官网地址:https://www.elastic.co/downloads/
1, 下载软件
wget https://artifacts.elastic.co/downloads/logstash/logstash-7.14.1-linux-x86_64.tar.gz
2, 解压
tar -zxvf logstash-7.14.1-linux-x86_64.tar.gz
3, 配置
创建配置文件logstash.conf ,并添加如下配置
input {
file {
path => "/usr/share/tomcat/logs/*.log"
start_position => "beginning"
}
}
filter {
}
output {
elasticsearch {
hosts => "localhost:9200"
}
}
4, 添加用户组权限
chown -R elsearch:elsearch logstash-7.14.1
5,启动
su elsearch
cd logstash-7.14.1/bin
./logstash -f logstash.conf
6, 通过Kibana查看日志
找到 Stack management,创建Index patterns 之后在 Discovery 中查看日志数据