vim /usr/lib/systemd/system/elasticsearch.service
LimitMEMLOCK=infinity #去掉注释,可以最大化使用内存,两台都改
#执行如下命令,使脚本生效
systemctl daemon-reload
#修改es配置文件锁定内存开启,这样es性能会大大提升
vi /etc/elasticsearch/elasticsearch.yml
boostrap.memory_lock: true
#启动ES
systemctl restart elasticsearch
cd /usr/local/src/
yum install logstash-5.6.5.rpm -y
cd /etc/logstash/conf.d/ #默认在这里,但是需要我们创建
/usr/share/logs/logstash/bin/logstash -e ‘input { stdin{} } output { stdout{ codec => rubydebug}}’
#然后手动输入hello看效果
vi /etc/logstash/conf.d/systemlog.conf