logstash linux 安装使用

logstash 教程:http://kibana.logstash.es/content/logstash/get_start/full_config.htmlhtml

                         https://wsgzao.github.io/post/elk/java

es配置教程:http://ju.outofmemory.cn/entry/214901linux

 

1、安装OpenJDK
yum install java-1.7.0-openjdk

2、安装Elaticsearch
一、下载ES
cd /tmp
wget https://download.elasticsearch.org/elasticsearch/elasticsearch/elasticsearch-1.4.4.tar.gz
tar zxvf elasticsearch-1.4.4.tar.gz
mv elasticsearch-1.4.4 /home/elasticsearch

二、安装启动脚本
cd /tmp
git clone https://github.com/elasticsearch/elasticsearch-servicewrapper.git
cd /tmp/elasticsearch-servicewrapper
mv service /home/elasticsearch/bin/
cd /tmp
rm -rf elasticsearch-servicewrapper
cd /home/elasticsearch/bin/service
vim elasticsearch.conf
编辑elasticsearch.conf(即:1 && 2 行),设置为/home/elasticsearch,修改ES_HEAP_SIZE  (内存的60%)(单位是M)
./elasticsearch install

三、打开防火墙9200
vim /etc/sysconfig/iptables
添加一行:
-A INPUT -m state --state NEW -m tcp -p tcp --dport 9200 -j ACCEPT

四、安装插件(可选)
cd /home/elasticsearch/
bin/plugin -install mobz/elasticsearch-head
bin/plugin -install lmenezes/elasticsearch-kopf
更多请参照:http://www.elastic.co/guide/en/elasticsearch/reference/1.3/modules-plugins.html

五、启动es
/etc/init.d/elasticsearch restart

六、测试(xxx.xxx.xxx.xxx是服务期IP地址)
能够访问:xxx.xxx.xxx.xxx:9200  ,看状态是不是:200
或者访问插件kopf:xxx.xxx.xxx.xxx:9200/_plugin/kopf


3、安装Logstash
一、安装 (已有更新版,请去官网查看)
cd /home
wget -O /home/logstash-1.4.2.tar.gz https://download.elasticsearch.org/logstash/logstash/logstash-1.4.2.tar.gz
tar zxvf logstash-1.4.2.tar.gz
rm -rf logstash-1.4.2.tar.gz
mv logstash-1.4.2 logstash
mkdir /etc/logstash
mkdir /var/log/logstash

二、建立配置文件:(这个路径与下面步骤的启动脚本里是对应的)
vim /etc/logstash/index.conf
添加以下内容:
input {
     file {
          path => "/var/log/messages"
          start_position => "beginning"
          codec => plain {
          charset => "GBK" }
          type => "file"
     }
}

output {
     elasticsearch {
          host => "127.0.0.1"
     }
}
补充:
更多功能:http://logstash.net/docs/1.4.2/

三、插件
cd /home/logstash
bin/plugin install contrib

四、启动文件
wget -O /etc/init.d/logstash http://update.biglog.org/logstash
chmod +x /etc/init.d/logstash
chkconfig --add logstash 
chkconfig logstash on
service logstash start

4、安装Kibana
一、安装
cd /home
wget https://download.elasticsearch.org/kibana/kibana/kibana-4.0.1-linux-x64.tar.gz
tar zxvf kibana-4.0.1-linux-x64.tar.gz
rm -fr kibana-4.0.1-linux-x64.tar.gz
mv kibana-4.0.1-linux-x64 kibana

二、配置
cd /home/kibana
vim config/kibana.yml
根据须要修改:
---kibana端口号,默认是5601
---kibana的索引名称,默认是:.kibana
---es的url,默认是:http://localhost:9200

三、打开防火墙
打开kibana对应的端口号,方法同上面

四、启动
cd /home/kibana
bin/kibana

五、测试
而后浏览器访问:xxx.xxx.xxx.xxx:5601,进行配置便可
相关文章
相关标签/搜索