《Filebeat 安装与配置》
Filebeat 是 Elastic 官方轻量级日志采集器,负责读取日志文件并发送到 Elasticsearch 或 Logstash。本文基于 6.x 记录 Debian 两种安装方式、核心配置与启动方法。
1 首选参考文档
- 官方安装文档:https://www.elastic.co/guide/en/beats/filebeat/6.5/filebeat-installation.html
- 索引模板:https://www.elastic.co/guide/en/beats/filebeat/6.5/filebeat-template.html
2 Debian 安装
2.1 通过 apt 源安装
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/6.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-6.x.list
sudo apt-get update && sudo apt-get install filebeat
2.2 通过 deb 包安装
curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-6.5.4-amd64.deb
sudo dpkg -i filebeat-6.5.4-amd64.deb
3 配置
配置文件位于 /etc/filebeat/filebeat.yml。下面是精简后的核心配置:
#========================== 通用设置 ============================
path.config: /etc/filebeat
path.data: /var/lib/filebeat
path.logs: /var/log/filebeat
#=========================== 日志输入 =============================
filebeat.inputs:
- type: log
enabled: true
# 需要采集的日志文件,支持 glob 通配
paths:
- /var/log/<app>/*.log
# 可选:给每条日志添加额外字段,便于后续过滤
fields:
level: debug
env: dev
# 多行日志合并(例如 Java 堆栈),可选项:
#multiline.pattern: ^\[
#multiline.negate: false
#multiline.match: after
#=========================== 模块配置 ============================
filebeat.config.modules:
path: ${path.config}/modules.d/*.yml
reload.enabled: false
#======================== 索引模板设置 ===========================
setup.template.settings:
index.number_of_shards: 3
#============================ 输出 ===============================
output.elasticsearch:
# ES 地址列表
hosts: ["localhost:9200"]
# 如需认证
#username: "elastic"
#password: "changeme"
# 收集 host/cloud 元数据,用于丰富日志
processors:
- add_host_metadata: ~
- add_cloud_metadata: ~
#============================ 采集自身监控 ===========================
xpack.monitoring.enabled: true
4 加载索引模板(可选)
Filebeat 会自动加载索引模板。也可手动参考:
filebeat setup --template
# 或
filebeat -setup
5 启动与查看
sudo service filebeat start
sudo service filebeat status
# 查看采集日志
tail -f /var/log/filebeat/filebeat
6 常见问题
6.1 Unable to find expected entry ‘main/source/Sources’
通过 apt 源安装时如果遇到:
Unable to find expected entry 'main/source/Sources' in Release file (Wrong sources.list entry or malformed file)
原因:Elastic 源不提供 source 包,add-apt-repository 会自动添加一行 deb-src 导致报错。
解决:删除 /etc/apt/sources.list 中对应 Elastic 仓库的 deb-src 条目,重新 sudo apt-get update 即可。
参考文档
阅读 —
·
全站 —