#新建配置文件
sudo vim /etc/logstash/conf.d/java.conf
#添加以下配置
input{ file{ path=>"/var/log/elasticsearch/elasticsearch.log" type => "elasticsearch-java-log" start_position => "beginning" stat_interval => "2" codec => multiline { pattern => "^\[" negate => true what => "previous" } } } output{ elasticsearch{ hosts =>["192.168.108.117:9200"] index =>"elasticsearch-java-log-%{+YYYY.MM.dd}.log" } }
输入以下命令
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/java.conf -t
配置成功:
.
sudo chmod 644 /var/log/elasticsearch/elasticsearch.log
sudo systemctl restart logstash