在 CentOS 上“调试 Filebeat”通常分为几个层面:看日志、看状态、看配置是否生效、看能不能把数据发到后端(Elasticsearch / Logstash / Kafka)。下面按实用顺序给你一套排查思路。
systemctl status filebeat
如果没启动:
systemctl start filebeat
systemctl enable filebeat
看进程:
ps -ef | grep filebeat
filebeat -e -d "*" -c /etc/filebeat/filebeat.yml
参数说明:
-e:输出到标准错误(终端)-d "*":打开所有 debug-c:指定配置文件⚠️ 会非常详细,适合排错
编辑 /etc/filebeat/filebeat.yml:
logging.level: debug
logging.to_files: true
logging.files:
path: /var/log/filebeat
name: filebeat
keepfiles: 7
然后重启:
systemctl restart filebeat
查看日志:
tail -f /var/log/filebeat/filebeat
filebeat test config
输出:
Config OK
filebeat test output
验证是否能连上 Elasticsearch / Logstash。
filebeat export config
或:
curl http://localhost:5066/stats
(如果开了 http 监控)
Filebeat 记录读取位置:
cat /var/lib/filebeat/registry/filebeat/data.json | jq
或:
ls -l /var/lib/filebeat/registry/
如果你发现 offset 不更新,说明:
临时关闭测试:
setenforce 0
永久解决:
ausearch -m avc -ts recent
setsebool -P filebeat_read_logs on
确保 filebeat 用户能读日志:
ls -l /var/log/xxx.log
id filebeat
测试后端连通性:
telnet es-host 9200
curl http://es-host:9200
curl 'http://localhost:9200/_cat/indices?v'
或:
curl 'http://localhost:9200/filebeat-*/_count'
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/test.log
output.console:
pretty: true
直接前台跑:
filebeat -e -c filebeat.yml
如果你愿意,可以把:
贴出来,我可以帮你精准定位问题。