扫一扫,微信登陆

 青浦修电脑 青浦笔记本维修 青浦手机维修 青浦电器维修

搜索
查看: 978|回复: 0

ELK日志收集

[复制链接]

1万

主题

1万

帖子

5万

积分

论坛元老

Rank: 8Rank: 8

积分
56206
发表于 2022-9-5 08:10:05 | 显示全部楼层 |阅读模式
搭建ELK
, t3 T; ^. a& r" Q! X5 a" V/ @9 XELK是由elasticsearch、logstash、kibana三个开源软件组成的一个组合体,ELK是elastic公司公司研发的一套完整的日志收集、分析和展示的企业级解决方案,在这三个软件当中,每个软件用于完成不同的功能,官方域名为elastic.io,ELK stack的主要优点:& d7 [" }4 y, `
1 j8 A9 A" V' S+ G
处理方式灵活:elasticsearch是实时全文索引,具有强大的搜索功能配置相当简单:elasticsearch的API全部使用JSON接口,logstash使用模块配置,kibana的配置文件部分更简单检索性能高效:基于优秀的设计,虽然每次查询都是实时,但是也可以达到百亿数据的查询秒级响应。集群线性扩展:elasticsearch和logstash都可以灵活线性扩展前端操作绚丽:kibana的前端设计比较绚丽,而且操作简单
! G" u, [  q- U. c' o7 d: lElasticsearch
4 a8 p: r% p+ e5 b' u4 q7 m: {7 ?elasticsearch是一个高度可扩展的开源全文搜索和分析引擎,它可实现数据的实时全文搜索、支持分布式可实现高可用、提供API接口,可以处理大规模日志数据,比如nginx、tomcat、系统日志等功能。
5 K' c- d0 X0 V 2 Z4 S6 @% P: R5 c* o
elasticsearch的特点:
  ?9 R+ v% w' U" `/ s* N% A ; E4 {5 v  Z1 f
实时收索、实时分析分布式架构、实时文件存储文档导向,所有对象都是文档高可用,易扩展,支持集群,分片与复制接口友好,支持json
9 C1 I5 Y: x" U7 C4 j部署elasticsearch 2 n& u7 V  z5 L8 Z+ \
GitHub - elastic/elasticsearch: Free and Open, Distributed, RESTful Search Engine,基于java开发
! D% [" B' t3 _" Z3 s " f8 t0 ?, }9 M  e9 c# j% v: J
centos系统关闭服务器的防火墙和selinux,ubuntu关闭防火墙,保持各服务器时间同步
7 V  G! n9 g6 C4 w0 ?
1 e$ `8 J, Q/ J) }1 r4 k+ d服务器1:172.20.22.24
# a+ a. B: a0 r, j6 [" Q. d , G8 n* Y2 C, _4 ?  r# N  k
服务器2:172.20.22.27
0 @6 y- J  F' n! I6 W2 v( N
% L- X( B: `5 {3 ]服务器3:172.20.22.28& G* A& v- J: \! X3 _+ ^4 R
4 Z  Q0 L- T" b7 S6 L; y  f- j
###ubuntu. B; `3 J2 v$ Z
# apt install -y ntpdate1 w: P: C1 X$ g, s0 h$ r
# rm -f /etc/localtime( Y7 \# J  Z1 \( v  R  X! y
# ln -s /usr/share/zoneinfo/Asia/Shanghai /etc/localtime  |- P, C' A, i
# hwclock --systohc9 }+ A  U9 W$ E$ z/ q, ^8 N- g0 {
# ntpdate -u ntp1.aliyun.com$ W$ b5 R3 z6 }) y
###设置内核参数
$ ]) r4 X: [9 f% |( k9 ]4 n0 P# vim /etc/security/limits.conf- v5 E" L7 C6 b- ]6 z; J
*                soft        nofile                500000
+ H8 N# i! a! T- {+ R( B*                hard        nofile                500000
* `& s' o; l7 F' L# vim /etc/security/limits.d/20-nproc.conf
# K1 b4 D3 Q6 g) {' z% x; M& Z% h*          soft    nproc     4096
3 E/ ?( h9 `# Velasticsearch soft    nproc     unlimited
5 S- Z  H3 D/ w0 v9 Q6 w, sroot       soft    nproc     unlimited4 x2 ~; m1 _  X, y! k
###安装jdk% T+ y' d$ W0 _- u' e! P; N7 i5 T8 l
# apt install -y openjdk-8-jdk5 Y* d. q3 [9 Y# D, D
! D9 g/ l/ b9 ^
###每个节点都安装
/ i. F. D. J( Q& ^, U/ Y( t# ls -lrt elasticsearch-7.12.1-amd64.deb, C; i; K# F: t) M
# dpkg -i elasticsearch-7.12.1-amd64.deb
) o6 d- y; h: U3 g8 O###节点1配置文件% O9 V: g/ Q5 `1 {: `
# grep '^[^#]' /etc/elasticsearch/elasticsearch.yml
! n- D% V% r* w6 {, ]% U. Y! ?3 bcluster.name: m63-elastic        #集群名称
; Y  a9 Z% G0 v% Y! Z$ o5 Z& Nnode.name: node1                 #当前节点在集群内的节点名称
& V. u' P$ V, u( [( Cpath.data: /data/elasticsearch   #数据保存目录
  S6 v9 R: \0 s- I4 {path.logs: /data/elasticsearch   #日志保存目录+ u# b) {& W% j. c$ e7 N" _  ^$ \
bootstrap.memory_lock: true      #服务启动的时候锁定足够的内存,防止数据写入swap
7 l; v  d; G1 [) i. u, t9 ]9 d) w* Vnetwork.host: 172.20.22.24       #监听IP
7 |& L/ _/ f: u! u- e; nhttp.port: 9200                  #监听端口: [9 ?! j3 r$ }. g( E
###集群中node节点发现列表4 G# e% `* p) ]4 Q5 Q" j* t
discovery.seed_hosts: ["172.20.22.24", "172.20.22.27","172.20.22.28"]
% j( m. u3 y8 S, W8 ~3 ]8 b9 {$ O###集群初始化哪些节点可以被选举为master! j# w/ o# e6 ~
cluster.initial_master_nodes: ["172.20.22.24", "172.20.22.27","172.20.22.28"]" }! s! M- Z% F3 _6 U
action.destructive_requires_name: true
& p) G0 P* [! V' P# mkdir /data/elasticsearch -p
7 K1 V% o+ H6 l8 [; h! s8 h# chown -R elasticsearch. /data/elasticsearch
( J& r6 m3 Y( f# systemctl start elasticsearch.service" h& K. t0 q5 A
###节点2
/ g3 T3 E* c2 b: f# grep '^[^#]' /etc/elasticsearch/elasticsearch.yml& X1 G& D' E) r( h$ D& ?
cluster.name: m63-elastic4 Y  u# H* W5 f8 \
node.name: node2
5 M/ W, c; q  n0 i# Fpath.data: /data/elasticsearch
/ Q; R& y1 `; C8 Zpath.logs: /data/elasticsearch
4 S" y7 W/ R' {% unetwork.host: 172.20.22.27
  m& o7 J6 \  B! Yhttp.port: 92005 l8 r* P3 C3 L/ g, ^
discovery.seed_hosts: ["172.20.22.24", "172.20.22.27","172.20.22.28"]
: x5 ^6 j0 _7 `" s7 |+ e! l. G, mcluster.initial_master_nodes: ["172.20.22.24", "172.20.22.27","172.20.22.28"]/ H/ [8 L5 T7 U! t
action.destructive_requires_name: true: ~0 T( B4 F6 F( l5 R
# mkdir /data/elasticsearch -p* c% h* c  s! |
# chown -R elasticsearch. /data/elasticsearch
9 q, n0 L1 d' Y9 P, p# systemctl start elasticsearch.service
5 x6 S; O9 t  \" @###节点3* P5 _3 E! ^7 N7 c
# grep '^[^#]' /etc/elasticsearch/elasticsearch.yml. E8 L! h$ N+ P. j
cluster.name: m63-elastic
# G  x6 B5 {0 j! Vnode.name: node35 \/ L* @' k! X8 X
path.data: /data/elasticsearch
& T2 n, y; g2 b7 Kpath.logs: /data/elasticsearch  p" {) B6 X$ t
network.host: 172.20.22.285 P' a. E: e% |: @4 m
http.port: 92007 L7 R/ N% y3 `# Z# n
discovery.seed_hosts: ["172.20.22.24", "172.20.22.27","172.20.22.28"]
1 v5 J; R& `9 _) R( X: t: hcluster.initial_master_nodes: ["172.20.22.24", "172.20.22.27","172.20.22.28"]
. ]- W: g- X1 n& x( ]action.destructive_requires_name: true
' }& N8 n# y3 E  ~0 |# mkdir /data/elasticsearch -p
4 b/ x" l# U. ^) k, l0 d: A# U# chown -R elasticsearch. /data/elasticsearch% R1 X/ a' y' T% _0 L0 X, |
# systemctl start elasticsearch.service 7 c" h! M$ S8 |+ n3 X$ s( n* z
浏览器访问验证 6 \& ]( N' S! i/ ?+ M
http://$IP:9200
* A8 Y+ j' y4 ]# O) }" ^
' X& z8 ^$ o  O ) U1 ]! b3 z( j( m) U( i
# V9 l  C6 \) h
Logstash ) m$ u) t) s- h; o1 ]
Logstash是一个具有实时传输能力的数据收集引擎,其可以通过插件实现日志收集和转发,支持日志过滤,支持普通log、自定义json格式的日志解析,最终把经过处理的日志发送给elasticsearch。
7 S! a; z; h1 X/ v3 O( X9 r; j
, D' u" Z/ v# }& H3 d! f: E部署Logstash ) I; d! }  S* k' |5 [7 s
Logstash是一个开源的数据收集引擎,可以水平伸缩,而且logstash是整个ELK当中用于最多插件的一个组件,其可以接收来自不同来源的数据并统一输出到指定的且可以是多个不同目的地
8 z: p$ y8 Q: n* @! F3 D! P; Z  z 7 K+ _. E! i! \& B2 H% I
https://github.com/elastic/logstash #GitHub; E, u. w, g9 D$ [: D. c1 r

1 Q, a9 C$ {/ x" vElastic Stack and Product Documentation | Elastic
; X; o$ `: x( ~0 r. a' M2 T: [
4 Q( u  m, n+ m+ O0 U5 Q环境准备:关闭防火墙和selinux,并且安装java环境
8 c6 g$ v+ v4 H8 p1 @* X' [7 S 6 s% |1 r1 O! O/ \8 D
# apt install -y openjdk-8-jdk
7 r/ w8 K6 N- d# ls -lrt logstash-7.12.1-amd64.deb1 A2 a: n' c/ R7 M1 s( S2 \# G- k" }
# dpkg -i logstash-7.12.1-amd64.deb
/ e% S$ [/ J6 ^9 u" u3 a1 S) k( s###启动测试. D* x* D+ R0 w9 e, x6 r8 t7 K. k
# /usr/share/logstash/bin/logstash -e  'input { stdin {} } output { stdout {}}'   ##标准输入和标准输出8 T3 I: O3 W" q0 H, ]9 L8 F' w1 m
hello world!~
( T& b* u' g. Q{" k! p7 e( k$ ~8 Z) A
      "@version" => "1",
# Q& U4 n$ j: |' w$ x4 [: K6 n8 e    "@timestamp" => 2022-04-13T06:16:32.212Z,) f( S3 R! ?& a: X" a
          "host" => "jenkins-slave",
5 N9 }6 V! R) K2 d; `       "message" => "hello world!~"4 D* e4 |/ b7 j2 D) A$ |+ S* D4 K* l
}
/ |+ \2 o" A0 M+ b+ E###通过配置文件启动: W9 `1 P4 p/ Y9 D) L4 S$ {, k
# cd /etc/logstash/conf.d/2 C2 }' B' \0 y4 L
# cat test.conf 6 W7 ]7 T; w( e7 B
input { , A. P6 R0 q# A0 P5 y9 a0 x' \
  stdin {}
4 c( A* w% O7 Z7 H}
/ i# E8 d3 d- k# t' Joutput {. E2 Q3 C+ R4 Y. w, \% P
  stdout {}
2 _9 ?+ r. s( C- ]}9 a: O+ R9 @# i+ H
, \& n- S- P: u9 x7 g; D. ?) M8 t
###通过指定配置文件启动
" l# t' |3 n0 g# /usr/share/logstash/bin/logstash -f test.conf -t   ##检查配置文件语法! Z% t5 z6 s( W% R, v( P
# /usr/share/logstash/bin/logstash -f test.conf
' q# r. ]% J$ S0 W% p9 r6 {7 q: m! }, z, S; f$ V+ A, A7 w+ O
####输出到elasticsearch
" L. n8 T. ~1 L/ Z- ]# cat test.conf * `" S+ }1 T' m
input { - k  V$ {' T1 W0 J: N# X
  stdin {}$ e4 m" A8 g) ?. ^. C% g9 b
}1 ~. _9 S4 m% d/ ^" d
output {; p7 U3 P4 Q# y7 S: y* @! @/ q
  #stdout {}
" }, v& T& W7 z% h+ t( X  elasticsearch {
/ p6 P; q! f4 h2 E! x6 ~    hosts => ["172.20.22.24:9200"], W# n1 R$ U# f& I& _7 J9 |
    index => "magedu-m63-test-%{+YYYY.MM.dd}"0 ^) R- s0 {5 P% K
  }3 d) m! H# z  [2 s7 J5 W  ?: Y
}, m% V( @& O: u$ Y7 K% j3 e
# /usr/share/logstash/bin/logstash -f test.conf
, f; s: A7 }4 }8 `version1
) d: k2 Q/ @4 ^6 \6 _! H  x  _version2) ^. n- r9 E' r4 H5 E9 b
version3" U3 g( `% I+ ]
test1* a% s7 x3 ?  s- k3 ^, \* X
test23 ^! C  e8 ~) }6 ^
test3$ l8 l7 K) a0 o; w" ?

- q( h; w! A( V  B0 G####elasticsearch服务器查看收集到的数据2 b. l- X% m7 `9 R$ @/ _3 C: y
# ls -lrt /data/elasticsearch/nodes/0/indices/
  f6 u+ r& o* Ftotal 4
$ E; x3 d0 h# C  Mdrwxr-xr-x 4 elasticsearch elasticsearch 4096 Apr 13 14:36 DyCv8w7mTleuAvlItAJlWA $ a5 X- ?/ V! s- o
kibana / M! q# _4 i8 }  n
kibana为elasticsearch提供一个查看数据的web界面,其主要是通过elasticsearch的API接口进行数据查找,并进行前端数据可视化的展现,另外还可以针对特定格式的数据生成相应的表格、柱状图、饼图等
+ c$ j$ n0 P  `7 s2 m# X) k$ v! _ 7 C% c" S5 o5 A- r% v. B( A
部署kibana
& q, \+ ^: B3 f7 c0 k1 E- y; |3 [# ls -lrt kibana-7.12.1-amd64.deb- a; T- j) k; @, x. Q0 q3 R+ H" f; @
# dpkg -i kibana-7.12.1-amd64.deb; d% I6 ?; r1 ^! `$ E
# grep "^[^$|#]" /etc/kibana/kibana.yml
8 d" C. c" X! [% q6 Jserver.port: 5601
5 T5 e" o4 |8 p! [server.host: "172.20.22.24"
- H4 H6 _/ C) ^elasticsearch.hosts: ["http://172.20.22.27:9200"]3 Y8 V6 |/ F, e. w
i18n.locale: "zh-CN"
# \$ D& n" H9 U. b' T# systemctl restart kibana
. L( m' B' N6 m& B. |浏览器访问http://172.20.22.24:5601
/ T% |6 u# }* A' t& E+ ` + I: w  [3 e: K* H
Stack Management-->索引模式-->创建索引模式& x& j) W! S8 e' h: e9 m: ?3 X

$ ^$ A, f1 n, F. A 9 D4 z+ b1 r5 l
选择时间字段
/ @  j8 a! s; i$ T  r4 S( B5 \% h$ o) D5 A6 M* {' e/ ^2 W
查看对应创建的索引日志信息/ v. d; J4 |! H( J' [: t7 C
- V: j& y6 d  X

  B2 G. u5 e, e* B - y- \6 ]5 [1 ^, o1 z$ i
收集tomcat日志 ( v' ]5 |# [$ T1 p: Z7 V7 E
收集tomcat服务器的访问日志以及tomcat错误日志进行实时统计,在kibana页面进行搜索展现,每台tomcat服务器要安装logstash负责收集日志,然后将日志转发给elasticsearch进行分析,再通过kibana在前端展现$ h8 y( x! t% d
  n$ I- G; X8 e# m4 N0 l
部署tomcat
$ `5 |; X5 S8 f####tomcat1,172.20.22.30' }9 b3 x! u" I' g
# apt install -y openjdk-8-jdk( n( |) _/ Z; O  O0 b' h
# ls -lrt apache-tomcat-8.5.77.tar.gz
2 \9 \7 W- C6 S- t, H" K-rw-r--r-- 1 root root 10559655 Apr 13 21:44 apache-tomcat-8.5.77.tar.gz
7 U# [3 y$ _5 \4 d% h4 ?; g4 H8 e# tar xf apache-tomcat-8.5.77.tar.gz -C /usr/local/src/4 m5 G) q  `0 ?. X
# ln -s /usr/local/src/apache-tomcat-8.5.77 /usr/local/tomcat
) T% x* H2 q6 N# cd /usr/local/tomcat
- r. a2 Y# a$ S0 a8 M1 x  p###修改tomcat日志格式为json
/ F) L( @7 P7 x* Q1 W# W% V# vim conf/server.xml
8 ^- X5 k( n9 k5 w....
" H( j, e) \2 y! D; { / ]  }) x" e1 g3 A, @; c8 r/ a  w
....: {) m2 I+ E" O0 {7 M5 l: z
# mkdir /usr/local/tomcat/webapps/myapp
6 a6 O* f1 {# a* G9 Y# echo "web1 172.20.22.30" > /usr/local/tomcat/webapps/myapp/index.html6 d8 y* I% C& f
# ./bin/catalina.sh start
2 x1 L. i0 J. S$ `: V9 A( |. x1 k, a* n5 u) i  D2 L
###访问测试
- R% u+ z  y0 {8 c- o# curl http://172.20.22.30:8080/myapp/
5 m' I0 t8 C) p5 M! G###查看访问日志
- f; R+ |$ R( ?2 o# ^9 i3 X# tail -f /usr/local/tomcat/logs/tomcat_access_log.2022-04-13.log
  X1 T- o8 N. n- o& v( |
: R  y% ^) g1 K+ F3 t- T) X####tomcat2,172.20.22.26
" [7 }6 T# H$ c9 V( |# apt install -y openjdk-8-jdk8 n, T% y3 {5 S; T
# ls -lrt apache-tomcat-8.5.77.tar.gz
% v9 P7 t1 I9 O# F+ }6 z( ^/ q-rw-r--r-- 1 root root 10559655 Apr 13 21:44 apache-tomcat-8.5.77.tar.gz
) y) k1 x! _4 O# E. s& Y- d7 k# tar xf apache-tomcat-8.5.77.tar.gz -C /usr/local/src/2 y/ m- L' f% O7 Z6 F& T2 @6 N
# ln -s /usr/local/src/apache-tomcat-8.5.77 /usr/local/tomcat
- O5 S. N7 R4 v2 L+ t# cd /usr/local/tomcat
6 L2 k' D. {, G4 ^###修改tomcat日志格式为json. l/ U" h4 }: a$ ^9 C2 p. _4 d
# vim conf/server.xml
/ x- X/ a  T4 I" W5 C....3 S0 j5 Z) X& z4 e+ ]4 y$ u* J
0 @5 [& j. F9 g, {8 C! s+ i
....
$ n/ j% {# K& E5 ]# mkdir /usr/local/tomcat/webapps/myapp
/ j) M% n% S( f" R7 Y# echo "web2 172.20.22.26" > /usr/local/tomcat/webapps/myapp/index.html$ A; H$ g  w; n- K! v3 R# m
# ./bin/catalina.sh start
3 C) {+ g0 \- ~2 c, Z9 f
2 d' e5 W' m) p4 n  }###访问测试4 K/ V- N6 G7 Q+ ], l* ?
# curl http://172.20.22.26:8080/myapp/% ^: Z4 `0 ~* R' N
###查看访问日志
' E  N+ ]6 e7 C- Y" ]4 o# tail -f /usr/local/tomcat/logs/tomcat_access_log.2022-04-14.log 5 ?2 B1 f: d0 o; I
部署logstash , K4 l" k7 T; K4 {; K
在tomcat服务器安装logstash收集tomcat和系统日志
" j- Q) t& [" B: a4 W 6 F" E- [$ e2 J+ @
####tomcat1,172.20.22.30
& |! _$ X2 [  ~) F# ls -lrt logstash-7.12.1-amd64.deb' H5 D& S3 C1 y
# dpkg -i logstash-7.12.1-amd64.deb0 P* R6 {3 T) Z
# vim /etc/systemd/system/logstash.service% J/ q$ }7 w+ Q7 ^
.../ l+ B$ K% T3 F; j
User=root! X8 R1 a) C7 o5 m
Group=root
0 s( `/ R) [2 A...
3 ^0 d" v% L% f- F# cd /etc/logstash/conf.d0 @" [2 _" U5 `# X0 X  G% O
# cat tomcat.conf6 u3 r2 A& ^, l) y- \
input {
5 T" t2 I6 S  X8 l8 k) [  file {8 n8 j/ q/ P' a4 c' R
    path => "/usr/local/tomcat/logs/tomcat_access_log*.log"" M6 `" N  v4 ^( |1 A: ~6 m
    type => "tomcat-log"  u; R+ j* M$ z# u
    start_position => "beginning"
( B4 B' e. m* J3 K. Q    stat_interval => "3"; s% l/ T) {0 j" a" B) y
  }% R; u" h" h' T, K
  file {
% ?# Y) w' B# {. Z) }, G% B    path => "/var/log/syslog"- [) r! l9 V. C
    type => "systemlog"
' r! D' O. g/ j( }: \2 B- T1 I    start_position => "beginning"
6 C) w3 x9 b6 ^    stat_interval => "3"
0 q' b% \2 B: y; J4 r  }
" [; y7 R8 [0 \, j}
; }# R; I+ ^1 @' T: [output {' O0 V8 [* ^) }+ U
  if [type] == "tomcat-log" {" M3 o/ V' H: V
  elasticsearch {$ c& q6 P" E6 ?' d( G
    hosts => ["172.20.22.24:9200","172.20.22.27:9200"]
* _  _+ P! F* s+ d& v0 X3 F) R    index => "elk-tomcat-%{+YYYY.MM.dd}"* ]0 u1 O. ?# g
  }}) O0 ]3 }0 f  E2 {
  if [type] == "systemlog" {
" e6 J0 H/ H7 P4 {" Q0 r% m  elasticsearch {
! ~  f% O! f; |0 o, ^    hosts => ["172.20.22.27:9200","172.20.22.27:9200"]2 a4 d9 w  o6 i2 q) f
    index => "elk-syslog-%{+YYYY.MM.dd}"
8 d9 c1 A8 O2 M0 W  }}
" u1 @/ c, p9 H& I: @' t7 L& H}( Z9 j1 N: W) s/ y% S9 W* p6 i/ C" T

8 v- X7 i( A: O6 i; P3 E  q3 B- A# /usr/share/logstash/bin/logstash -f tomcat.conf -t
1 t' L0 M( u5 \6 b3 R# z# systemctl daemon-reload
' `# I# c5 Q. G# systemctl start logstash.service/ F" h0 V0 Y6 a) l
# scp tomcat.conf root@3172.20.22.26' }( B3 C( @" O, a

* [" u3 u0 B3 j) ~####tomcat2,172.20.22.26
, k2 d0 Y  {$ w. ]6 P# ls -lrt logstash-7.12.1-amd64.deb
* |$ J6 I" r: ~4 g# dpkg -i logstash-7.12.1-amd64.deb
; Y# Y3 _! b" V: x+ L# Q, |9 ?# vim /etc/systemd/system/logstash.service: p' E$ Y4 s3 P
...7 X4 y3 c% d) g4 }& h' ~( r
User=root. l, O0 H) ]* Y) q
Group=root
. V1 z7 \, S3 E$ q' U0 h...1 i0 F$ D. g) u
# systemctl daemon-reload
" v7 d- C* v/ g# systemctl daemon-reload. ?4 D$ R$ U2 [* O# p5 K- P( h8 H
# systemctl start logstash.service
' Q$ g7 o5 `7 Y' K3 N通过kibana展现! r6 f1 d$ e, z. s7 q! X: ]* C. |/ p5 Y4 C
8 T+ S4 B5 z# L) ^: D' H! M
5 `8 u; y* l( [) \& u8 A
收集Java日志
! {( u5 W% `  {! |5 v使用codec的multiline插件实现多行匹配,这是一个可以将多行进行合并的插件,而且可以使用what指定将匹配到的行与前面的行合并还是和后面的行合并. M2 V6 L- P# l0 ?9 ~
# l  D+ D& j3 }. Q
Multiline codec plugin | Logstash Reference [8.1] | Elastic' I; t" E) v* ~9 \9 g7 K- m
. t. [) o- l! m3 v" T% x. l
添加logstash配置文件 , K3 b5 g$ F0 d; m8 _: |
###收集logstash自身的日志,172.20.22.26
, ^7 e: t9 O% F  w# cd /etc/logstash/conf.d
4 j1 H& b; |! m% W, \1 N# cat java.conf
; x8 u8 w& g+ L: m3 p" Vinput {
/ d2 t# D; Z7 v8 `4 C6 w. K  file {3 u* Q' u# C% [2 x; |
    path => "/var/log/logstash/logstash-plain.log"1 w. U- c' Z8 _- t. e# ~% k# I
    type => "logstash-log"
+ v, L8 h# I' l& S$ F    start_position => "beginning"
& `7 v4 V; s$ z: e* W    stat_interval => "3"# {, B' x  \( Y& V2 |0 \/ n
    codec => multiline {
6 j2 ~1 v! M7 S2 Q# l      pattern => "^\[") v  S& H, A% r$ |( p% z
      negate => true* z* V* I2 z/ e6 q" [
      what => "previous"
$ q3 C. d* \6 L2 j8 W) K. L7 \   }}
2 ^2 V& Y, A% T! A}: Y: l* v. x  U( Y
output {& D! s' t, V- b0 n: m4 R; k- a/ K
  if [type] == "logstash-log" {$ _4 R8 t, E# y) e
  elasticsearch {
4 q; u8 Z6 k/ u1 e0 |) B$ m! q" v    hosts => ["172.20.22.24"]7 j9 `. S0 V% W8 ~9 @) g. ?; }
    index => "logstash-log-%{+YYYY.MM.dd}"
5 D8 W' P% r& P) C  }}, |8 ]9 J! e- ?$ U) [8 v' q7 l
}
3 }. H* Q0 |* r  }3 `& O" T# r( e: k: X7 b, F; t
# /usr/share/logstash/bin/logstash -f java.conf -t- s1 L% `. k6 b7 ~  ~3 X1 X3 i$ t
# systemctl restart logstash.service
: c) E1 ~; l. D( U
6 K  `# q) e8 n2 C( k###收集logstash自身的日志,172.20.22.30
7 Y# ], n9 G  S- y# cd /etc/logstash/conf.d7 Q: j0 {3 C, q1 a" D! ?9 f
# cat java.conf - r  N; C: |+ m, s
input {. _# w5 K0 A/ ]% E" r  v
  file {
: G% g$ t0 {6 S! j* N7 D$ @    path => "/var/log/logstash/logstash-plain.log"
( Q9 ]( j7 W: \' l( F    type => "logstash-log"
. U! |2 y8 o3 [1 t- C( {    start_position => "beginning"
( X& |$ o0 V! C: W# X% t( X    stat_interval => "3"
1 a1 M, D- I; [, s2 D, |! d' [) @    codec => multiline {# r. U/ E' j9 g) @5 u" z0 E1 g" \
      pattern => "^\["
7 m. n1 ?! L' I4 X: ^8 B: A      negate => true
. z% k1 P; @2 n/ T/ i      what => "previous"
  v  H3 k$ k0 e9 A/ H6 D6 K' m4 u* s, i   }}
( @$ E# j1 K* M' F8 o}. i7 a0 `  K' B/ f" J8 _9 H
output {
, l2 b# Y' q/ M0 p0 i- J  if [type] == "logstash-log" {) [8 k! y5 O; p. r# p7 S) ~5 {
  elasticsearch {( a( w$ J1 J& G
    hosts => ["172.20.22.24"]
# w' I; G/ E, M" g2 x    index => "logstash-log-%{+YYYY.MM.dd}"! ~$ q" H2 X- k2 p: `7 \% {, c0 S, x
  }}
/ y2 w" H9 G' \% T% \}
: S8 I9 ~  }8 B( z$ h, \9 L! P# n% Q) G1 `' v
# /usr/share/logstash/bin/logstash -f java.conf -t
9 K! P- l; U. c% z4 y: i; e2 R# systemctl restart logstash.service % q$ i: Q0 n0 X) Y
查看kibana收集到的日志* O- Y& o( h* ~) g% N' h; k1 i
! H; p& e$ P/ u5 H! Q0 i
! p# f. x. R' i
# X6 B5 ~9 _( ?. e9 X, a# ^# c$ _
filebeat结合redis、logstash收集nginx日志 $ R" H( \" h" C% g, a& B
使用filebeat收集日志发送到logstash1,再由logstash1发送到redis,最后再由logstash2发送到elasticsearch
+ G) x# \1 ~/ R+ B
5 J: I$ M$ b0 U# I% l5 I- Dweb1:172.20.22.30,部署好nginx、filebeat、llogstash
5 u6 i0 N. E  c . J. l. ]5 k4 F, r7 F0 n- M! y+ h
web2:172.20.22.26,部署好nginx、filebeat、llogstash2 M. Z/ p2 t. X' n

5 _+ ~8 K9 e, s" O8 \logstash服务器2:172.20.22.23,redis服务器:172.20.23.1575 o- \  E! s- E; ?7 [  g" T& d' C+ w

" Z  w" m. E- U) R6 n3 k/ Mnginx服务器相关配置
7 L4 D; s0 W- L2 _; k8 k' `部署nginx
0 z3 M% y6 W% d7 P2 q: [$ ?# wget http://nginx.org/download/nginx-1.18.0.tar.gz( d+ b$ F$ e; c4 O9 j5 R
# tar xf nginx-1.18.0.tar.gz( L0 |( D" t* A; `( z2 r
# cd nginx-1.18.0
. r, e/ S2 w7 ?3 t; E( v; z# ./configure --prefix=/usr/local/nginx --with-http_ssl_module
0 e( {9 J$ }2 O( L# ^# make -j4 && make install
# j2 S4 _1 ~* p6 c* v& N# /usr/local/nginx/sbin/nginx % T# O3 y  F/ z: z8 V
部署配置logstash
9 ]$ z1 G2 C% G* O% U9 \把filebeat收集到的日志信息发送到redis
: I& [5 V3 E( s1 `3 S, _ ( C8 q2 h/ M/ h( v' l8 H. F+ Z. ~
# apt install -y openjdk-8-jdk
$ Q) e* |2 s: B. Q6 N# dpkg -i logstash-7.12.1-amd64.deb8 y& [8 v, T$ z6 O
# cat /etc/logstash/conf.d/beats-to-redis.conf
  @5 M% n' v1 O; B% Cinput {0 H$ V  @( p& P0 X4 \
  beats {6 \  s: R" O0 S* x# @1 {9 p( r
    port => 5044
' `0 x4 ?5 E# Y7 |    codec => "json"5 _& X8 w" ~) U' w8 |9 y, D3 ^
  }0 d& E0 g) u7 _$ v; \
  beats {
2 ^* c9 J, S. }: h7 N    port => 50453 x  W/ f; {9 U& `+ D" _
    codec => "json"& w! y5 @- }1 x. w
  }
/ W/ Y, Y6 m; s: ^, l}
$ L/ r" W# h  h1 a# o1 E+ Poutput {5 A5 B6 }; g$ ?+ h$ I
  if [fields][project] == "filebeat-systemlog" {6 m3 i# L. a0 R* K" z- }
    redis {8 q6 `7 I1 u, g1 z# d3 N
      data_type => "list"* N* w. ~3 H; k* }4 K
      key => "filebeat-redis-systemlog"2 s- E3 @$ f1 f9 t8 i8 O3 P
      host => "172.20.23.157"
$ s2 R. d. o3 k- o* [% T      port => "6379"# @* I+ T2 H' @0 w' s4 ~3 j# H
      db => "0"
" V. N' l2 ^* ]2 Y5 V* M      password => "12345678"
( O3 _# T- A$ |* T0 V# Y( e9 t  }}
9 O4 \- W- R- }: y) y$ O  if [fields][project] == "filebeat-nginx-accesslog" {
3 {- T6 P0 X5 D/ u    redis {4 O- M) n# `/ ?, v9 m4 }) d- L
      data_type => "list", d; P2 q/ Z8 f$ J
      key => "filebeat-redis-nginx-accesslog"
! w# C, y  l6 Z' \0 ]      host => "172.20.23.157"
2 j5 j7 j5 \" V8 ^" s. {7 P& h      port => "6379"8 d8 c: p4 m. F9 X/ C
      db => "1"
) c* C- P: X: F2 I5 S) Z      password => "12345678"
+ Q) k# X1 t' r  }}
1 ?5 T4 G* i$ Q% N% h7 [  if [fields][project] == "filebeat-nginx-errorlog" {* _6 e5 z, W; n
    redis {5 h, x& c* n+ [+ E& O
      data_type => "list"
8 \1 W+ R$ P0 G) i+ z      key => "filebeat-redis-nginx-errorlog"
& _0 B3 `: }8 o7 V7 `* b0 {4 d      host => "172.20.23.157"
" Y6 A2 u9 |' g' h" h! g, s      port => "6379"
$ t4 V, `9 V9 V6 K8 t      db => "1"( `( l+ ?( Z! ?
      password => "12345678"+ a# R" g8 F+ J. t  b
  }}
: K) W+ f# B) j8 [2 G: K}! m! d; T0 r1 Q& d" a" ^
# systemctl start logstash
, [2 t3 ~0 j" O+ v5 }' h# scp /etc/logstash/conf.d/beats-to-redis.conf root@172.20.22.26:/etc/logstash/conf.d/ 2 m5 i& Z) r- L, \0 `$ S2 ^
部署配置filebeat
, Y$ @8 B) ^8 \4 v; s通过filebeat收集日志信息发送到logstash
: E. V; E% g& e* s' t 7 L4 V. d/ B; b3 J" F0 I1 A
# dpkg -i filebeat-7.12.1-amd64.deb9 Z: Z( e* j2 p* s5 T0 E
# grep -v "#" /etc/filebeat/filebeat.yml | grep "^[^$]", ?0 n1 l# I0 M& v4 P
filebeat.inputs:
6 K2 l, V1 L4 c/ y- E" {- type: log
: l" W/ c+ @" [' r6 |  P  enabled: true
4 c( _, c  \' u8 Z( H$ I, E  paths:: n3 r5 s3 b: G+ s
    - /var/log/syslog
7 J1 T4 V6 G# V" U- v  fields:6 S. [8 S5 i: c0 E$ K+ g
    project: filebeat-systemlog
, h; Y) i9 f, k* |- type: log
  M& Q5 I5 u% K: N  enabled: true
% b( H) c, i* H9 m  }% H, P* O  paths:4 p5 j( K; t# X( }2 r& f; R
    - /usr/local/nginx/logs/access.log! P6 F: F- u' @  _, p
  fields:  z+ f5 a+ K9 c6 G
    project: filebeat-nginx-accesslog
6 H1 y( m6 P2 e4 B3 T4 s- p- type: log/ P* X  l. l: H( ^
  enabled: true
- o0 R# I3 M0 O8 X* V+ L7 _; _  paths:
1 x: r! [! i' q) j5 O! n    - /usr/local/nginx/logs/error.log! j$ n8 c7 }" |6 O$ F
  fields:; ?6 ~5 ~$ h! }3 ~" x6 i
    project: filebeat-nginx-errorlog7 U  t( |4 N; Z- w- w% b  C& j
filebeat.config.modules:; D! {8 z3 D" Q: a* P- Q
  path: ${path.config}/modules.d/*.yml
- |+ B. ~: R6 f$ w% I  reload.enabled: false' C( W8 r: u- a) B" B
setup.template.settings:
& @' i$ _. \7 s3 O! m! C5 p0 ?  index.number_of_shards: 1
+ m; B8 x, |) R8 {setup.kibana:) h2 T& s$ X$ f
processors:
3 R+ f- N5 \" K  - add_host_metadata:0 G% C/ E0 |2 ~8 h" Z7 s* v4 u3 p8 m
      when.not.contains.tags: forwarded! G9 s7 h% C6 i$ {
  - add_cloud_metadata: ~& y  w/ F. m( r: X4 O0 Y( v
  - add_docker_metadata: ~1 R0 y  f* l. Q
  - add_kubernetes_metadata: ~
6 j1 o5 `7 m. q" z% G* m7 Moutput.logstash:
" {; ^% x0 \: I( }/ `  hosts: ["172.20.22.30:5044","172.20.22.30:5045"]
4 z# I5 o  C6 _  enabled: true& ]0 N$ n" Y/ g" J4 k( l) ~" b# C
  worker: 2
  x$ ?- M, z7 e: _  compression_level: 3
8 M1 R* V+ n. c  loadbalance: true$ o3 [3 @9 g# g, K& x5 q

  f4 ~; {0 R- N9 |# systemctl start filebeat
* z% t: r& {1 k. N# scp /etc/filebeat/filebeat.yml root@172.20.22.26:/etc/filebeat/ ' H2 K: P" D$ B0 |1 }! G
logstash服务器配置
' A  i% s4 E" h: h# Glogstash服务器2:172.20.22.23,把redis缓存的日志发送到elasticsearch
! |( n# r: M& ^# q. R, l
1 t% l) c7 s' h% T. {# apt install -y openjdk-8-jdk
+ h6 T3 j4 b8 h& Q: H# dpkg -i logstash-7.12.1-amd64.deb
* K1 K. s6 n7 E2 d% c+ N1 |# cat /etc/logstash/conf.d/redis-to-es.conf
5 f: J+ ?" e) G1 A3 E/ ?input {
4 Q# V2 ]- x' W* l, M3 w* ~  redis {1 ^2 N( x$ R! i, A5 A4 k5 J& `
    data_type => "list"
' h, i5 Y  w% o6 P! u    key => "filebeat-redis-nginx-accesslog"
& R6 w: M, P# ], {* b1 K' x    host => "172.20.23.157"5 z9 w) z$ h) I
    port => "6379"
. _* z% v. s, \5 f4 J6 F, D    db => "1"
. i2 V% v- i* N! e/ _' F: U( ~    password => "12345678"9 k/ L* |+ a4 g
  }
  Y5 I: k% U& a8 B1 T. |  redis {. N* F9 J) h+ p
    data_type => "list"8 K$ V6 e! r0 G
    key => "filebeat-redis-nginx-errorlog"
) O; J% M& p# F# S" V    host => "172.20.23.157"
9 P1 L! c" T) [# s! s, ~$ t    port => "6379"  l- w( O0 ]# {+ v+ h* j" x
    db => "1"6 ~/ N! N( t8 A" q4 L# n
    password => "12345678"
9 H0 n' l4 M* B, l4 Z+ |0 `  }& X! B! }4 H& q
  redis {4 z5 g8 |. e9 f: l: D/ v/ i
    data_type => "list"
' j  ]3 k. A) k8 `# R- d    key => "filebeat-redis-systemlog"
( R2 W. Y' Y: ]' |    host => "172.20.23.157"$ j" M; ^) O/ a6 a+ v7 M7 s6 B
    port => "6379"
6 i5 @. S, S7 }1 B8 R- T- }4 x  q    db => "0"4 B4 S. A. m" [
    password => "12345678"' y( j) x) r8 b: s  s
  }2 D" v( T( I& Z2 L" {
}
* j! v9 _0 G4 @2 Noutput {4 x' N9 s' p$ x+ u
  if [fields][project] == "filebeat-systemlog" {- B) X4 X6 o& w' Z
    elasticsearch {, s6 Q0 I( J0 g: w9 b& }( I
      hosts => ["172.20.22.28:9200"]
0 j4 j* I* q; w( B: T  p      index => "filebeat-systemlog-%{+YYYY.MM.dd}"
" y  t$ p0 ~) a# m; A+ C  }}
$ @0 J# F. x  z) n  if [fields][project] == "filebeat-nginx-accesslog" {
4 K/ N! Z$ v* T8 X3 {4 k    elasticsearch {0 p' {: ]- T' E
      hosts => ["172.20.22.28:9200"]
+ C0 {2 {/ u% Y      index => "filebeat-nginx-accesslog-%{+YYYY.MM.dd}"
! ~3 d9 ?; T9 U0 R% |  }}
) |" I" q9 U$ Z7 L  if [fields][project] == "filebeat-nginx-errorlog" {
$ w$ ~" a* B' S8 Y" n2 L    elasticsearch {
9 |; R/ v4 T6 M4 B2 }! g6 r  ~      hosts => ["172.20.22.28:9200"]& V2 Y  t0 ?& K4 |3 x
      index => "filebeat-nginx-errorlog-%{+YYYY.MM.dd}"/ g5 L5 l$ V! s* y. M$ b" n) [+ F
  }}$ }$ ~3 [4 [7 q8 R4 T' n7 b
}# L: d0 `6 M% l6 R" X: g  W4 ^" J
# systemctl restart logstash.service * v/ s* G- [9 V1 K5 P
redis安装配置
% G5 ?  C% T! k# `( Q3 {redis服务器:172.20.23.157,
( V9 t& m2 z0 i" |+ q  [1 C * N4 v( ^4 }. _: F, h  B# [0 F: L
# yum install -y redis
: M& k! c* S1 D8 F. @! l2 z% \8 I# vim /etc/redis.conf
4 h4 X+ r  w$ F# p+ [. B2 h- m0 S! Y####修改以下配置项8 s& m- G' {. y; |0 z
bind 0.0.0.09 ~, P; J* ^4 Q: j* V4 i& H
....
- i% ~! h7 ?! m3 O9 t+ T3 X. u/ M7 Z" [save "": |$ o$ ]$ A# V8 K$ t7 }; M8 s
....0 V: L/ p1 h3 k" q6 B$ x% L; Z
requirepass 12345678
% x0 z& m9 M& n....
  ^) B  r1 j+ H  U- J: c# systemctl start redis
! r! Z$ L' h: C& {/ ]###测试连接redis
! `$ V' h4 b4 A5 @# redis-cli + l6 S- s2 ]4 f9 \/ a
127.0.0.1:6379> auth 123456782 e9 I! d: x4 {- M& o
OK
3 u$ R- ?  N, t6 W127.0.0.1:6379> ping
0 p; f2 I4 C: g8 `8 n3 q4 r7 fPONG# A! ~. w+ V/ f* E$ D
5 G& @; ~. X  B* ^
###验证收集到的日志信息1 K% X. i( b1 |. O9 X# m
127.0.0.1:6379[1]> keys *
$ q; P2 k# M$ k) N3 K1) "filebeat-redis-nginx-accesslog"# v7 o' W3 Z, ^
2) "filebeat-redis-nginx-errorlog"
/ Z% ]' X; y# L, |127.0.0.1:6379[1]> select 03 w6 T# T3 u- w6 n  m: h
OK0 [/ W! _3 g& y0 `( i( q
127.0.0.1:6379> keys *; {* d2 P( D. O
1) "filebeat-redis-systemlog" 1 Q, p3 ~* r7 S% }. r7 H; m0 y
通过head插件验证生成的索引
- ?9 [4 ^9 A2 _  E9 K) J% z1 b& i8 U; a) w7 B7 ^1 K/ M" K; V( y
4 s* K3 J" ]+ c* n3 l+ K  x
kibana验证收集到的日志信息 6 M# t! m$ Y9 Z) P; j) N

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

x
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Copyright © 2001-2013 Comsenz Inc.Powered by Discuz!X3.4( 沪ICP备18024137号 )
快速回复 返回顶部 返回列表