在 CentOS 上编译安装 Filebeat,一般有两种方式:
下面重点讲 从源码编译安装 Filebeat(基于 CentOS 7/8)。
yum install -y git wget curl gcc make
Filebeat 是 Go 语言写的,需要 Go 1.20+(以 8.x 为例)。
wget https://go.dev/dl/go1.22.4.linux-amd64.tar.gz
tar -C /usr/local -xzf go1.22.4.linux-amd64.tar.gz
编辑 /etc/profile 或 ~/.bashrc:
export PATH=$PATH:/usr/local/go/bin
export GOPATH=$HOME/go
export PATH=$PATH:$GOPATH/bin
生效:
source /etc/profile
验证:
go version
Elastic 官方仓库:
git clone https://github.com/elastic/beats.git
cd beats
git checkout v8.13.0
(版本号可到 https://github.com/elastic/beats/releases 查看)
进入 filebeat 目录:
cd filebeat
make
或:
go build -o filebeat .
编译完成后会生成:
./filebeat
cp filebeat /usr/local/bin/
chmod +x /usr/local/bin/filebeat
mkdir -p /etc/filebeat
cp filebeat.yml /etc/filebeat/
filebeat version
编辑 /etc/filebeat/filebeat.yml:
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
output.elasticsearch:
hosts: ["localhost:9200"]
测试配置:
filebeat test config
创建 /etc/systemd/system/filebeat.service:
[Unit]
Description=Filebeat
After=network.target
[Service]
ExecStart=/usr/local/bin/filebeat -c /etc/filebeat/filebeat.yml
Restart=always
[Install]
WantedBy=multi-user.target
启动:
systemctl daemon-reload
systemctl enable filebeat
systemctl start filebeat
go build -ldflags "-s -w" -o filebeat .
或增加 swap。
yum install centos-release-scl
yum install devtoolset-11
scl enable devtoolset-11 bash
✅ 生产环境建议直接用官方 RPM:
rpm -ivh filebeat-8.x.rpm
| 场景 | 建议 |
|---|---|
| 生产环境 | ✅ RPM / 官方二进制 |
| 学习源码 | ✅ 编译 |
| 定制功能 | ✅ 编译 |
| 快速部署 | ✅ 官方包 |
如果你愿意,我可以:
你现在用的是 CentOS 7 还是 8?