参考文章:https://blog.youkuaiyun.com/wp500/article/details/41040213
1.下载logstash6.4.0
下载页面:https://www.elastic.co/cn/downloads/logstash
下载地址:https://artifacts.elastic.co/downloads/logstash/logstash-6.4.0.tar.gz
2.解压到任意目录
tar -zxvf logstash-6.4.0.tar.gz
3.修改配置文件
vim config/logstash-es.conf
#注意要设置编码格式,防止中文乱码
input {
beats {
port => 5044
codec => json{ charset => "UTF-8" }
}
}
output {
elasticsearch {
hosts => ["http://192.168.200.201:9201","http://192.168.200.202:9201","http://192.168.200.203:9201"]
index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
#user => "elastic"
#password => "changeme"
}
}
4.启动服务
#控制台启动,且输出日志
bin/logstash -f logstash-es.conf
#后台启动
bin/logstash -f config/logstash-es.conf &