实战
logstash配置
input {
#stdin {}
beats {
port => 5044
}
}
output {
elasticsearch {
hosts => ["192.168.126.17:9200"]
#index=>"linux-varlog-%{+YYYY.MM.dd}"
}
stdout { codec => rubydebug }
}
filebeat配置
# filebeat.yml
filebeat.prospectors:
- input_type: log
paths:
- /var/log/*.log
encoding: utf-8
output.logstash:
hosts: ["192.168.126.17:5044"]
elasticsearch配置
# filename : config/elasticsearch.yml
node.name: t17
path.data: ./data
path.logs: ./logs
network.host: 192.168.126.17
http.cors.enabled: true
http.cors.allow-origin: "*"