在 CentOS 上 Filebeat 没有数据(无日志上报) 是很常见的问题,通常不是单一原因。下面按排查顺序给你一套系统思路,基本能覆盖 90% 的情况。
systemctl status filebeat
ps -ef | grep filebeat
如果没跑:
systemctl start filebeat
systemctl enable filebeat
查看日志:
journalctl -u filebeat -f
# 或
tail -f /var/log/filebeat/filebeat
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
常见问题:
stdout 而不是 logenabled: false✅ 测试路径是否存在:
ls -l /var/log/xxx.log
Filebeat 只采集新增内容:
echo "test log" >> /var/log/xxx.log
如果文件一直没变化,Filebeat 不会发数据。
output.elasticsearch:
hosts: ["http://localhost:9200"]
output.logstash:
hosts: ["localhost:5044"]
❌ 常见错误:
测试连通性:
telnet localhost 5044
curl http://localhost:9200
filebeat -e -c /etc/filebeat/filebeat.yml
重点看:
ps -ef | grep filebeat
默认用户:filebeat
解决:
chmod 644 /var/log/xxx.log
# 或
setfacl -m u:filebeat:r /var/log/xxx.log
getenforce
如果是 Enforcing:
setenforce 0 # 临时
或放行:
ausearch -m avc -ts recent
Filebeat 用 registry 记录读取位置:
/var/lib/filebeat/registry
如果之前读过文件,再改内容也不会发。
✅ 清空 registry(测试用):
systemctl stop filebeat
rm -rf /var/lib/filebeat/registry
systemctl start filebeat
GET filebeat-*/_search
tail -f /var/log/logstash/logstash-plain.log
如果你愿意,可以把下面信息发我,我可以直接帮你定位:
filebeat.yml(脱敏)systemctl status filebeat 输出journalctl -u filebeat 报错我可以一步一步帮你精确到行。