參考php
https://www.cnblogs.com/davidwang456/p/4485433.html?_t=1443088424295html
https://segmentfault.com/a/1190000009550668 java
https://blog.csdn.net/huixueyi/article/details/81117379 mysql
https://www.cnblogs.com/FlyAway2013/p/10944836.htmllinux
redhat6.5 經過yum安裝以下組件
sql
java-1.8.0-openjdk-1.8.0.242.b07-1.el6_10.x86_64mongodb
mongodb-server-2.4.14-4.el6.x86_64(元數據)apache
graylog-server-2.3.2-1.noarch (日誌展現與搜索)segmentfault
elasticsearch-2.4.6-1.noarch (日誌數據)centos
rsyslog-5.8.10-12.el6.x86_64 (採集)
問題:
一、因爲配置yum經過代理proxy=http://192.168.1.250:3128訪問互聯網,後因主機變動了IP致使Squid服務配置未容許其代理訪問,排查了半天
二、先安裝了elasticsearch5.x啓動正常,可是graylog始終提示「graylog Could not load field information」,且elasticsearch.yml配置改network.host後沒法啓動,後安裝elasticsearch2.x正常
三、graylog的inputs裏syslog tcp沒法接收數據,gelf udp能接收WAF日誌而沒法顯示和查詢,最後rsyslog.conf配置*.* @@192.168.0.245:5142終於能顯示和查詢收集的日誌數據
參考如下連接在同個主機上安裝了loganalyzer+apache+php+mysql日誌服務器
https://www.cnblogs.com/mchina/p/linux-centos-rsyslog-loganalyzer-mysql-log-server.html