下面给你一个**在 Debian 上使用 Filebeat 收集系统日志(含常见日志类型)**的完整思路和示例配置,适合新手到生产环境参考。
常见 Debian 日志位置:
/var/log/syslog/var/log/auth.log/var/log/kern.log/var/log/nginx/,/var/log/mysql/journald 或 filebeat systemd 模块)sudo apt update
sudo apt install filebeat -y
安装完成后:
sudo systemctl enable filebeat
sudo systemctl start filebeat
编辑配置文件:
sudo vi /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: filestream
id: syslog
paths:
- /var/log/syslog
- /var/log/auth.log
- /var/log/kern.log
- type: filestream
id: nginx
paths:
- /var/log/nginx/*.log
✅ Debian 11+ 推荐使用
filestream(老版本用log)
output.elasticsearch:
hosts: ["http://localhost:9200"]
username: "elastic"
password: "your_password"
或者输出到 Logstash:
output.logstash:
hosts: ["localhost:5044"]
sudo filebeat test config
sudo filebeat test output
sudo systemctl restart filebeat
Debian 官方支持很多模块,简化解析:
sudo filebeat modules enable system nginx
编辑模块配置:
sudo vi /etc/filebeat/modules.d/system.yml
示例:
- module: system
syslog:
enabled: true
auth:
enabled: true
然后:
sudo filebeat setup
sudo systemctl restart filebeat
如果不想读文件,可以直接读 journal:
filebeat.inputs:
- type: journald
id: systemd
paths:
- /run/log/journal
⚠️ 注意:
确保 filebeat 能读日志:
sudo usermod -aG adm filebeat
检查:
sudo journalctl -u filebeat -f
加:
close_inactive: 1h
clean_inactive: 72h
ignore_older: 48h
Debian
└── Filebeat
├── Elasticsearch
└── Kibana
或
Debian
└── Filebeat → Logstash → Elasticsearch
如果你告诉我:
我可以直接给你一份可复制的 filebeat.yml ✅