参考php
https://www.cnblogs.com/davidwang456/p/4485433.html?_t=1443088424295html
https://segmentfault.com/a/1190000009550668 java
https://blog.csdn.net/huixueyi/article/details/81117379 mysql
https://www.cnblogs.com/FlyAway2013/p/10944836.htmllinux
redhat6.5 经过yum安装以下组件
sql
java-1.8.0-openjdk-1.8.0.242.b07-1.el6_10.x86_64mongodb
mongodb-server-2.4.14-4.el6.x86_64(元数据)apache
graylog-server-2.3.2-1.noarch (日志展现与搜索)segmentfault
elasticsearch-2.4.6-1.noarch (日志数据)centos
rsyslog-5.8.10-12.el6.x86_64 (采集)
问题:
一、因为配置yum经过代理proxy=http://192.168.1.250:3128访问互联网,后因主机变动了IP致使Squid服务配置未容许其代理访问,排查了半天
二、先安装了elasticsearch5.x启动正常,可是graylog始终提示“graylog Could not load field information”,且elasticsearch.yml配置改network.host后没法启动,后安装elasticsearch2.x正常
三、graylog的inputs里syslog tcp没法接收数据,gelf udp能接收WAF日志而没法显示和查询,最后rsyslog.conf配置*.* @@192.168.0.245:5142终于能显示和查询收集的日志数据
参考如下连接在同个主机上安装了loganalyzer+apache+php+mysql日志服务器
https://www.cnblogs.com/mchina/p/linux-centos-rsyslog-loganalyzer-mysql-log-server.html