logstash收集nginx日志

(1)安装nginx

1.安装nginx

yum install epel-release -y 
yum install nginx -y 

2.修改日志文件格式为json

#vim /etc/nginx/nginx.conf 
http {
    log_format access_json '{"@timestamp":"$time_iso8601",'
                           '"host":"$server_addr",'
                           '"clientip":"$remote_addr",'
                           '"size":$body_bytes_sent,'
                           '"responsetime":$request_time,'
                           '"upstreamtime":"$upstream_response_time",'
                           '"upstreamhost":"$upstream_addr",'
                           '"http_host":"$host",'
                           '"url":"$uri",'
                           '"domain":"$host",'
                           '"xff":"$http_x_forwarded_for",'
                           '"referer":"$http_referer",'
                           '"status":"$status"}';
    access_log  /var/log/nginx/access.log  access_json;
    }

3.启动nginx

systemctl start nginx 
systemctl enable nginx 

4.压测

ab -n 1000 -c 1  http://192.168.1.31/index.html

5.查看日志

# tail -1 /var/log/nginx/access.log 
{"@timestamp":"2018-05-29T14:56:35+08:00","host":"192.168.1.31","clientip":"192.168.1.31","size":3700,"responsetime":0.000,"upstreamtime":"-","upstreamhost":"-","http_host":"192.168.1.31","url":"/index.html","domain":"192.168.1.31","xff":"-","referer":"-","status":"200"}

(2)logstash配置

1.logstash配置

#vim /etc/logstash/conf.d/nginx-access-log.conf 
input {
        file {
                path => "/var/log/nginx/access.log"
                type => "nginx-access-log"
                start_position => "beginning"
                stat_interval => "2"
                }
        }

output {
        if [type] == "nginx-access-log" {
                elasticsearch {
                        hosts => ["192.168.1.31:9200"]
                        index => "nginx-access-log-%{+YYYY.MM.dd}"
                }
        }
        file {
        path => "/tmp/logstash-nginx-access-log-%{+YYYY.MM.dd}"
         }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/nginx-access-log -t 
systemctl restart logstash 

3.head插件查看索引
1195071-20180529152809101-548987018.png
4.kibana查看
1195071-20180529152814138-2032506404.png
1195071-20180529162411988-1359118700.png

转载于:https://www.cnblogs.com/lovelinux199075/p/9105096.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值