在 CentOS 上调试 Filebeat 配置,通常可以按下面几个步骤来做,从配置检查 → 前台运行 → 日志排查 → 输出验证逐步定位问题。
Filebeat 自带配置校验命令,先确认 YAML 没写错:
filebeat test config -c /etc/filebeat/filebeat.yml
如果配置有问题,会直接提示哪一行出错。
如果是输出到 ES 或 Logstash,可以测试连通性:
filebeat test output -c /etc/filebeat/filebeat.yml
示例输出成功:
elasticsearch: https://localhost:9200...
parse url... OK
connection... OK
authentication... OK
停止服务,前台运行,可以看到实时日志:
systemctl stop filebeat
filebeat -e -c /etc/filebeat/filebeat.yml -d "*"
参数说明:
-e:日志输出到终端-c:指定配置文件-d "*":开启所有 debug 日志(也可指定模块,如 -d "publish")观察重点:
调试完 Ctrl+C 退出即可。
如果是通过 systemd 运行:
journalctl -u filebeat -f
或查看日志文件(取决于配置):
tail -f /var/log/filebeat/filebeat
filebeat export config
或启用 HTTP 监控(filebeat.yml):
http.enabled: true
http.host: 0.0.0.0
http.port: 5066
然后访问:
http://<ip>:5066/stats
可以看到:
paths 写错解决:
ls -l /var/log/xxx.log
getenforce # 若是 Enforcing,注意 SELinux
调试:
curl -u elastic:password http://localhost:9200
查看详细错误:
systemctl status filebeat
journalctl -xe
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/test.log
output.console:
pretty: true
然后运行:
filebeat -e -c filebeat.yml
能直接看到事件输出,最快验证配置是否正确。
如果你愿意,可以把你的 filebeat.yml(敏感信息打码) 或具体报错日志贴出来,我可以帮你精确分析。