1.下载安装文件
假如我们下载到/opt/elk
wget https:
//download.elastic.co/logstash/logstash/logstash-2.3.2.tar.gz
|
2.解压安装文件
假如我们解压到/opt/elk目录
tar zxvf logstash-
2.3
.
2
.tar.gz
|
3.增加配置文件
假如配置文件名称为logstash-demo.conf
input {
file {
path =>
"/opt/hiker/log/igoeasy-api/igoeasy-api.log"
start_position => beginning
}
}
filter {
grok {
match => {
"message"
=>
"%{COMBINEDAPACHELOG}"
}
}
}
output {
elasticsearch { hosts =>
"192.168.1.10:9200"
}
}
|
4.启动Logstash
打开/opt/elk/logstash-2.3.2
cd /opt/elk/logstash-
2.3
.
2
#测试配置是否正确
bin/logstash -f logstash-demo.conf --configtest
#启动
bin/logstash -f logstash-demo.conf.conf
|
参考文档:https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html