在 CentOS 上“迁移 Filebeat 数据”通常分几种场景,先说明你属于哪一种,再给你对应做法。
Filebeat 本身不存储业务日志,它主要是:
registry 文件(最重要)
记录“日志读到哪了”,防止重复采集或漏采
默认路径:
/var/lib/filebeat/registry
(Filebeat 7+ 是 registry/ 目录)
配置文件
/etc/filebeat/filebeat.yml
模块配置(如有)
/etc/filebeat/modules.d/
证书文件(如果用了 TLS)
/etc/filebeat/certs/
日志文件(非必须)
/var/log/filebeat/
目标:新机器继续从“旧机器读到的位置”采集
# 停止 filebeat
systemctl stop filebeat
# 打包关键数据
tar czf filebeat-migrate.tar.gz \
/etc/filebeat \
/var/lib/filebeat/registry \
/var/log/filebeat
传到新机器:
scp filebeat-migrate.tar.gz root@new-server:/root/
# 安装同版本 filebeat
yum install filebeat -y
# 停止服务
systemctl stop filebeat
# 覆盖配置和数据
tar xzf filebeat-migrate.tar.gz -C /
# 启动
systemctl start filebeat
systemctl enable filebeat
✅ registry 保留 → 不会重复采集
适合:
/etc/filebeat/filebeat.yml
/etc/filebeat/modules.d/
直接拷贝即可,不需要 registry
如果你意思是:
“Filebeat 发到 ES 的数据怎么迁移”
那是 Elasticsearch 数据迁移,不是 Filebeat
常见方式:
⚠️ 注意:
registry 格式变了建议:
# 升级前
systemctl stop filebeat
cp -r /var/lib/filebeat /var/lib/filebeat.bak
# 查看状态
systemctl status filebeat
# 看日志
journalctl -u filebeat -f
# 看 registry
ls -l /var/lib/filebeat/registry
你可以告诉我:
我可以直接给你一条命令搞定版的迁移方案。