ELK搭建

一、创建swap空间

[root@jiaxin swap]# cd /mnt/swap/
[root@jiaxin swap]# dd if=/dev/zero of=swapfile bs=1M count=4096
[root@jiaxin swap]# mkswap swapfile 
[root@jiaxin swap]# swapon swapfile

开现自挂载

[root@jiaxin swap]# vim /etc/fstab 
/mnt/swap/swapfile swap swap defaults 0 0

让系统积极使用swap空间

[root@jiaxin swap]# cat /proc/sys/vm/swappiness 
0
[root@jiaxin swap]# vim /etc/sysctl.conf 
vm.swappiness=100
[root@jiaxin swap]# sysctl -p
[root@jiaxin swap]# cat /proc/sys/vm/swappiness 
100

安装JDK
官网:https://www.oracle.com/technetwork/java/javase/downloads/jdk8-downloads-2133151.html

[root@jiaxin src]# wget https://download.oracle.com/otn-pub/java/jdk/8u191-b12/2787e4a523244c269598db4e85c51e0c/jdk-8u191-linux-x64.tar.gz?AuthParam=1546066225_ea0f756f9c5ee46830a068eac225e345
[root@jiaxin src]# tar xf jdk-8u191-linux-x64.tar.gz
[root@jiaxin src]# mv jdk1.8.0_191/ /usr/java/jdk1.8
[root@jiaxin src]# vim /etc/profile
##################JDK########################
JDK_HOME=/usr/java/jdk1.8
JRE_HMOE=$JDK_HOME/jre
PATH=$PATH:$JDK_HOME/bin:$JRE_HOME/bin
CLASSPATH=.:$JDK_HOME/lib/dt.jar:$JDK_HOME/lib/tools.jar
[root@jiaxin src]# source /etc/profile
[root@jiaxin src]# java -version
java version "1.8.0_191"
Java(TM) SE Runtime Environment (build 1.8.0_191-b12)
Java HotSpot(TM) 64-Bit Server VM (build 25.191-b12, mixed mode)

二、下载安装kibana
官网:https://www.elastic.co/downloads/kibana

[root@jiaxin swap]# cd /usr/local/src/
[root@jiaxin src]# wget https://artifacts.elastic.co/downloads/kibana/kibana-6.5.4-linux-x86_64.tar.gz
[root@jiaxin src]# tar xf kibana-6.5.4-linux-x86_64.tar.gz 
[root@jiaxin src]# mv kibana-6.5.4-linux-x86_64 /usr/local/kibana
[root@jiaxin src]# cd /usr/local/kibana/
[root@jiaxin kibana]# vim config/kibana.yml
server.port: 5601
server.host: "0.0.0.0"
elasticsearch.url: "http://localhost:9200"
kibana.index: ".kibana"

后台运行kibana

[root@jiaxin kibana]# nohup ./bin/kibana &

访问url:
http://47.99.89.247:5601/
Kibana server is not ready yet
正常~!
三、下载安装elasticsearch

[root@jiaxin src]# wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.5.4.tar.gz
[root@jiaxin src]# tar xf elasticsearch-6.5.4.tar.gz 
[root@jiaxin src]# mv elasticsearch-6.5.4 /usr/local/elasticsearch
[root@jiaxin src]# cd /usr/local/elasticsearch/
[root@jiaxin elasticsearch]# vim config/elasticsearch.yml
path.data: /path/to/data
path.logs: /path/to/logs
network.host: 0.0.0.0
http.port: 9200
[root@jiaxin local]# groupadd elasticsearch
[root@jiaxin local]# useradd -r -g elasticsearch elasticsearch
[root@jiaxin local]# chown -R elasticsearch:elasticsearch elasticsearch/
[root@jiaxin local]# chown -R elasticsearch:elasticsearch /path/
[root@jiaxin local]# vim /etc/security/limits.conf 
* soft nofile 65536
* soft nofile 65536
* soft nofile 65536
* hard nofile 65536
[root@jiaxin local]# ulimit -u 4096
[root@jiaxin local]# vim /etc/sysctl.conf 
vm.max_map_count = 262144
[root@jiaxin local]# sysctl  -p
[root@jiaxin local]# vim /etc/security/limits.d/20-nproc.conf
*       soft    nproc     unlimited
[root@jiaxin local]# su elasticsearch
bash-4.2$ cd elasticsearch/
bash-4.2$ ./bin/elasticsearch &

打开URLhttp://47.99.89.247:5601/app/kibana#/home?_g=()

四、下载安装logstash

[root@jiaxin src]# wget https://artifacts.elastic.co/downloads/logstash/logstash-6.5.4.tar.gz
[root@jiaxin src]# mv logstash-6.5.4 /usr/local/logstash
[root@jiaxin src]# cd /usr/local/logstash/
[root@jiaxin logstash]# vim config/logstash.yml
http.host: "0.0.0.0"
[root@jiaxin logstash]# vim nginx.conf
input {
        beats {
                port => 5044
        }
}

output {
        elasticsearch {
                hosts => ["127.0.0.1:9200"]
                index => "haha"
        }
}
[root@jiaxin logstash]# ./bin/logstash -f nginx.conf

五、客户端服务器安装 filebeat

[root@sannian src]# wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-6.5.4-linux-x86_64.tar.gz
[root@sannian src]# mv filebeat-6.5.4-linux-x86_64 /usr/local/filebeat
[root@sannian src]# cd /usr/local/filebeat/
[root@sannian filebeat]# vim filebeat.yml
filebeat.inputs:
- type: log
  enabled: true
  multiline.pattern: '^baseLog INFO'
  multiline.negate: true
  multiline.match: after
  paths:
    - /work/var/baseLog/*.log

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 5

output.logstash:
  hosts: ["47.99.89.247:5044"]
[root@sannian filebeat]# /usr/local/filebeat/filebeat -e -c /usr/local/filebeat/filebeat.yml 
ELK是指Elasticsearch、Logstash和Kibana这三个开源软件的组合,用于构建实时数据分析和可视化的日志收集系统。ELK平台的搭建可以在Windows环境下进行。根据引用\[1\],在Windows 11环境下,可以使用logstash 8.0.0、elasticsearch 8.0.0和kibana 8.0.0进行搭建。 首先,需要下载elasticsearch、logstash、kibana和filebeat。根据引用\[2\],这些软件可以免费下载并使用。 接下来,打开一个新的shell,并执行命令切换到elk软件的安装目录。根据引用\[3\],可以使用类似以下命令切换到kibana的安装目录: ``` cd F:\soft\elk .\kibana-7.16.0-windows-x86_64\kibana-7.16.0-windows-x86_64\bin\kibana.bat ``` 以上是在Windows系统下搭建ELK平台的简要步骤。具体的配置和使用方法可以参考相关文档或教程。 #### 引用[.reference_title] - *1* [Windows环境下搭建完整的ELK平台](https://blog.youkuaiyun.com/m0_52403371/article/details/129894030)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^insertT0,239^v3^insert_chatgpt"}} ] [.reference_item] - *2* *3* [ELK搭建开源日志系统(window版本)—图文详细](https://blog.youkuaiyun.com/likewiehyou/article/details/124438761)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^insertT0,239^v3^insert_chatgpt"}} ] [.reference_item] [ .reference_list ]
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值