ELK集群启动顺序
1.ES集群
3台机器都要启动
su - esuser
nohup /usr/local/src/elasticsearch-7.7.1/bin/elasticsearch &
2.zookeeper+kafka 103
启动zookeeper
nohup /usr/local/src/kafka_2.12-3.2.0/bin/zookeeper-server-start.sh /usr/local/src/kafka_2.12-3.2.0/config/zookeeper.properties &
启动kafka
nohup /usr/local/src/kafka_2.12-3.2.0/bin/kafka-server-start.sh /usr/local/src/kafka_2.12-3.2.0/config/server.properties &
3.logstash 102
针对不同的数据源,我们用不同的配置文件
nohup /usr/local/src/logstash-7.7.1/bin/logstash -f /usr/local/src/logstash-7.7.1/config/fb_oslog.yml &
nohup /usr/local/src/logstash-7.7.1/bin/logstash -f /usr/local/src/logstash-7.7.1/config/kafka.yml &
4.filebeat 101
针对不同的数据源,我们用不同的配置文件
nohup /usr/local/src/filebeat-7.7.1-linux-x86_64/filebeat -e -c /usr/local/src/filebeat-7.7.1-linux-x86_64/oslog2es.yml -d "publish" &
nohup /usr/local/src/filebeat-7.7.1-linux-x86_64/filebeat -e -c /usr/local/src/filebeat-7.7.1-linux-x86_64/oslog2kafka.yml -d "publish" &
5.kibana
su - esuser
nohup /usr/local/src/kibana-7.7.1-linux-x86_64/bin/kibana &
参考后面ELK服务化
systemctl start elasticsearch
systemctl start zookeeper
systemctl start kafka
systemctl start logstash
systemctl start filebeat
systemctl start kibana
如何触发日志
101上
echo "[INFO] node-1: hello world" >/var/log/test.log
echo "[WARN] node-2: hello world, I am node-1" >/var/log/test.log
数据流向,日志检查
通过查看filebeat日志,确认是否有日志采集
查看kafka topic中是否有新的记录,看kafka日志
查看logstash日志,是否有接收到日志
最快的显示就是kibana有新日志显示