在 Debian 上通过 Filebeat 收集日志,一般流程如下(以 Elastic Stack / ELK 场景为例,也适用于直接输出到 logstash、elasticsearch、kafka 等)。
sudo apt update
sudo apt install -y curl gpg
# 导入 Elastic GPG
curl -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elastic-keyring.gpg
# 添加源
echo "deb [signed-by=/usr/share/keyrings/elastic-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-8.x.list
sudo apt update
sudo apt install -y filebeat
如需 7.x,把
8.x改成7.x
wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-8.x.x-amd64.deb
sudo dpkg -i filebeat-8.x.x-amd64.deb
配置文件路径:
/etc/filebeat/filebeat.yml
filebeat.inputs:
- type: filestream
id: system-logs
paths:
- /var/log/syslog
- /var/log/auth.log
output.elasticsearch:
hosts: ["http://localhost:9200"]
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/myapp/*.log
fields:
app: myapp
output.logstash:
hosts: ["192.168.1.10:5044"]
例如系统模块:
sudo filebeat modules enable system
编辑模块配置:
sudo vi /etc/filebeat/modules.d/system.yml
sudo systemctl enable filebeat
sudo systemctl start filebeat
查看状态:
systemctl status filebeat
sudo filebeat test config
sudo filebeat test output
curl -X GET "localhost:9200/_cat/indices?v"
filebeat-*Filebeat 需能读取日志:
sudo usermod -aG adm filebeat
可使用:
filebeat.inputs:
- type: journald
multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
multiline.negate: true
multiline.match: after
如果你告诉我:
我可以给你一份可直接用的配置文件。