首页 > 其他 > 详细

ELK之logstash收集日志写入redis及读取redis

时间:2019-02-10 21:08:21      阅读:445      评论:0      收藏:0      [点我收藏+]

logstash->redis->logstash->elasticsearch

1.安装部署redis

cd /usr/local/src
wget http://download.redis.io/releases/redis-3.2.8.tar.gz
tar xf redis-3.2.8.tar.gz
cd redis-3.2.8/
make
ln -s /usr/local/src/redis-3.2.8 /usr/local/redis
cd /usr/local/redis/

vim redis.conf 
bind 10.0.0.22
daemonize yes
save ""
#save 900 1
#save 300 10
#save 60 10000
requirepass root123

cp src/redis-server /usr/bin/
cp src/redis-cli /usr/bin/
redis-server /usr/local/redis/redis.conf

登录redis需要认证

技术分享图片

配置logstash的systemlog_to_redis.conf

vim systemlog_to_redis.conf
input {
  file {
    path => "/var/log/messages"
    type => "systemlog"
    start_position => "beginning"
    stat_interval => "2"
  }
}

output {
  if [type] == "systemlog" {
    redis {
      data_type => "list"
      host => "10.0.0.22"
      db => "1"
      port => "6379"
      password => "root123"
      key => "systemlog"
    }
  }
}
systemctl restart logstash
# 手动写入messages日志
cat /etc/hosts >> /var/log/messages
echo "helloword" >> /var/log/messages

登陆redis查看

技术分享图片

2.配置logstash从reids中取出数据到elasticsearch

# 使用linux-elk2(10.0.0.33)上的logstash从redis取数据
vim redis-es.conf 
input {
  redis {
    data_type => "list"
    host => "10.0.0.22"
    db => "1"
    port => "6379"
    key => "systemlog"
    password => "root123"
  }
}

output {
  elasticsearch {
    hosts => ["10.0.0.33:9200"]
    index => "redis-systemlog-%{+YYYY.MM.dd}"
  }
}
systemctl restart logstash

logstash统计日志,有两个以上的key时,就必须加判断

技术分享图片

 

收集日志写入redis及读取redis:http://blog.51cto.com/jinlong/2056563

ELK之logstash收集日志写入redis及读取redis

原文:https://www.cnblogs.com/fawaikuangtu123/p/10360142.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!