在 Debian 下 Filebeat 占用 CPU / 内存 / IO 过高,通常不是“Bug”,而是配置或运行环境导致的。下面按常见原因 → 排查方法 → 解决办法给你梳理。
paths:
- /var/log/*
或:
- /var/log/**/*.log
问题:
✅ 解决:
paths:
- /var/log/nginx/access.log
- /var/log/syslog
exclude_files: ['.gz$', '.zip$']
例如:
表现:
✅ 解决:
harvester 限制harvester_limit: 10
multiline.pattern: '^\['
multiline.match: after
问题:
✅ 解决:
multiline.timeout: 5s
Filebeat 会:
✅ 检查:
filebeat test output
✅ 解决:
queue.mem:
events: 4096
如果你同时:
/var/log/syslogjournald✅ 建议只保留一种
✅ 解决:
clean_inactive: 72h
ignore_older: 24h
老版本有已知性能问题
✅ 检查:
filebeat version
✅ 建议:
top -p $(pgrep filebeat)
filebeat export config
filebeat -e -d "*"
curl localhost:5066/stats
filebeat.inputs:
- type: log
paths:
- /var/log/nginx/*.log
exclude_files: ['.gz$']
harvester_limit: 10
output.elasticsearch:
hosts: ["http://es:9200"]
你可以贴:
filebeat.ymltop 截图我可以直接帮你定位是哪一条配置在吃资源。