温馨提示×

filebeat在debian如何收集日志

小樊
37
2026-10-09 09:06:15
栏目: 智能运维

下面给你一个在 Debian 上用 Filebeat 收集日志的完整实践指南,从安装到常见场景配置,偏实战。


一、环境准备

1. 系统要求

  • Debian 10 / 11 / 12
  • 已具备 root 或 sudo 权限
  • 日志文件存在(如 /var/log/*.log)

二、安装 Filebeat(Debian)

方式一:使用官方 APT 仓库(推荐)

sudo apt update
sudo apt install -y curl gnupg apt-transport-https

导入 Elastic GPG Key:

curl -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elastic-keyring.gpg

添加仓库(以 8.x 为例):

echo "deb [signed-by=/usr/share/keyrings/elastic-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" \
| sudo tee /etc/apt/sources.list.d/elastic-8.x.list

安装 Filebeat:

sudo apt update
sudo apt install filebeat

三、Filebeat 核心配置文件

配置文件位置:

/etc/filebeat/filebeat.yml

四、基础示例:收集系统日志

1. 编辑配置

filebeat.inputs:
  - type: filestream
    id: system-log
    paths:
      - /var/log/syslog
      - /var/log/auth.log

output.elasticsearch:
  hosts: ["http://localhost:9200"]
  username: "elastic"
  password: "your_password"

或输出到 Logstash:

output.logstash:
  hosts: ["localhost:5044"]

五、启用 Filebeat 模块(推荐)

Filebeat 自带很多模块(nginx、system、mysql 等)

查看可用模块

filebeat modules list

启用系统模块

sudo filebeat modules enable system

配置模块

sudo nano /etc/filebeat/modules.d/system.yml

示例:

- module: system
  syslog:
    enabled: true
  auth:
    enabled: true

六、初始化并启动

1. 测试配置

sudo filebeat test config

2. 加载索引模板(ES 用户)

sudo filebeat setup

3. 启动服务

sudo systemctl enable filebeat
sudo systemctl start filebeat

4. 查看状态

systemctl status filebeat
journalctl -u filebeat -f

七、收集自定义日志(如应用日志)

filebeat.inputs:
  - type: filestream
    id: app-log
    paths:
      - /opt/myapp/logs/*.log
    fields:
      app: myapp
    fields_under_root: true

八、Docker 日志收集(常见)

filebeat.inputs:
  - type: container
    paths:
      - '/var/lib/docker/containers/*/*.log'

九、常见问题排查

1. 没有数据?

journalctl -u filebeat -n 100

2. 文件权限问题

sudo usermod -aG adm filebeat

3. 旧版本使用 log 而不是 filestream

Filebeat 7.16+ 建议使用 filestream


十、典型架构示意

日志文件 → Filebeat → Logstash / ES → Kibana

如果你愿意,我可以:

  • 给你 nginx / mysql / java 应用 的示例
  • 帮你 对接 Kafka / Loki
  • 按你的 Debian 版本 + ES 版本 精确配置

直接说你的使用场景即可。

0 踩