软件:
filebeat-6.4.2-linux-x86_64 用于采集日志发送到logstash
配置:filebeat.yml
filebeat.inputs:
– type: log
enabled: true
paths:
– /var/log/httpd/*
exclude_files: [‘.gz$’]
output.logstash:
hosts: [“192.168.3.124:5044”]
启动:
./filebeat run -e 这样启动显示运行日志,
欠缺: 监控, 后台运行
———-
elasticsearch-6.4.2, 负责保存由logstash输入的数据
启动: ./bin/elasticsearch
logstash-6.4.2 输入filebeat的日志, 并输出到es
cat run.conf
input {
beats {
port => “5044”
}
}
filter {
grok {
match => { “message” => “%{COMBINEDAPACHELOG}” }
}
date {
match => [ “timestamp” , “dd/MMM/yyyy:HH:mm:ss Z” ]
}
}
output {
elasticsearch { hosts => [“localhost:9200”] }
stdout { codec => rubydebug }
}
启动
./bin/logstash -f run.conf –config.reload.automatic
kibana-6.4.2-linux-x86_64 es的图形化客户端, 方便显示统计图等内容