首页 > 其他 > 详细

ELK-logstash

时间:2021-03-04 22:57:12      阅读:26      评论:0      收藏:0      [点我收藏+]

下载对应的logstash

https://artifacts.elastic.co/downloads/logstash/logstash-7.10.1-linux-x86_64.tar.gz

解压logstash

tar -xf logstash-7.10.1-linux-x86_64.tar.gz

移动到自己的目录就可以了

测试

../bin/logstash -e input { stdin{} } output { elasticsearch {hosts => ["192.168.50.80:9200"]} }

测试文件结构input {        file {

                path => "/var/log/messages"
                type => "system"
                #按行读取日志
                start_position => "beginning"
        }

        file {
                path => "/usr/local/elasticsearch/logs/elasticsearch.log"
                type => "elasticsearch"
                start_position => "beginning"
          #按事物读取   codec => multiline { pattern => "^\[" negate => true what => "previous" } } } output { if [type] == "system" { elasticsearch { hosts => ["192.168.50.80:9200"] index => "system-%{+YYYY.MM.dd}" } } if [type] == "elasticsearch" { elasticsearch { hosts => ["192.168.50.80:9200"] index => "elasticsearch-%{+YYYY.MM.dd}" } } }

 

ELK-logstash

原文:https://www.cnblogs.com/xiongyoutom/p/14483246.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!