日志分析 入门教程

papertrailapp

SC Magazine

AlienVault

http://forums.alienvault.com/

Logstash

https://logstash.jira.com/browse/LOGSTASH

https://logstash-metlog.readthedocs.org/en/latest/index.html

http://grokdebug.herokuapp.com/

logzilla

相关博客

http://blog.chinaunix.net/uid-11065483-id-3654882.html

http://enable.blog.51cto.com/747951/1049411

http://www.cnblogs.com/ibook360/archive/2013/03/15/2961141.html

http://ppp.cylab.cmu.edu/wordpress/

http://code.taobao.org/p/TimeTunnel/src/

https://papertrailapp.com/

https://github.com/stanzgy/wiki/blob/master/openstack/setup-log-collect-service.md

http://www.vmdoh.com/blog/centralizing-logs-lumberjack-logstash-and-elasticsearch

http://blog.sina.com.cn/s/blog_5459f60d0101ogbp.html

http://rritw.com/a/JAVAbiancheng/ANT/20130322/328118.html

http://www.it165.net/admin/html/201303/906.html

http://jaseywang.me/2012/12/26/logstash-%E5%88%9D%E4%BD%93%E9%AA%8C/

http://chenlinux.com/2012/10/21/elasticearch-simple-usage/

http://cleversoft.wordpress.com/2013/04/05/887/

http://de.slideshare.net/ae_bm/logstash-elasticsearch-kibana

https://medium.com/devops-programming/b01bd0876e82

https://github.com/lusis/chef-logstash

http://kibana.org/intro.html

http://blog.sina.com.cn/s/blog_a84e73f70101chk5.html

https://support.shotgunsoftware.com/entries/23563217-Installing-Logstash-Central-Server-Kibana-Installation

http://edgeofsanity.net/article/2012/12/26/elasticsearch-for-logging.html

http://blog.lusis.org/blog/2012/01/31/load-balancing-logstash-with-redis/

http://patrickscables.tumblr.com/post/29929829473

http://josediazgonzalez.com/2013/01/01/setting-up-beaver-for-use-with-logstash/

http://blog.naver.com/PostView.nhn?blogId=junix&logNo=80186624546

http://www.javacodegeeks.com/2013/02/your-logs-are-your-data-logstash-elasticsearch.html

http://techhari.blogspot.kr/2013/03/elasticsearch-cluster-setup-in-2-minutes.html

http://jablonskis.org/2013/elasticsearch-and-logstash-tuning/

http://jpmens.net/2012/08/06/my-logstash-and-graylog2-notes/

http://linuxdrops.com/log-management-using-logstash-and-kibana-on-centos-rhel-fedora/

http://ci.openstack.org/logstash.html

http://log.medcl.net/item/2013/03/logstash-nginx-logs-grok-pattern-debugging/

https://isc.sans.edu/diary/Guest+Diary%3A+Dylan+Johnson+-+There%27s+value+in+them+there+logs!/15289

http://blog.sina.com.cn/s/blog_a84e73f70101ck5r.html

http://gt-logiciel-libre.org/

http://tm.durusau.net/?cat=1067











  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
## 什么是graylog Graylog 是一个简单易用、功能较全面的日志管理工具,相比 ELK 组合, 优点: - 部署维护简单 - 查询语法简单易懂(对比ES的语法…) - 内置简单的告警 - 可以将搜索结果导出为 json - 提供简单的聚合统计功能 - UI 比较友好 - 当然, 拓展性上比 ELK 差很多。 整套依赖: - Graylog 提供 graylog 对外接口 - Elasticsearch 日志文件的持久化存储和检索 - MongoDB 只是存储一些 Graylog 的配置 ## 安装 > 可以是裸机安装,也可以是docker安装,这里用docker安装 环境要求: - centos7.4 - cpu2个 内存2G 参考: https://hub.docker.com/r/graylog2/graylog/ ### 环境准备 ``` mkdir /root/graylog && cd /root/graylog //挂载目录 mkdir -p mongo_data graylog_journal es_data //配置文件目录 mkdir -p ./graylog/config cd ./graylog/config wget https://raw.githubusercontent.com/Graylog2/graylog-docker/3.0/config/graylog.conf wget https://raw.githubusercontent.com/Graylog2/graylog-docker/3.0/config/log4j2.xml //提前准备镜像 docker pull mongo:3 docker pull graylog/graylog:3.0 docker pull elasticsearch:5.6.9 ``` ### docker-compose.yml ``` version: '2' services: # MongoDB: https://hub.docker.com/_/mongo/ mongo: image: mongo:3 volumes: - ./mongo_data:/data/db - /etc/localtime:/etc/localtime # Elasticsearch: https://www.elastic.co/guide/en/elasticsearch/reference/5.5/docker.html elasticsearch: image: elasticsearch:5.6.9 volumes: - ./es_data:/usr/share/elasticsearch/data - /etc/localtime:/etc/localtime environment: - http.host=0.0.0.0 - transport.host=localhost - network.host=0.0.0.0 # Disable X-Pack security: https://www.elastic.co/guide/en/elasticsearch/reference/5.5/security-settings.html#general-security-settings - xpack.security.enabled=false - "ES_JAVA_OPTS=-Xms512m -Xmx512m" ulimits: memlock: soft: -1 hard: -1 mem_limit: 1g # Graylog: https://hub.docker.com/r/graylog/graylog/ graylog: image: graylog/graylog:3.0 volumes: - ./graylog_journal:/usr/share/graylog/data/journal - ./graylog/config:/usr/share/graylog/data/config - /etc/localtime:/etc/localtime environment: # CHANGE ME! - GRAYLOG_PASSWORD_SECRET=somepassword

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值