logstash使用filebeat作为日志源
警告
本文最后更新于 2020-05-30 17:09,文中内容可能已过时。
logstash配置:
input {
beats {
port => 5044
host => "0.0.0.0"
}
}
output{
kafka{
bootstrap_servers => "log1:9092"
topic_id => "test_kafka"
}
}
启动logstash
nohup ./logstash -f test.conf &
filebeat配置:
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/messages
name: "log1"
output.logstash:
hosts: ["10.0.0.6:5044"]
logging.level: debug
启动filebeat
nohup ./filebeat -e -c filebeat.yml &
新建一个终端生成日志,然后观察kafka

请我喝杯水

