以收集es日志为例
1,编辑配置filebeat配置文件
cat >> /etc/filebeat/filebeat.yml << 'EOF'
filebeat.inputs:
- type: log
enabled: true
paths:
/var/log/elasticsearch/elasticsearch.log
multiline.pattern: '^\[' # 这三项是应对多行匹配用得
multiline.negate: true
multiline.match: after
output.elasticsearch:
hosts: ["http://10.4.7.11:9200"]
index: "es-%{[agent.version]}-%{+yyyy.MM}"
setup.template.enabled: false
setup.template.name: "nginx"
setup.template.pattern: "nginx-*"
setup.ilm.enabled: false
EOF
es日志下载地址(少量仅供学习使用):
https://download.csdn.net/download/renren_100/21442859
最终的获取效果: