在 CentOS 上设置 Filebeat 采集路径,主要是通过修改 Filebeat 的配置文件(通常是 /etc/filebeat/filebeat.yml)来指定 inputs 的路径。
下面给你一个完整、常用的配置示例。
/etc/filebeat/filebeat.yml
编辑配置文件:
vim /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/nginx/access.log
- /var/log/nginx/error.log
- /data/logs/app/*.log
paths:
- /data/logs/**/*.log
**表示递归所有子目录
output.elasticsearch:
hosts: ["http://localhost:9200"]
或输出到 Logstash:
output.logstash:
hosts: ["localhost:5044"]
systemctl restart filebeat
systemctl enable filebeat
查看状态:
systemctl status filebeat
filebeat test config
filebeat test output
检查:
enabled: true临时关闭 SELinux 测试:
setenforce 0
如果你有 具体日志路径 / 输出方式(ES / Kafka / Logstash),我可以帮你写一份可直接用的配置。