Elasticsearch2.3.3+Logtash2.3.2+Kibana4.5.1 搭建實時日誌

1.下載:linux

1. Elasticsearch: wget https://download.elastic.co/elasticsearch/release/org/elasticsearch/distribution/tar/elasticsearch/2.3.3/elasticsearch-2.3.3.tar.gz
2. Logtash:wget https://download.elastic.co/logstash/logstash/logstash-2.3.2.tar.gz
3. Kibana: wget https://download.elastic.co/kibana/kibana/kibana-4.5.1-linux-x64.tar.gznginx

2.安裝(3個軟件都是解壓便可使用)elasticsearch

1:首先Elasticsearch,須要Jdk環境(這裏省略...),以非root用戶啓動,要不會報錯。url

cd elasticsearch-2.3.3
bin/elasticsearch -d (後臺啓動)

2:Logtash日誌

在根目錄建立logtash.conf文件(用此文件來啓動)code

input {
    file {
        path => "/usr/local/nginx/logs/access.log" #你的日誌文件
        start_position => beginning
        ignore_older => 0
    }
}

filter {

     grok {
        match => { "message" => "%{COMBINEDAPACHELOG}"}
     }
     geoip {
        source => "clientip"
     }
}
          
output { 
     elasticsearch {
        hosts => ["localhost:9200"] 
        index => "logstash-%{+YYYY.MM.dd}"
     } 
}
啓動logtash:bin/logstash -f logstash.conf

出現這個啓動成功ip

3.Kibanaget

編輯conf下的kibana.yml 改爲你的host.input

elasticsearch.url: "http://localhost:9200"

而後啓動Kibana:it

bin/kibana

 

訪問上邊的複製最後一行去訪問就能夠了。默認端口是5601

相關文章
相關標籤/搜索