温馨提示×

ubuntu filebeat怎么看运行状态

小樊
35
2026-09-20 11:11:11
栏目: 智能运维

在 Ubuntu 上查看 Filebeat 运行状态,常见有以下几种方式,取决于你是怎么安装的(systemd / 二进制 / 容器)。


一、如果是通过 apt / deb 安装(最常见)

1️⃣ 查看 Filebeat 服务状态

systemctl status filebeat

常见状态说明:

  • active (running) ✅ 正常运行
  • inactive (dead) ❌ 已停止
  • failed ❌ 启动失败

2️⃣ 查看是否开机自启

systemctl is-enabled filebeat

二、查看日志(排查问题最有用)

Filebeat 日志位置

journalctl -u filebeat -f

或查看日志文件(取决于配置):

/var/log/filebeat/filebeat

三、确认 Filebeat 进程是否存在

ps aux | grep filebeat

或

pgrep -a filebeat

四、直接测试 Filebeat 配置和运行状态

1️⃣ 测试配置文件是否正确

filebeat test config

2️⃣ 测试输出(如 ES / Logstash)

filebeat test output

五、查看 Filebeat 采集情况(高级)

查看 registry(已采集文件进度)

cat /var/lib/filebeat/registry/filebeat/data.json | jq

(如果没有 jq:apt install jq)


六、如果是 Docker 运行的 Filebeat

docker ps | grep filebeat
docker logs -f filebeat

七、快速自查清单 ✅

  • [ ] systemctl status filebeat 是 running
  • [ ] filebeat test config 无报错
  • [ ] 日志中没有 error / cannot connect
  • [ ] 目标(ES / Kafka / Logstash)能收到数据

如果你愿意,可以把 systemctl status filebeat 或日志报错贴出来,我可以帮你具体看是哪一步有问题。

0 踩