在 CentOS 上,Filebeat 本身具备自动重连机制,一般不需要手动干预。下面分几种常见场景说明“重连”怎么做、以及如果“不重连”该怎么处理。
Filebeat 默认配置:
output.elasticsearch:
hosts: ["http://localhost:9200"]
或
output.logstash:
hosts: ["localhost:5044"]
当后端不可用时:
backoff 控制output.elasticsearch:
hosts: ["http://es1:9200","http://es2:9200"]
backoff.init: 1s
backoff.max: 60s
worker: 2
说明:
backoff.init:首次重试等待时间backoff.max:最大重试间隔systemctl status filebeat
systemctl start filebeat
systemctl enable filebeat
⚠️ Filebeat 没有 restart-reconnect 命令,只能重启进程
systemctl restart filebeat
pkill filebeat
/usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml
journalctl -u filebeat -f
或
tail -f /var/log/filebeat/filebeat
常见错误:
connection refusedEOFi/o timeout# 防火墙
firewall-cmd --list-all
# SELinux
getenforce
timedatectl
ntpdate pool.ntp.org
output.kafka:
hosts: ["kafka1:9092","kafka2:9092"]
topic: logs
backoff: 1s
Kafka 断连也会自动重连。
CentOS 上 Filebeat 不需要手动重连,断线会自动重连;如果“不连”,90% 是服务没跑或后端地址/防火墙问题。
如果你愿意,可以贴一下:
filebeat.yml 的 output 部分systemctl status filebeat我可以帮你精准定位。