在 CentOS 上 Filebeat 不收集日志,通常不是单一原因,而是配置、权限、路径、服务状态或系统环境中的某一项出了问题。下面按最常见 → 较少见的顺序,系统性帮你排查。
systemctl status filebeat
✅ 正常状态应为 active (running)
❌ 如果不是,先启动:
systemctl start filebeat
systemctl enable filebeat
查看启动失败原因:
journalctl -u filebeat -n 50
配置文件位置:
/etc/filebeat/filebeat.yml
pathsfilebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/nginx/access.log
- /var/log/messages
✅ 常见错误:
enabled: falsepaths 写错或目录不存在C:\)ls -l /var/log/messages
ls -l /var/log/nginx/
⚠️ 注意:
/*.log)✅ 正确示例:
paths:
- /var/log/nginx/*.log
ps -ef | grep filebeat
通常是 root 或 filebeat 用户运行。
测试权限:
sudo -u filebeat cat /var/log/messages
❌ 如果报错:
Permission denied
✅ 解决方案:
usermod -aG adm filebeat
systemctl restart filebeat
chmod 644 /var/log/messages
查看 SELinux 状态:
getenforce
如果是 Enforcing,可能是原因。
✅ 临时验证:
setenforce 0
systemctl restart filebeat
如果 关闭 SELinux 后就能收集,说明是 SELinux 问题。
✅ 正确做法(不关 SELinux):
setsebool -P daemons_enable_cluster_mode 1
或允许 Filebeat 读取日志:
semanage fcontext -a -t var_log_t "/var/log(/.*)?"
restorecon -Rv /var/log
journalctl -u filebeat -f
或:
tail -f /var/log/filebeat/filebeat
常见错误:
No such file or directoryPermission deniedharvester closedls /var/lib/filebeat/registry/
如果 registry 损坏,可清空(⚠️ 会重新采集):
systemctl stop filebeat
rm -rf /var/lib/filebeat/registry
systemctl start filebeat
output.elasticsearch:
hosts: ["http://localhost:9200"]
# 或
output.logstash:
hosts: ["localhost:5044"]
❌ 错误示例:
output.elasticsearch:
(hosts 没写)
output.console:
pretty: true
然后:
filebeat -e -c /etc/filebeat/filebeat.yml
✅ 如果能在终端看到日志,说明 采集没问题,问题在输出
如果日志被 logrotate 切割,Filebeat 可能停止采集。
✅ 建议配置:
filebeat.inputs:
- type: log
paths:
- /var/log/nginx/*.log
scan_frequency: 10s
ignore_older: 24h
✅ 快速自检:
systemctl status filebeat
filebeat test config
filebeat test output
你可以直接贴出以下信息(去掉敏感 IP):
/etc/filebeat/filebeat.ymlsystemctl status filebeatjournalctl -u filebeat -n 30我可以 直接帮你指出是哪一行配置导致不采集 ✅