sudo systemctl stop filebeat
sudo cp /etc/filebeat/filebeat.yml /etc/filebeat/filebeat.yml.bak
# 创建快照仓库
curl -XPUT "http://localhost:9200/_snapshot/my_backup" -H 'Content-Type: application/json' -d'{"type": "fs", "settings": {"location": "/path/to/snapshot/repo"}}'
# 创建快照
curl -XPUT "http://localhost:9200/_snapshot/my_backup/snapshot_$(date +%Y%m%d%H%M%S)"
sudo cp -R /var/lib/filebeat/state /var/lib/filebeat/state.bak
sudo cp /etc/filebeat/filebeat.yml.bak /etc/filebeat/filebeat.yml
curl -XPOST "http://localhost:9200/_snapshot/my_backup/snapshot_YYYYMMDDHHMMSS/_restore"
sudo cp -R /var/lib/filebeat/state.bak /var/lib/filebeat/state
sudo systemctl start filebeat
cron任务自动化备份。filebeat -configtest -e验证。