日志/消息整体流向:Flume -> kafka -> logstash -> elasticsearch -> kibana
1、日志信息写入kafka(Flume -> kafka)
1.1、Flume及Kafka安装配置
2、从kafka写入ES(kafka -> logstash代理程序 -> elasticsearch)
2.1、logstash及ES安装配置
参考:
https://www.sojson.com/blog/90.html
3、展示(elasticsearch -> kibana)
4、定制化搜索
利用ES提供的Restful API
参考资料:
https://www.cnblogs.com/moonandstar08/p/6556899.html
https://blog.csdn.net/u010463032/article/details/78870536
https://segmentfault.com/p/1210000011002688
或
http://timeyang.com/articles/12/2017/09/02/%E5%9F%BA%E4%BA%8EJava%E3%80%81Kafka%E3%80%81ElasticSearch%E7%9A%84%E6%90%9C%E7%B4%A2%E6%A1%86%E6%9E%B6%E7%9A%84%E8%AE%BE%E8%AE%A1%E4%B8%8E%E5%AE%9E%E7%8E%B0
https://www.cnblogs.com/smartloli/p/6978645.html
https://www.cnblogs.com/moonandstar08/p/6556899.html