在 Debian 系统上使用 Filebeat(通常来自 Elastic Beacon/Elastic Stack)主要是出于日志采集、转发与运维可观测性的需求。下面从“为什么用 Filebeat”以及“为什么特别在 Debian 上用”两个角度说明。
Filebeat 是 Elastic 官方推出的 轻量级日志采集器,用 Go 编写:
应用日志 → Filebeat → ES → Kibana
Filebeat 自带很多模块,比如:
在 Debian 上非常实用,例如:
filebeat modules enable system
.deb 包dpkg -i filebeat-8.x.amd64.deb
Debian 使用:
/var/log/Filebeat 可:
journald 模块读系统日志Debian 上常用:
systemctl enable filebeat
systemctl start filebeat
与 Debian 服务管理完全一致。
Debian 服务器
├─ nginx
├─ systemd
└─ Filebeat → Elasticsearch / Kafka
/var/log/auth.logsudo apt install filebeat
sudo filebeat modules enable system
sudo filebeat setup
sudo systemctl enable --now filebeat
在 Debian 上使用 Filebeat,是因为它轻量、稳定、易部署,并且非常适合把 Debian 服务器上的系统与应用日志安全地送到 Elastic Stack 中做集中分析和监控。
如果你愿意,我也可以按你的使用场景(服务器 / 容器 / 云)给你一份具体配置示例。