深色模式
Filebeat 安装与采集
Filebeat 是 Elastic 官方的轻量级日志采集器,适合把服务器上的日志文件稳定地发往 ElasticSearch 或 Logstash。本文以采集 nginx access log 为例。
适用环境
bash
# 确认 nginx 日志路径与系统版本
ls -l /var/log/nginx/access.log
cat /etc/os-release | grep -E '^(ID|VERSION_ID)='
# 确认能连通 ES
curl -s http://localhost:9200/_cluster/health?pretty | head -n 51
2
3
4
5
6
2
3
4
5
6
操作步骤
1. 安装 Filebeat
bash
# Debian/Ubuntu
sudo apt-get update && sudo apt-get install -y filebeat
# RHEL/CentOS
sudo yum install -y filebeat1
2
3
4
5
2
3
4
5
2. 配置输入与输出(/etc/filebeat/filebeat.yml)
yaml
filebeat.inputs:
- type: filestream
id: nginx-access
paths:
- /var/log/nginx/access.log
output.elasticsearch:
hosts: ["http://localhost:9200"]
username: "elastic"
password: "你的密码"1
2
3
4
5
6
7
8
9
2
3
4
5
6
7
8
9
3. 启动并设置开机自启
bash
sudo systemctl enable --now filebeat
sudo filebeat test output # 测试到 ES 的连接1
2
2
DANGER
不要把 ES 密码明文写在 filebeat.yml 里提交到 git。生产环境用 keystore:echo "密码" | filebeat keystore add ES_PASSWORD --stdin,配置里引用 ${ES_PASSWORD}。
验证
bash
# 看 Filebeat 自身日志有无报错
sudo journalctl -u filebeat -n 50 --no-pager
# 在 ES 中确认索引已创建并有文档
curl -s 'http://localhost:9200/_cat/indices/filebeat*?v'
curl -s 'http://localhost:9200/filebeat-*/_count'1
2
3
4
5
6
2
3
4
5
6
常见坑
WARNING
nginx 日志被 logrotate 切割后,Filebeat 用 inode 跟踪位置;若文件被 copytruncate 方式轮转,可能漏读或重复读,建议使用 create 模式轮转。
WARNING
filestream 与旧版 log 输入类型不兼容,升级后 registry 文件需清理,否则重复采集。