在 Ubuntu 上让 Filebeat 对接 Elasticsearch(ES),一般步骤如下(以 Filebeat 8.x + Elasticsearch 8.x 为例,7.x 也类似)。
sudo apt update
sudo apt install filebeat -y
安装后配置文件路径:
/etc/filebeat/filebeat.yml
sudo vim /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
output.elasticsearch:
hosts: ["http://192.168.1.100:9200"]
如果你使用的是 ES 8.x(默认开启 TLS + 安全):
sudo mkdir -p /etc/filebeat/certs
sudo cp ca.crt /etc/filebeat/certs/
output.elasticsearch:
hosts: ["https://192.168.1.100:9200"]
username: "elastic"
password: "your_password"
ssl:
certificate_authorities: ["/etc/filebeat/certs/ca.crt"]
sudo filebeat test config
sudo filebeat test output
sudo filebeat setup --index-management
(如果使用了 Kibana)
sudo filebeat setup -e \
-E output.elasticsearch.hosts=["https://192.168.1.100:9200"] \
-E output.elasticsearch.username=elastic \
-E output.elasticsearch.password=your_password \
-E setup.kibana.host=https://192.168.1.101:5601
sudo systemctl enable filebeat
sudo systemctl start filebeat
sudo systemctl status filebeat
curl -u elastic:password https://192.168.1.100:9200/_cat/indices?v
你会看到类似:
filebeat-8.x.x-2026.01.15
filebeat-*setup.template.settings:
index.number_of_shards: 1
sudo usermod -aG adm filebeat
multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
multiline.negate: true
multiline.match: after
filebeat.inputs:
- type: log
paths:
- /tmp/test.log
output.elasticsearch:
hosts: ["http://localhost:9200"]
echo "hello es" >> /tmp/test.log
如果你愿意,可以告诉我:
我可以给你一份 完全可直接用的配置文件。