本地安装Filebeat 7.12.0 服务器7.9.0
安装包:rpm
配置命令:
/usr/share/filebeat/bin/filebeat setup -path.config /home/gum/filebeat/ -path.data /home/gum/filebeat/data -path.logs /home/gum/filebeat/logs -path.home /usr/share/filebeat/ -e
启动命令:
nohup /usr/share/filebeat/bin/filebeat run -path.config /home/gum/filebeat/ -path.data /home/gum/filebeat/data -path.logs /home/gum/filebeat/logs -path.home /usr/share/filebeat/ &
配置文件:
filebeat.inputs:
- type: log
enabled: true
paths:
- /home/gum/gem/gw/interface/api/logs/log-es*
fields:
source: interface
json.keys_under_root: true
json.overwrite_keys: true
json.add_error_key: true
message_key: srcip
setup.ilm.enabled: false
setup.template.name: "interface"
setup.template.pattern: "interface-index-*"
setup.template.settings:
index.number_of_shards: 1
index.number_of_replicas: 1
output.elasticsearch:
hosts: [********]
username: *****
password: *******
indices:
- index: "interface-index-%{+yyyy.MM.dd}"
when.equals:
fields:
source: "interface"
logging.level: debug
processors:
- add_locale: ~
环境介绍:
elasticsearch 7.9.0
kibana 由于环境问题,访问不到
遇到的问题:
1、为啥kibana还是会去链接,想把这个关了,但是没找到具体方法,虽然没报错
2、出现一下这个问题,未找到问题原因
Exiting: 1 error: error loading index pattern: returned 413 to import file: <nil>. Response: {"statusCode":413,"error":"Request Entity Too Large","message":"Payload content length greater than maximum allowed: 1048576"}
3、为啥kibana上会多了一个旧的索引模版,这个模版数据完全是基础模版那样的,每次运行配置命令都会有
上面的是配置好的模版,下面的是自动生成的
4、Kibana dashboards 的这个配置具体是做啥的,没搞懂