ELK基础介绍:logstash负责收集日志、elasticsearch负责存储日志、kibana负责展示日志大屏
1.基础环境安装
2.elasticsearch安装
3.logstash安装
4.kibana安装
1.基础环境准备:两台服务器ELK-master(192.168.77.139)、ELK-slave(192.168.77.138)
1.1环境配置:ELK-master、ELK-slave如下配置,两台都需要配置
关闭防火墙:systemctl stop firewalld
关闭selinux:setenforce 0
1.2时间一致配置:
yum install -y ntpdate
/usr/sbin/ntpdate ntp1.aliyun.com
1.3配置DNS解析:
vim /etc/hosts
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
192.168.77.138 ELK-slave
192.168.77.139 ELK-master
1.4测试DNS解析成功:ELK-slave去ping ELK-master
2.Elasticsearch部署:ELK-slave和ELK-master均需配置,负责存储logstash收集过来的日志,基于索引的存储方式,便于检索。
2.1下载安装GPG key:
rpm --import https://packages.elastic.co/GPG-KEY-elasticsearch
2.2.添加yum仓库:
vim /etc/yum.repos.d/elk.repo
[elasticsearch-2.x]
name=Elasticsearch repository for 2.x packages
baseurl=http://packages.elastic.co/elasticsearch/2.x/centos
gpgcheck=1
gpgkey=http://packages.elastic.co/GPG-KEY-elasticsearch