下面以 Debian 系列(Debian 10/11/12,Ubuntu 类似) 为例,说明 Filebeat 的安装与基础配置。
sudo apt update
sudo apt install -y curl gnupg apt-transport-https
# 导入 Elastic GPG Key
curl -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elastic-keyring.gpg
# 添加仓库
echo "deb [signed-by=/usr/share/keyrings/elastic-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-8.x.list
# 安装
sudo apt update
sudo apt install -y filebeat
如使用 7.x 版本,把
8.x改为7.x
/etc/filebeat/
├── filebeat.yml # 主配置
└── modules.d/ # 模块配置
filebeat.inputs:
- type: filestream
id: nginx-access
paths:
- /var/log/nginx/access.log
output.elasticsearch:
hosts: ["http://localhost:9200"]
username: "elastic"
password: "your_password"
setup.kibana:
host: "http://localhost:5601"
Elasticsearch 8.x 默认开启安全认证
7.x 可不加 username / password
sudo filebeat modules enable nginx
sudo nano /etc/filebeat/modules.d/nginx.yml
示例:
- module: nginx
access:
enabled: true
var.paths: ["/var/log/nginx/access.log"]
error:
enabled: true
var.paths: ["/var/log/nginx/error.log"]
# 初始化索引模板(首次)
sudo filebeat setup
# 启动服务
sudo systemctl enable filebeat
sudo systemctl start filebeat
# 查看状态
sudo systemctl status filebeat
output.logstash:
hosts: ["localhost:5044"]
Logstash 需配置 beats input:
input {
beats {
port => 5044
}
}
Filebeat 需要读取日志:
sudo usermod -aG adm filebeat
journalctl -u filebeat -f
sudo filebeat test config
sudo filebeat test output
如果你有 具体使用场景(如 Docker、Kubernetes、系统日志、Elasticsearch 版本),我可以给你更精确的配置示例。