下面按常见场景给你说明:在 Debian 上如何使用 Filebeat 转发日志(最典型是转发到 Logstash / Elasticsearch / Kafka)。
sudo apt update
sudo apt install filebeat -y
或者使用官方仓库(推荐):
curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-8.x.x-amd64.deb
sudo dpkg -i filebeat-8.x.x-amd64.deb
配置文件位置:
/etc/filebeat/filebeat.yml
Filebeat 转发主要分两部分:
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
- /var/log/nginx/*.log
output.logstash:
hosts: ["logstash-server:5044"]
Logstash 默认接收端口是 5044(Beats input)
sudo systemctl enable filebeat
sudo systemctl start filebeat
sudo systemctl status filebeat
output.elasticsearch:
hosts: ["http://elasticsearch:9200"]
username: "elastic"
password: "your_password"
(可选)指定索引:
setup.template.name: "filebeat"
setup.template.pattern: "filebeat-*"
output.kafka:
hosts: ["kafka1:9092", "kafka2:9092"]
topic: "filebeat-logs"
sudo filebeat test config
sudo filebeat test output
sudo filebeat -e -c /etc/filebeat/filebeat.yml
enabled: truejournalctl -u filebeat -f
rm -rf /var/lib/filebeat/registry
systemctl restart filebeat
应用日志
↓
Filebeat(Debian)
↓
Logstash / ES / Kafka
如果你能告诉我:
我可以给你一份可直接用的 filebeat.yml。