https://github.com/elastic/beats-dashboardsmysql
1、介紹git
filebeat貌似功能筆logstash更好,是下一代的日誌收集器。github
topbeat按期收集系統信息如每一個進程信息、負載、內存、磁盤等等,而後將數據發送到elasticsearch進行索引。sql
packetbeat能夠分析某個時間段mysql或者mongodb的慢查詢日誌狀況;還有I/O吞吐量;這個時間段內常常執行的查詢語句,http訪問狀況等信息;而後將分析出來的結果以圖表的形式展示出來。mongodb
2、須要的beats包json
filebeat-1.2.3-x86_64.rpmcurl
topbeat-1.2.2-x86_64.rpmelasticsearch
packetbeat-1.2.2-x86_64.rpmide
3、安裝beatsurl
一、安裝filebeat
[root@ossec-server ~]# rpm -ivh filebeat-1.2.3-x86_64.rpm
warning: filebeat-1.2.3-x86_64.rpm: Header V4 RSA/SHA1 Signature, key ID d88e42b4: NOKEY
Preparing... ########################################### [100%]
1:filebeat ########################################### [100%]
[root@ossec-server ~]# curl -XPUT 'http://localhost:9200/_template/filebeat?pretty' -d@/etc/filebeat/filebeat.template.json
{
"acknowledged" : true
}
[root@ossec-server ~]# /etc/init.d/filebeat start
Stopping filebeat: [FAILED]
Starting filebeat: [ OK ]
二、安裝topbeat
[root@ossec-server ~]# rpm -ivh topbeat-1.2.2-x86_64.rpm
Preparing... ########################################### [100%]
package topbeat-1.2.2-1.x86_64 is already installed
[root@ossec-server ~]# curl -XPUT 'http://localhost:9200/_template/topbeat' -d@/etc/topbeat/topbeat.template.json
{"acknowledged":true}
[root@ossec-server ~]# /etc/init.d/topbeat start
三、安裝packetbeat
[root@ossec-server ~]# rpm -ivh packetbeat-1.2.2-x86_64.rpm
Preparing... ########################################### [100%]
package packetbeat-1.2.2-1.x86_64 is already installed
[root@ossec-server ~]# curl -XPUT 'http://localhost:9200/_template/packetbeat' -d@/etc/packetbeat/packetbeat.template.json
{"acknowledged":true}
[root@ossec-server ~]# /etc/init.d/topbeat start
Starting topbeat: [ OK ]
四、安裝dashboards
[root@ossec-server ~]# git clone https://github.com/elastic/beats-dashboards.git
Initialized empty Git repository in /root/beats-dashboards/.git/
remote: Counting objects: 1303, done.
remote: Total 1303 (delta 0), reused 0 (delta 0), pack-reused 1303
Receiving objects: 100% (1303/1303), 2.75 MiB | 152 KiB/s, done.
Resolving deltas: 100% (892/892), done.
[root@ossec-server ~]# cd beats-dashboards
[root@ossec-server beats-dashboards]# sh load.sh -url http://localhost:9200
Loading dashboards to http://localhost:9200 in .kibana
{"error":"IndexAlreadyExistsException[[.kibana] already exists]","status":400}{"acknowledged":true}Loading search Cache-transactions:
{"_index":".kibana","_type":"search","_id":"Cache-transactions","_version":1,"created":true}
Loading search DB-transactions:
{"_index":".kibana","_type":"search","_id":"DB-transactions","_version":1,"created":true}
Loading search Default-Search:
{"_index":".kibana","_type":"search","_id":"Default-Search","_version":1,"created":true}
Loading search Filesystem-stats:
{"_index":".kibana","_type":"search","_id":"Filesystem-stats","_version":1,"created":true}
Loading search HTTP-errors:
{"_index":".kibana","_type":"search","_id":"HTTP-errors","_version":1,"created":true}
Loading search MongoDB-errors:
{"_index":".kibana","_type":"search","_id":"MongoDB-errors","_version":1,"created":true}
Loading search MongoDB-transactions:
{"_index":".kibana","_type":"search","_id":"MongoDB-transactions","_version":1,"created":true}
Loading search MongoDB-transactions-with-write-concern-0:
{"_index":".kibana","_type":"search","_id":"MongoDB-transactions-with-write-concern-0","_version":1,"created":true}
五、添加beats索引