安裝filebeat服務(在須要收集日誌的主機安裝filebeat)docker
下載和安裝key文件vim
rpm --import https://packages.elastic.co/GPG-KEY-elasticsearch
建立yum源文件(版本要和elasticsearch和kibana同樣)elasticsearch
[root@localhost ~]# vim /etc/yum.repos.d/elk-elasticsearch.repo [elastic-5.x] name=Elastic repository for 5.x packages baseurl=https://artifacts.elastic.co/packages/5.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md
開始安裝並啓動服務url
yum install filebeat systemctl start filebeat systemctl status filebeat
收集日誌spa
[root@localhost ~]# grep "^\s*[^# \t].*$" /etc/filebeat/filebeat.yml filebeat.prospectors: - type: log enabled: true paths: - /var/xxx/*.log - /var/xxx/*.out multiline.pattern: ^\[ //multiline這三行是讀取多行日誌的,不把註釋去掉,在kibana查看日誌格式會很亂 multiline.negate: true //false改成true multiline.match: after setup.kibana: host: "192.168.1.191:5601" output.elasticsearch: hosts: ["192.168.1.191:9200"]
重啓服務rest
systemctl restart filebeat
docker pull docker.io/kibana:5.6.12 docker run -it -d -e ELASTICSEARCH_URL=http://192.168.1.191:9200 --name kibana --restart=always -p 5601:5601 kibana:5.6.12