一、logstash安装 :
1 官网下载logstash-7.6.2.tar.gz
2 mkdir -p /usr/local/logstash
3 tar -zxvf logstash-7.6.2.tar.gz
二、导入mysql 数据步骤:
1 logstash-7.6.2下建立jdbc.conf和jdbc.sql
2 /logstash/logstash-7.6.2/logstash-core/lib/jars 下加入mysql-connector-java-5.1.6.jar
3 jdbc.sql直接放入查询语句
4 jdbc.conf放入一下内容(根据实际配置)
input {
stdin {
}
jdbc {
# mysql jdbc connection string to our backup databse 后面的test对应mysql中的test数据库
jdbc_connection_string => "jdbc:mysql://139.224.234.236:3306/guli"
# the user we wish to excute our statement as
jdbc_user => "root"
jdbc_password => "123456"
# the path to our downloaded jdbc driver
#jdbc_driver_library => "/elasticsearch-jdbc-2.3.2.0/lib/mysql-connector-java-5.1.38.jar"
# the name of the driver class for mysql
#jdbc_driver_class => "com.mysql.jdbc.Driver"
jdbc_paging_enabled => "true"
jdbc_page_size => "50000"
#以下对应着要执行的sql的绝对路径。
statement_filepath => "/mydata/logstash/logstash-7.6.2/config/jdbc.sql"
#定时字段 各字段含义(由左至右)分、时、天、月、年,全部为*默认含义为每分钟都更新(测试结果,不同的话请留言指出)
schedule => "* * * * *"
#设定ES索引类型
type => "cc_type"
}
}
filter {
json {
source => "message"
remove_field => ["message"]
}
}
output {
elasticsearch {
#ESIP地址与端口
hosts => "139.224.234.236:9200"
#ES索引名称(自己定义的)
index => "cc_index"
#自增ID编号
document_id => "%{id}"
}
stdout {
#以JSON格式输出
codec => json_lines
}
}
5 启动logstash
bin/logstash -f /usr/local /logstash/logstash-7.6.2/jdbc/conf -t(可检查)