logstash通过tcp收集日志

(1)标准输入输出tcp模块

1.修改配置文件

#vim /etc/logstash/conf.d/tcp.conf 
input {
        tcp {
                port => "5600"
                mode => "server"
                type => "tcplog"
        }
}

output {
        stdout {
                codec => rubydebug
        }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/tcp.conf -t 
logstash -f /etc/logstash/conf.d/tcp.conf 

3.nc发送日志

echo hello | nc 192.168.1.32 5600 

4.验证

(2)日志输出到elasticsearch

1.修改配置文件

#vim /etc/logstash/conf.d/tcp.conf 
input {
        tcp {
                port => "5600"
                mode => "server"
                type => "tcplog"
        }
}

output {
        if [type] == "tcplog" {
                elasticsearch {
                        hosts => ["192.168.1.31:9200"]
                        index => "tcplog-%{+YYYY.MM.dd}"
                }
        }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/tcp.conf -t 
logstash -f /etc/logstash/conf.d/tcp.conf 

3.nc发送日志

echo "hello world " | nc 192.168.1.32 5600 

4.head插件验证

5.kibana添加索引

猜你喜欢

转载自www.cnblogs.com/lovelinux199075/p/9106392.html