一、filebeat容器
1. d:/usr2/local/etc/filebeat/目录下filebeat.yml文件配置
filebeat.inputs:
- type: log
enabled: true
paths:
- /usr/share/filebeat/log/apps/*/*.log
output.logstash:
hosts: ["192.168.1.110:5044"]
2. 启动filebeat
docker run -v /d/usr/share/filebeat/apps/log:/usr/share/filebeat/log/apps -v /d/usr2/local/etc/filebeat/filebeat.yml:/usr/share/filebeat/filebeat.yml --name filebeat1 elastic/filebeat:7.7.0
二、logstash容器
1. d:/usr2/local/etc/logstash/pipeline1目录下logstash.conf配置文件
input {
stdin { }
beats {
port => 5044
}
}
filter {
ruby {
code => "
path = event.get('log')['file']['path']
puts format('path = %<path>s', path: path)
if (!path.nil?) && (!path.empty?)
e