logstash使用filebeat作为日志源
警告
本文最后更新于 2020-05-30 17:09,文中内容可能已过时。
logstash配置:
input {
beats {
port => 5044
host => "0.0.0.0"
}
}
output{
kafka{
bootstrap_servers => "log1:9092"
topic_id => "test_kafka"
}
}
启动logstash
nohup ./logstash -f test.conf &
filebeat配置:
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/messages
name: "log1"
output.logstash:
hosts: ["10.0.0.6:5044"]
logging.level: debug
启动filebeat
nohup ./filebeat -e -c filebeat.yml &
新建一个终端生成日志,然后观察kafka
data:image/s3,"s3://crabby-images/0c209/0c2095386670a74c9239a52c80588272d4211c8f" alt=""
请我喝杯水
data:image/s3,"s3://crabby-images/640a0/640a082a41628b86e5c3b816e806c59511ead8ba" alt="SoulChild 微信号"
data:image/s3,"s3://crabby-images/22c96/22c96b8b2675894b486306994c0f75b2b8f9f200" alt="SoulChild 微信打赏"