下面给你一个在 Debian 上用 Filebeat 收集日志的完整实践指南,从安装到常见场景配置,偏实战。
root 或 sudo 权限/var/log/*.log)sudo apt update
sudo apt install -y curl gnupg apt-transport-https
导入 Elastic GPG Key:
curl -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elastic-keyring.gpg
添加仓库(以 8.x 为例):
echo "deb [signed-by=/usr/share/keyrings/elastic-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" \
| sudo tee /etc/apt/sources.list.d/elastic-8.x.list
安装 Filebeat:
sudo apt update
sudo apt install filebeat
配置文件位置:
/etc/filebeat/filebeat.yml
filebeat.inputs:
- type: filestream
id: system-log
paths:
- /var/log/syslog
- /var/log/auth.log
output.elasticsearch:
hosts: ["http://localhost:9200"]
username: "elastic"
password: "your_password"
或输出到 Logstash:
output.logstash:
hosts: ["localhost:5044"]
Filebeat 自带很多模块(nginx、system、mysql 等)
filebeat modules list
sudo filebeat modules enable system
sudo nano /etc/filebeat/modules.d/system.yml
示例:
- module: system
syslog:
enabled: true
auth:
enabled: true
sudo filebeat test config
sudo filebeat setup
sudo systemctl enable filebeat
sudo systemctl start filebeat
systemctl status filebeat
journalctl -u filebeat -f
filebeat.inputs:
- type: filestream
id: app-log
paths:
- /opt/myapp/logs/*.log
fields:
app: myapp
fields_under_root: true
filebeat.inputs:
- type: container
paths:
- '/var/lib/docker/containers/*/*.log'
journalctl -u filebeat -n 100
sudo usermod -aG adm filebeat
log 而不是 filestreamFilebeat 7.16+ 建议使用 filestream
日志文件 → Filebeat → Logstash / ES → Kibana
如果你愿意,我可以:
直接说你的使用场景即可。