温馨提示×

ubuntu filebeat如何对接es

小樊
40
2026-09-20 11:10:16
栏目: 智能运维

在 Ubuntu 上让 Filebeat 对接 Elasticsearch(ES),一般步骤如下(以 Filebeat 8.x + Elasticsearch 8.x 为例,7.x 也类似)。


一、环境准备

  • Ubuntu 20.04 / 22.04
  • 已运行的 Elasticsearch(HTTP 或 HTTPS)
  • 可选:Kibana(用于查看数据)

二、安装 Filebeat(Ubuntu)

1. 使用 APT 安装(推荐)

sudo apt update
sudo apt install filebeat -y

安装后配置文件路径:

/etc/filebeat/filebeat.yml

三、配置 Filebeat 对接 ES

1. 编辑配置文件

sudo vim /etc/filebeat/filebeat.yml

2. 基础配置示例(无安全认证)

filebeat.inputs:
  - type: log
    enabled: true
    paths:
      - /var/log/*.log

output.elasticsearch:
  hosts: ["http://192.168.1.100:9200"]

3. Elasticsearch 启用安全认证(ES 8.x 默认)

如果你使用的是 ES 8.x(默认开启 TLS + 安全):

(1)拷贝 ES 证书到 Filebeat

sudo mkdir -p /etc/filebeat/certs
sudo cp ca.crt /etc/filebeat/certs/

(2)修改 filebeat.yml

output.elasticsearch:
  hosts: ["https://192.168.1.100:9200"]
  username: "elastic"
  password: "your_password"
  ssl:
    certificate_authorities: ["/etc/filebeat/certs/ca.crt"]

四、加载索引模板(重要)

1. 测试配置

sudo filebeat test config
sudo filebeat test output

2. 加载模板和 ILM

sudo filebeat setup --index-management

(如果使用了 Kibana)

sudo filebeat setup -e \
  -E output.elasticsearch.hosts=["https://192.168.1.100:9200"] \
  -E output.elasticsearch.username=elastic \
  -E output.elasticsearch.password=your_password \
  -E setup.kibana.host=https://192.168.1.101:5601

五、启动 Filebeat

sudo systemctl enable filebeat
sudo systemctl start filebeat
sudo systemctl status filebeat

六、验证数据是否进入 ES

1. 查询索引

curl -u elastic:password https://192.168.1.100:9200/_cat/indices?v

你会看到类似:

filebeat-8.x.x-2026.01.15

2. Kibana 中查看

  • Stack Management → Index Patterns
  • 创建 filebeat-*
  • Discover 查看日志

七、常见问题

1. 时间字段不对

setup.template.settings:
  index.number_of_shards: 1

2. 权限问题

  • 确保 filebeat 用户能读日志
sudo usermod -aG adm filebeat

3. 多行日志(如 Java 异常)

multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
multiline.negate: true
multiline.match: after

八、最简示例(快速测试)

filebeat.inputs:
  - type: log
    paths:
      - /tmp/test.log

output.elasticsearch:
  hosts: ["http://localhost:9200"]
echo "hello es" >> /tmp/test.log

如果你愿意,可以告诉我:

  • ES 版本(7.x / 8.x)
  • 是否启用 HTTPS / 安全认证
  • 日志类型(系统日志 / Nginx / 应用日志)

我可以给你一份 完全可直接用的配置文件。

0 踩