
[root@elk-2 ~]# vi /etc/logstash/logstash.yml
http.host: "192.168.200.12"
配置logstash收集syslog日志:
[root@elk-2 ~]# vi /etc/logstash/conf.d/syslog.conf
input {
syslog {
type => "system-syslog"
port => 10514
}
}
output {
stdout {
codec => rubydebug
}
}
检测配置文件是否错误:
[root@elk-2 ~