logstash 教程:http://kibana.logstash.es/content/logstash/get_start/full_config.htmlhtml
https://wsgzao.github.io/post/elk/java
es配置教程:http://ju.outofmemory.cn/entry/214901linux
1、安裝OpenJDK yum install java-1.7.0-openjdk 2、安裝Elaticsearch 一、下載ES cd /tmp wget https://download.elasticsearch.org/elasticsearch/elasticsearch/elasticsearch-1.4.4.tar.gz tar zxvf elasticsearch-1.4.4.tar.gz mv elasticsearch-1.4.4 /home/elasticsearch 二、安裝啓動腳本 cd /tmp git clone https://github.com/elasticsearch/elasticsearch-servicewrapper.git cd /tmp/elasticsearch-servicewrapper mv service /home/elasticsearch/bin/ cd /tmp rm -rf elasticsearch-servicewrapper cd /home/elasticsearch/bin/service vim elasticsearch.conf 編輯elasticsearch.conf(即:1 && 2 行),設置爲/home/elasticsearch,修改ES_HEAP_SIZE (內存的60%)(單位是M) ./elasticsearch install 三、打開防火牆9200 vim /etc/sysconfig/iptables 添加一行: -A INPUT -m state --state NEW -m tcp -p tcp --dport 9200 -j ACCEPT 四、安裝插件(可選) cd /home/elasticsearch/ bin/plugin -install mobz/elasticsearch-head bin/plugin -install lmenezes/elasticsearch-kopf 更多請參照:http://www.elastic.co/guide/en/elasticsearch/reference/1.3/modules-plugins.html 五、啓動es /etc/init.d/elasticsearch restart 六、測試(xxx.xxx.xxx.xxx是服務期IP地址) 能夠訪問:xxx.xxx.xxx.xxx:9200 ,看狀態是不是:200 或者訪問插件kopf:xxx.xxx.xxx.xxx:9200/_plugin/kopf 3、安裝Logstash 一、安裝 (已有更新版,請去官網查看) cd /home wget -O /home/logstash-1.4.2.tar.gz https://download.elasticsearch.org/logstash/logstash/logstash-1.4.2.tar.gz tar zxvf logstash-1.4.2.tar.gz rm -rf logstash-1.4.2.tar.gz mv logstash-1.4.2 logstash mkdir /etc/logstash mkdir /var/log/logstash 二、建立配置文件:(這個路徑與下面步驟的啓動腳本里是對應的) vim /etc/logstash/index.conf 添加以下內容: input { file { path => "/var/log/messages" start_position => "beginning" codec => plain { charset => "GBK" } type => "file" } } output { elasticsearch { host => "127.0.0.1" } } 補充: 更多功能:http://logstash.net/docs/1.4.2/ 三、插件 cd /home/logstash bin/plugin install contrib 四、啓動文件 wget -O /etc/init.d/logstash http://update.biglog.org/logstash chmod +x /etc/init.d/logstash chkconfig --add logstash chkconfig logstash on service logstash start 4、安裝Kibana 一、安裝 cd /home wget https://download.elasticsearch.org/kibana/kibana/kibana-4.0.1-linux-x64.tar.gz tar zxvf kibana-4.0.1-linux-x64.tar.gz rm -fr kibana-4.0.1-linux-x64.tar.gz mv kibana-4.0.1-linux-x64 kibana 二、配置 cd /home/kibana vim config/kibana.yml 根據須要修改: ---kibana端口號,默認是5601 ---kibana的索引名稱,默認是:.kibana ---es的url,默認是:http://localhost:9200 三、打開防火牆 打開kibana對應的端口號,方法同上面 四、啓動 cd /home/kibana bin/kibana 五、測試 而後瀏覽器訪問:xxx.xxx.xxx.xxx:5601,進行配置便可