logstash使用filebeat作为日志源

logstash配置:

input {
  beats {
    port => 5044
    host => "0.0.0.0"
  }
}

output{
  kafka{
    bootstrap_servers => "log1:9092"
    topic_id => "test_kafka"
  }
}

启动logstash

nohup ./logstash -f test.conf &

 

filebeat配置:

filebeat.inputs:
- type: log
  enabled: true
  paths:
   - /var/log/messages

name: "log1"
output.logstash:
 hosts: ["10.0.0.6:5044"]
logging.level: debug

启动filebeat

nohup ./filebeat -e -c filebeat.yml &

 

新建一个终端生成日志,然后观察kafka

相关文章

发表新评论