前提条件安装了 JDK 这个就不说了
下载Logstash
wget https://artifacts.elastic.co/downloads/logstash/logstash-5.6.1.tar.gz
也可以直接登录 https://www.elastic.co/cn/downloads/logstash 下载
解压
tar -zxvf logstash-5.6.1.tar.gz -C /usr/local
查看地址
修改环境变量
vi /etc/profile 文件尾部增加
export LOGSTASH_HOME=/usr/local/logstash-5.6.1
export PATH=$PATH:$LOGSTASH_HOME/bin
source /etc/profile
读取一个文件夹下的日志怎么搞
input {
file {
path => "/home/rohit/dummy/*.log"
type => "log"
}
}
filter {
if [type] == "log" {
grok {
pattern => "%{COMBINEDAPACHELOG}"
}
}
}
output {
elasticsearch { host => localhost } stdout { } }
}
filebeat 安装
官网下载 https://www.elastic.co/cn/downloads/beats/filebeat
filebeat -e -c filebeat.yml &