在 Debian 系统上,验证 Filebeat 的状态通常可以从 服务状态、进程、日志、配置测试、数据输出 几个方面入手。下面按常用方式逐步说明。
Filebeat 一般通过 systemd 管理:
systemctl status filebeat
正常输出应类似:
active (running)查看是否开机自启:
systemctl is-enabled filebeat
ps aux | grep filebeat
或:
pgrep -a filebeat
journalctl -u filebeat -f
tail -f /var/log/filebeat/filebeat
重点关注:
Connection to ... refusedNo such file or directoryharvester started / closedfilebeat test config
输出:
Config OK
测试输出目标(如 Elasticsearch / Logstash):
filebeat test output
在 filebeat.yml 中:
http.enabled: true
http.port: 5066
然后:
curl http://localhost:5066/stats
ls -l /var/lib/filebeat/registry
GET filebeat-*/_search
| 状态 | 判断方式 |
|---|---|
| 正常运行 | systemctl status 为 running,日志无错误 |
| 配置错误 | filebeat test config 报错 |
| 无数据 | 日志无 harvester,或 output 不通 |
| 文件未读取 | 检查 paths 与文件权限 |
如果你愿意,可以贴出:
filebeat.yml 关键配置systemctl status filebeat 输出我可以帮你具体分析。