ELK--Logstash 安装
中国镜像:https://www.newbe.pro/Mirrors/Mirrors-Logstash/
https://mirrors.huaweicloud.com/logstash/6.4.1/
1.下载logstash安装包
wget https://mirrors.huaweicloud.com/logstash/6.4.1/logstash-6.4.1.tar.gz
2.解压安装包
tar -xvf logstash-6.4.1.tar.gz
安装包结构:
3.配置Logstash
要配置Logstash,需要创建一个配置文件,指定要使用的插件和每个插件的设置,运行logstash时,使用-f指定配置文件。官网demo:https://www.elastic.co/guide/en/logstash/current/config-examples.html
3.1 直接启动
bin/logstash -e 'input { stdin {} } output { stdout{} }'
bin/logstash -e 'input { stdin {} } output { stdout{codec => ouyangcheng} }'
bin/logstash -e 'input { stdin {} } output { elasticsearch {hosts => ["127.0.0.1:9200"]} stdout{} }'
bin/logstash -e 'input { stdin {} } output { elasticsearch {hosts => ["192.168.0.101:9200", "192.168.0.102:9200"]} stdout{} }'
3.2 以配置文件的形式
3.2.1 编辑配置文件:vim logstash-comcat.config
input {
file {
type => "tomcatlog"
path => "/home/data/logs/*/*.log"
discover_interval => 10
}
}
output {
elasticsearch {
index => "tomcat-%{+YYYY.MM.dd}"
hosts => ["127.0.0.1:9200"]
}
}
3.2.2 启动logstack
sh bin/logstash -f logstash-comcat.config
3.2.3 msyql 数据同步
(1)编辑mysql配置文件
vim logstash-mysql.config
(2)文件内容为:
input {
stdin {}
jdbc {
type => "jdbc"
jdbc_user => "root"
jdbc_password => "123456"
jdbc_driver_library => "/home/data/soft/logstash-6.4.1/mysql-connector-java-8.0.13.jar"
jdbc_driver_class => "com.mysql.jdbc.Driver"
statement => "SELECT * from t_blog where update_time >= :sql_last_value"
tracking_column => "update_time"
clean_run => true
schedule => "* * * * *"
jdbc_connection_string => "jdbc:mysql://127.0.0.1:3306/oyc?characterEncoding=UTF-8"
}
}
output {
elasticsearch {
hosts => ["127.0.0.1:9200"]
index => "blog"
document_id => "%{id}"
document_type => "blog"
}
stdout {
codec => json_lines
}
}
(3) 启动
nohup sh bin/logstash -f logstash-mysql.config &
(4) 效果
同步数据:
使用kibana查询数据:
更多案例可参考 gitbook使用手册:http://doc.yonyoucloud.com/doc/logstash-best-practice-cn/index.html
https://blog.youkuaiyun.com/qq_38270106/article/details/88699334