Elastic Stack之FileBeat使用实战



   本篇博客数据流走向:FileBeat ===》logstash ===> elasticsearch。 






[root@node105 ~]# wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.6.12-x86_64.rpm
---- ::-- https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.6.12-x86_64.rpm
Resolving artifacts.elastic.co (artifacts.elastic.co)..., 2a04:4e42:1a::
Connecting to artifacts.elastic.co (artifacts.elastic.co)||:... connected.
HTTP request sent, awaiting response... OK
Length: (8.8M) [application/octet-stream]
Saving to: ‘filebeat-5.6.-x86_64.rpm’ %[===========================================================================================================================================================>] ,, .9KB/s in 2m 2s -- :: (74.0 KB/s) - ‘filebeat-5.6.-x86_64.rpm’ saved [/] [root@node105 ~]#

[root@node105 ~]# wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.6.12-x86_64.rpm



[root@node105 ~]#
[root@node105 ~]# ll
-rw-r--r--. root root Sep : filebeat-5.6.-x86_64.rpm
-rw-r--r--. root root Mar : GeoLite2-City.tar.gz
-rw-r--r--. root root Sep : logstash-5.6..rpm
[root@node105 ~]#
[root@node105 ~]#
[root@node105 ~]# rpm -ivh filebeat-5.6.-x86_64.rpm
warning: filebeat-5.6.-x86_64.rpm: Header V4 RSA/SHA512 Signature, key ID d88e42b4: NOKEY
Preparing... ################################# [%]
Updating / installing...
:filebeat-5.6.- ################################# [%]
[root@node105 ~]#
[root@node105 ~]#

[root@node105 ~]# rpm -ivh filebeat-5.6.12-x86_64.rpm

[root@node105 ~]#
[root@node105 ~]# rpm -ql filebeat
[root@node105 ~]#

[root@node105 ~]# rpm -ql filebeat


[root@node105 ~]#
[root@node105 ~]#
[root@node105 ~]# cp /etc/filebeat/filebeat.yml{,.bak}
[root@node105 ~]#
[root@node105 ~]# ll /etc/filebeat/
-rw-r--r--. root root Sep : filebeat.full.yml
-rw-r--r--. root root Sep : filebeat.template-es2x.json
-rw-r--r--. root root Sep : filebeat.template-es6x.json
-rw-r--r--. root root Sep : filebeat.template.json
-rw-------. root root Sep : filebeat.yml
-rw-------. root root Mar : filebeat.yml.bak
[root@node105 ~]#
[root@node105 ~]#

[root@node105 ~]# cp /etc/filebeat/filebeat.yml{,.bak}            #备份默认的配置文件

[root@node105 ~]#
[root@node105 ~]# cat /etc/filebeat/filebeat.yml | egrep -v "^#|^$| #"
- input_type: log
- /var/log/httpd/access_log
hosts: ["node105.yinzhengjie.org.cn:5044"]
[root@node105 ~]#
[root@node105 ~]#

[root@node105 ~]# cat /etc/filebeat/filebeat.yml | egrep -v "^#|^$| #"  #只需要修改logstash服务器的地址,以及收集日志的path,别忘记注释掉默认的es集群配置!


[root@node105 conf.d]#
[root@node105 conf.d]# cat beats-filter-elasticsearch.conf
input {
beats {
port =>
} filter {
grok {
match => { "message" => "%{HTTPD_COMBINEDLOG}" }
remove_field => "message"
date {
match => ["timestamp","dd/MMM/YYYY:H:m:s Z"]
remove_field => "timestamp"
geoip {
source => "clientip"
target => "geoip"
database => "/etc/logstash/maxmind/GeoLite2-City.mmdb"
mutate {
rename => {
"agent" => "user_agent"
} output {
elasticsearch {
hosts => ["http://node101.yinzhengjie.org.cn:9200/","http://node102.yinzhengjie.org.cn:9200/","http://node103.yinzhengjie.org.cn:9200/"]
index => "logstash-%{+YYYY.MM.dd}"
document_type => "httpd_access_logs"
} [root@node105 conf.d]#
[root@node105 conf.d]#
[root@node105 conf.d]# logstash -f beats-filter-elasticsearch.conf -t
WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console
Configuration OK
[root@node105 conf.d]#

[root@node105 conf.d]# cat beats-filter-elasticsearch.conf

[root@node105 conf.d]# logstash -f  beats-filter-elasticsearch.conf
WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console
[INFO ] -- ::28.925 [[main]<beats] Server - Starting server on port:

[root@node105 conf.d]# logstash -f beats-filter-elasticsearch.conf        #启动logstash服务

[root@node105 ~]#
[root@node105 ~]# ss -ntl | grep
LISTEN ::: :::*
[root@node105 ~]#

[root@node105 ~]# ss -ntl | grep 5044                          #检查监听端口是否启动,如果启动成功,咱们就可以继续下面的操作啦!


[root@node105 ~]#
[root@node105 ~]# ss -ntl | grep
LISTEN ::: :::*
[root@node105 ~]#
[root@node105 ~]#
[root@node105 ~]#
[root@node105 ~]# systemctl start filebeat
[root@node105 ~]#
[root@node105 ~]# systemctl status filebeat
● filebeat.service - filebeat
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled)
Active: active (running) since Mon -- :: CST; 10s ago
Docs: https://www.elastic.co/guide/en/beats/filebeat/current/index.html
Main PID: (filebeat)
CGroup: /system.slice/filebeat.service
└─ /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebe... Mar :: node105.yinzhengjie.org.cn systemd[]: Started filebeat.
Mar :: node105.yinzhengjie.org.cn systemd[]: Starting filebeat...
[root@node105 ~]#
[root@node105 ~]#

[root@node105 ~]# systemctl start filebeat

[root@node105 ~]#
[root@node105 ~]# ps -ef | grep filebeat | grep -v grep
root : ? :: /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat
[root@node105 ~]#
[root@node105 ~]#

[root@node105 ~]# ps -ef | grep filebeat | grep -v grep              #启动FileBeat后,检查filebeat进程是否存在!


[root@node101 ~]#
[root@node101 ~]# curl -X GET http://node101.yinzhengjie.org.cn:9200/logstash-*/_search?q=response:404 | jq .
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
542k --:--:-- --:--:-- --:--:-- 585k
"took": ,
"timed_out": false,
"_shards": {
"total": ,
"successful": ,
"skipped": ,
"hits": {
"total": ,
"max_score": 2.14398,
"hits": [
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltN80kXxXllWpXYAEc",
"_score": 2.14398,
"_source": {
"request": "/test60.html",
"geoip": {
"timezone": "Asia/Tokyo",
"ip": "",
"latitude": 35.69,
"country_name": "Japan",
"country_code2": "JP",
"continent_code": "AS",
"country_code3": "JP",
"location": {
"lon": 139.69,
"lat": 35.69
"longitude": 139.69
"offset": ,
"auth": "-",
"ident": "-",
"input_type": "log",
"verb": "GET",
"source": "/var/log/httpd/access_log",
"type": "log",
"tags": [
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:02:27.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"beat": {
"name": "node105.yinzhengjie.org.cn",
"hostname": "node105.yinzhengjie.org.cn",
"version": "5.6.12"
"host": "node105.yinzhengjie.org.cn",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltN80kXxXllWpXYAEd",
"_score": 2.14398,
"_source": {
"request": "/test57.html",
"geoip": {
"ip": "",
"latitude": 34.7725,
"country_name": "China",
"country_code2": "CN",
"continent_code": "AS",
"country_code3": "CN",
"location": {
"lon": 113.7266,
"lat": 34.7725
"longitude": 113.7266
"offset": ,
"auth": "-",
"ident": "-",
"input_type": "log",
"verb": "GET",
"source": "/var/log/httpd/access_log",
"type": "log",
"tags": [
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:02:28.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"beat": {
"name": "node105.yinzhengjie.org.cn",
"hostname": "node105.yinzhengjie.org.cn",
"version": "5.6.12"
"host": "node105.yinzhengjie.org.cn",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltEA3lXxXllWpXYACI",
"_score": 2.14398,
"_source": {
"request": "/test52.html",
"geoip": {
"timezone": "Europe/Paris",
"ip": "",
"latitude": 48.6942,
"continent_code": "EU",
"city_name": "Brunoy",
"country_name": "France",
"country_code2": "FR",
"country_code3": "FR",
"region_name": "Essonne",
"location": {
"lon": 2.4922,
"lat": 48.6942
"postal_code": "",
"region_code": "",
"longitude": 2.4922
"auth": "-",
"ident": "-",
"verb": "GET",
"path": "/var/log/httpd/access_log",
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:02:41.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"host": "",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltEAIs3WCT5NaOiwEi",
"_score": 2.14398,
"_source": {
"request": "/test53.html",
"geoip": {
"city_name": "Shanghai",
"timezone": "Asia/Shanghai",
"ip": "",
"latitude": 31.0449,
"country_name": "China",
"country_code2": "CN",
"continent_code": "AS",
"country_code3": "CN",
"region_name": "Shanghai",
"location": {
"lon": 121.4012,
"lat": 31.0449
"region_code": "SH",
"longitude": 121.4012
"auth": "-",
"ident": "-",
"verb": "GET",
"path": "/var/log/httpd/access_log",
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:02:38.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"host": "",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltD9ccXxXllWpXYACF",
"_score": 2.14398,
"_source": {
"request": "/test60.html",
"geoip": {
"timezone": "Asia/Tokyo",
"ip": "",
"latitude": 35.69,
"country_name": "Japan",
"country_code2": "JP",
"continent_code": "AS",
"country_code3": "JP",
"location": {
"lon": 139.69,
"lat": 35.69
"longitude": 139.69
"auth": "-",
"ident": "-",
"verb": "GET",
"path": "/var/log/httpd/access_log",
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:02:27.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"host": "",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltEBmksru-A5a8RIhh",
"_score": 2.14398,
"_source": {
"request": "/test52.html",
"geoip": {
"timezone": "Africa/Accra",
"ip": "",
"latitude": ,
"country_name": "Ghana",
"country_code2": "GH",
"continent_code": "AF",
"country_code3": "GH",
"location": {
"lon": -,
"longitude": -
"auth": "-",
"ident": "-",
"verb": "GET",
"path": "/var/log/httpd/access_log",
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:02:44.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"host": "",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltEMH9XxXllWpXYACa",
"_score": 2.14398,
"_source": {
"request": "/test53.html",
"geoip": {
"timezone": "Europe/Rome",
"ip": "",
"latitude": 42.5245,
"continent_code": "EU",
"city_name": "Piansano",
"country_name": "Italy",
"country_code2": "IT",
"country_code3": "IT",
"region_name": "Provincia di Viterbo",
"location": {
"lon": 11.8298,
"lat": 42.5245
"postal_code": "",
"region_code": "VT",
"longitude": 11.8298
"auth": "-",
"ident": "-",
"verb": "GET",
"path": "/var/log/httpd/access_log",
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:03:28.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"host": "",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltOqroXxXllWpXYAF7",
"_score": 2.14398,
"_source": {
"request": "/test53.html",
"geoip": {
"timezone": "Asia/Ho_Chi_Minh",
"ip": "",
"latitude": ,
"country_name": "Vietnam",
"country_code2": "VN",
"continent_code": "AS",
"country_code3": "VN",
"location": {
"lon": ,
"offset": ,
"auth": "-",
"ident": "-",
"input_type": "log",
"verb": "GET",
"source": "/var/log/httpd/access_log",
"type": "log",
"tags": [
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:49:10.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"beat": {
"name": "node105.yinzhengjie.org.cn",
"hostname": "node105.yinzhengjie.org.cn",
"version": "5.6.12"
"host": "node105.yinzhengjie.org.cn",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltOpdbsru-A5a8RIib",
"_score": 2.14398,
"_source": {
"request": "/test54.html",
"geoip": {
"ip": "",
"latitude": -22.8305,
"country_name": "Brazil",
"country_code2": "BR",
"continent_code": "SA",
"country_code3": "BR",
"location": {
"lon": -43.2192,
"lat": -22.8305
"longitude": -43.2192
"offset": ,
"auth": "-",
"ident": "-",
"input_type": "log",
"verb": "GET",
"source": "/var/log/httpd/access_log",
"type": "log",
"tags": [
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:49:07.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"beat": {
"name": "node105.yinzhengjie.org.cn",
"hostname": "node105.yinzhengjie.org.cn",
"version": "5.6.12"
"host": "node105.yinzhengjie.org.cn",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
"_index": "logstash-2019.03.11",
"_type": "httpd_access_logs",
"_id": "AWltO0cmsru-A5a8RIi5",
"_score": 2.14398,
"_source": {
"request": "/test56.html",
"geoip": {
"city_name": "Taipei",
"timezone": "Asia/Taipei",
"ip": "",
"latitude": 25.0478,
"country_name": "Taiwan",
"country_code2": "TW",
"continent_code": "AS",
"country_code3": "TW",
"region_name": "Taipei City",
"location": {
"lon": 121.5318,
"lat": 25.0478
"region_code": "TPE",
"longitude": 121.5318
"offset": ,
"auth": "-",
"ident": "-",
"input_type": "log",
"verb": "GET",
"source": "/var/log/httpd/access_log",
"type": "log",
"tags": [
"referrer": "\"-\"",
"@timestamp": "2019-03-11T14:49:51.000Z",
"response": "",
"bytes": "",
"clientip": "",
"@version": "",
"beat": {
"name": "node105.yinzhengjie.org.cn",
"hostname": "node105.yinzhengjie.org.cn",
"version": "5.6.12"
"host": "node105.yinzhengjie.org.cn",
"httpversion": "1.1",
"user_agent": "\"curl/7.29.0\""
[root@node101 ~]#
[root@node101 ~]#

[root@node101 ~]# curl -X GET http://node101.yinzhengjie.org.cn:9200/logstash-*/_search?q=response:404 | jq .

Elastic Stack之FileBeat使用实战的更多相关文章

  1. Elastic Stack之Redis集群使用

    Elastic Stack之Redis集群使用 作者:尹正杰  版权声明:原创作品,谢绝转载!否则将追究法律责任. 本篇博客数据流走向:FileBeat ===>Redis  ===>lo ...

  2. SpringBoot 整合 Elastic Stack 最新版本(7.14.1)分布式日志解决方案,开源微服务全栈项目【有来商城】的日志落地实践

    一. 前言 日志对于一个程序的重要程度不用过多的言语修饰,本篇将以实战的方式讲述开源微服务全栈项目 有来商城 是如何整合当下主流日志解决方案 ELK +Filebeat . 话不多说,先看实现的效果图 ...

  3. Elastic Stack

    Elastic Stack 开发人员不能登陆线上服务器查看详细日志 各个系统都有日志,日志数据分散难以查找 日志数据量大,查询速度慢,或者数据不够实时 官网地址:https://www.elastic ...

  4. Elastic Stack之kibana使用

    Elastic Stack之kibana使用 作者:尹正杰  版权声明:原创作品,谢绝转载!否则将追究法律责任. 本篇博客数据流走向:FileBeat ===>Redis  ===>log ...

  5. Elastic Stack之搜索引擎基础

    Elastic Stack之搜索引擎基础 作者:尹正杰  版权声明:原创作品,谢绝转载!否则将追究法律责任. 一.搜索引擎概述 1>.什么是搜索引擎 搜索引擎(Search Engine)是指根 ...

  6. Elastic Stack之ElasticSearch分布式集群yum方式搭建

    Elastic Stack之ElasticSearch分布式集群yum方式搭建 作者:尹正杰  版权声明:原创作品,谢绝转载!否则将追究法律责任. 一.搜索引擎及Lucene基本概念 1>.什么 ...

  7. 使用 Elastic Stack 来监控和调优 Golang 应用程序

    Golang 因为其语法简单,上手快且方便部署正被越来越多的开发者所青睐,一个 Golang 程序开发好了之后,势必要关心其运行情况,今天在这里就给大家介绍一下如果使用 Elastic Stack 来 ...

  8. Elastic Stack 开源的大数据解决方案

    目的 本文主要介绍的内容有以下三点: 一. Elastic Stack是什么以及组成部分 二. Elastic Stack前景以及业务应用 三. Elasticsearch原理(索引方向) 四. El ...

  9. ES 集中式日志分析平台 Elastic Stack(介绍)

    一.ELK 介绍 ELK 构建在开源基础之上,让您能够安全可靠地获取任何来源.任何格式的数据,并且能够实时地对数据进行搜索.分析和可视化. 最近查看 ELK 官方网站,发现新一代的日志采集器 File ...


  1. css溢出显示省略号

    单行溢出省略号 .show-detail li .info-name { width:278px; display:inline-block; /*下面是重点*/ overflow: hidden; ...

  2. windows开关机事件

    开关机事件.xml <ViewerConfig> <QueryConfig> <QueryParams> <Simple> <BySource&g ...

  3. centos6.8下安装破解quartus prime16.0以及modelsim ae安装

    前言 装逼使用 流程 安装modelsim: 1.modelsim ae在linux下是32位的,对于64位系统需要安装32位库:yum install xulrunner.i686 2.给予权限: ...

  4. 【XSY2667】摧毁图状树 贪心 堆 DFS序 线段树

    题目大意 给你一棵有根树,有\(n\)个点.还有一个参数\(k\).你每次要删除一条长度为\(k\)(\(k\)个点)的祖先-后代链,问你最少几次删完.现在有\(q\)个询问,每次给你一个\(k\), ...

  5. PHP 事务写法

    $md=new Model(); //创建事务 $md->startTrans(); //开始事务 $md->table("ym_xxx")->where(&qu ...

  6. IISEXPRESS64位运行

    调试时使用IISEXPRESS 64位.经网上查找这样开启

  7. 自写juqery插件实现左右循环滚动效果图

    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xht ...

  8. [2017-7-25]Android Learning Day3

    最近真的有点迷茫,感觉没有一个完整的教学体系很难进行下去,有的都是自己瞎捉摸,就跟以前ACM的时候一样,动不动就“这就是一道,水题暴力就行了”.“我们枚举一下所有的状态,找一下规律就行了”,mmp哟. ...

  9. poj 1144 (Tarjan求割点数量)

    题目链接:http://poj.org/problem?id=1144 描述 一个电话线公司(简称TLC)正在建立一个新的电话线缆网络.他们连接了若干个地点分别从1到N编号.没有两个地点有相同的号码. ...

  10. javascript之奇淫技巧

    最近准备面试,复习一下javascript,整理了一些javascript的奇淫技巧~ //为兼容ie的模拟Object.keys() Object.showkeys = function(obj) ...