Elastic Stack安装 - Filebeat

环境:

OS: Centos 7.6

JDK: 1.8.0_91

下载地址:

https://artifacts.elastic.co/downloads/beats/heartbeat/heartbeat-7.4.2-linux-x86_64.tar.gz
https://artifacts.elastic.co/downloads/beats/packetbeat/packetbeat-7.4.2-linux-x86_64.tar.gz
https://artifacts.elastic.co/downloads/beats/metricbeat/metricbeat-7.4.2-linux-x86_64.tar.gz
https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.4.2-linux-x86_64.tar.gz
https://artifacts.elastic.co/downloads/logstash/logstash-7.4.2.tar.gz
https://artifacts.elastic.co/downloads/kibana/kibana-7.4.2-linux-x86_64.tar.gz
https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.4.2-linux-x86_64.tar.gz

安装Filebeat


tar -xzvf filebeat-7.4.2-linux-x86_64.tar.gz
cd filebeat-7.4.2-linux-x86_64/

vim filebeat.yml
# 配置如下信息
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log
  multiline.pattern: "^[0-9]{4}-[0-9]{2}-[0-9]{2}"
  multiline.negate: true
  multiline.match: after
  multiline.timeout: 10s


output.elasticsearch:
  hosts: ["myEShost:9200"]
setup.kibana:
  host: "mykibanahost:5601"

# setup dashboards
./filebeat setup --dashboards

# 启动
./filebeat -e -c filebeat.yml -d "publish"

要了解关于安装和配置其他Beat的更多信息,请参阅入门文档:

Elastic Beats To capture
Auditbeat Audit data
Filebeat Log files
Heartbeat Availability monitoring
Metricbeat Metrics
Packetbeat Network traffic
Winlogbeat Windows event logs