logstash 教程:http://kibana.logstash.es/content/logstash/get_start/full_config.html
https://wsgzao.github.io/post/elk/
es配置教程:http://ju.outofmemory.cn/entry/214901
一、安装OpenJDK
yum install java-1.7.0-openjdk
二、安装Elaticsearch
1、下载ES
cd /tmp
wget https://download.elasticsearch.org/elasticsearch/elasticsearch/elasticsearch-1.4.4.tar.gz
tar zxvf elasticsearch-1.4.4.tar.gz
mv elasticsearch-1.4.4 /home/elasticsearch
2、安装启动脚本
cd /tmp
git clone https://github.com/elasticsearch/elasticsearch-servicewrapper.git
cd /tmp/elasticsearch-servicewrapper
mv service /home/elasticsearch/bin/
cd /tmp
rm -rf elasticsearch-servicewrapper
cd /home/elasticsearch/bin/service
vim elasticsearch.conf
编辑elasticsearch.conf(即:1 && 2 行),设置为/home/elasticsearch,修改ES_HEAP_SIZE (内存的60%)(单位是M)
./elasticsearch install
3、打开防火墙9200
vim /etc/sysconfig/iptables
添加一行:
-A INPUT -m state --state NEW -m tcp -p tcp --dport 9200 -j ACCEPT
4、安装插件(可选)
cd /home/elasticsearch/
bin/plugin -install mobz/elasticsearch-head
bin/plugin -install lmenezes/elasticsearch-kopf
更多请参照:http://www.elastic.co/guide/en/elasticsearch/reference/1.3/modules-plugins.html
5、启动es
/etc/init.d/elasticsearch restart
6、测试(xxx.xxx.xxx.xxx是服务期IP地址)
可以访问:xxx.xxx.xxx.xxx:9200 ,看状态是否是:200
或者访问插件kopf:xxx.xxx.xxx.xxx:9200/_plugin/kopf
三、安装Logstash
1、安装 (已有更新版,请去官网查看)
cd /home
wget -O /home/logstash-1.4.2.tar.gz https://download.elasticsearch.org/logstash/logstash/logstash-1.4.2.tar.gz
tar zxvf logstash-1.4.2.tar.gz
rm -rf logstash-1.4.2.tar.gz
mv logstash-1.4.2 logstash
mkdir /etc/logstash
mkdir /var/log/logstash
2、创建配置文件:(这个路径与下面步骤的启动脚本里是对应的)
vim /etc/logstash/index.conf
添加如下内容:
input {
file {
path => "/var/log/messages"
start_position => "beginning"
codec => plain {
charset => "GBK" }
type => "file"
}
}
output {
elasticsearch {
host => "127.0.0.1"
}
}
补充:
更多功能:http://logstash.net/docs/1.4.2/
3、插件
cd /home/logstash
bin/plugin install contrib
4、启动文件
wget -O /etc/init.d/logstash http://update.biglog.org/logstash
chmod +x /etc/init.d/logstash
chkconfig --add logstash
chkconfig logstash on
service logstash start
四、安装Kibana
1、安装
cd /home
wget https://download.elasticsearch.org/kibana/kibana/kibana-4.0.1-linux-x64.tar.gz
tar zxvf kibana-4.0.1-linux-x64.tar.gz
rm -fr kibana-4.0.1-linux-x64.tar.gz
mv kibana-4.0.1-linux-x64 kibana
2、配置
cd /home/kibana
vim config/kibana.yml
根据需要修改:
---kibana端口号,默认是5601
---kibana的索引名称,默认是:.kibana
---es的url,默认是:http://localhost:9200
3、打开防火墙
打开kibana对应的端口号,方法同上面
4、启动
cd /home/kibana
bin/kibana
5、测试
然后浏览器访问:xxx.xxx.xxx.xxx:5601,进行配置即可