在 CentOS 上启动 Filebeat 通常有两种方式:使用 systemd(推荐)或直接运行二进制文件。下面按常见场景说明。
sudo systemctl start filebeat
sudo systemctl enable filebeat
sudo systemctl status filebeat
sudo systemctl stop filebeat
sudo systemctl restart filebeat
在启动前建议先测试配置:
sudo filebeat test config
测试输出(Elasticsearch / Logstash)连接:
sudo filebeat test output
如果你是手动解压的 Filebeat:
cd /opt/filebeat
sudo ./filebeat -e -c filebeat.yml
-e:输出日志到标准错误(方便排查)-c:指定配置文件后台运行:
nohup sudo ./filebeat -e -c filebeat.yml > filebeat.log 2>&1 &
sudo chown -R root:root /etc/filebeat
journalctl -u filebeat -f
rpm -qa | grep filebeat
# 或
which filebeat
如果你能告诉我:
我可以给你更精确的启动方案。