您的位置:首页 > 其它

logstash安装

2018-04-23 18:09 369 查看

1.部署

cd /usr/local/src
wget https://artifacts.elastic.co/downloads/logstash/logstash-5.2.2.rpm
sha1sum logstash-5.2.2.rpm

#这个rpm安装需要读取/usr/bin/java,所以需要将我们常用jdk目录的java软连接过去
ln -s /usr/local/jdk1.8.0_151/bin/java /usr/bin/
rpm --install logstash-5.2.2.rpm

2.写一个简易的配置文件收集一下messages和secure日志

#这个配置文件可以放在/etc/logstash/conf.d/ 下,自己根据情况定义*.conf
input {
file {
path => [ "/var/log/messages","/var/log/secure" ]
start_position => "beginning"
}
}

filter {
if [path] == "/var/log/messages" {
mutate {
replace => { type => "messages_type" }
}
}
if [path] == "/var/log/secure" {
mutate {
replace => { type => "secure_type" }
}
}
}

output {
stdout {
codec=>rubydebug
}
if [type] == "messages_type" {
elasticsearch {
hosts =>"11.0.0.51:9200"
index => "messages-%{+YYYY.MM.dd}"
}
}
if [type] == "secure_type"  {
elasticsearch {
hosts =>"11.0.0.51:9200"
index => "secure-%{+YYYY.MM.dd}"
}
}
}
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签:  logstash 初步 51cto