1、filebeat配置
>/etc/filebeat/filebeat.yml
filebeat.prospectors:
- type: log
enabled: true
paths:
- /root/project/logs/all/all.log
fields:
service: test1
2、Logstash 配置
vim /etc/logstash/conf.d/logstash.conf
input {
beats {
port => 5044
codec => plain {
charset => "UTF-8"
}
}
}
output {
elasticsearch {
hosts => "127.0.0.1:9200"
manage_template => false
index => "%{[fields][service]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
}
3、kibana页面配置
创建索引时,会有test1的日志了