九、實戰之ELK

ELK 是一整套實時日志處理的解決方案,是三個軟件產品的首字母縮寫,Elasticsearch,Logstash 和 Kibana。

  • Elasticsearch: 存儲各類日志
  • Logstash: logstash server端用來搜集日志
  • Kibana: web化接口用作查尋和可視化日志
    這三款軟件都是開源軟件,通常是配合使用,而且又先后歸于 Elastic.co 公司名下,故被簡稱為 ELK 協議棧,見下圖。
ELK

1. 安裝elasticsearch

請參加之前的文章,elasticsearch安裝

2. 安裝logstash

  • 下載logstash 5.6.4

  • 修改配置文件jvm.options,默認需要1G,可以根據需要修改

-Xms256m
-Xmx256m
  • 測試1(控制臺輸入,控制臺輸出)
./logstash -e'input { stdin { } } output { stdout {} }'
  • 測試2(控制臺輸入,輸出到ESs)
./logstash -e 'input { stdin { } } output { elasticsearch { hosts => ["127.0.0.1:9200"] } stdout { codec => rubydebug }}'
  • 創建配置文件log.conf
input {
    file {
        path => ["/Users/makun/software/elk/logstash-5.6.5/logs/logstash-plain.log"]
    }   
}
output {
    elasticsearch {
        hosts => "127.0.0.1:9200"
        index => "logstash-logs-%{+YYYY.MM.dd}"
        template_overwrite => true
    }
}
  • 啟動
MacBook-Pro:bin makun$ ./logstash -f ../mk_conf/log.conf 
Sending Logstash's logs to /Users/makun/software/elk/logstash-5.6.5/logs which is now configured via log4j2.properties
[2017-12-09T00:39:34,838][INFO ][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/Users/makun/software/elk/logstash-5.6.5/modules/fb_apache/configuration"}
[2017-12-09T00:39:34,844][INFO ][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/Users/makun/software/elk/logstash-5.6.5/modules/netflow/configuration"}
[2017-12-09T00:39:35,473][INFO ][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://127.0.0.1:9200/]}}
[2017-12-09T00:39:35,475][INFO ][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://127.0.0.1:9200/, :path=>"/"}
[2017-12-09T00:39:35,628][WARN ][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"http://127.0.0.1:9200/"}
[2017-12-09T00:39:35,686][INFO ][logstash.outputs.elasticsearch] Using mapping template from {:path=>nil}
[2017-12-09T00:39:35,693][INFO ][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"template"=>"logstash-*", "version"=>50001, "settings"=>{"index.refresh_interval"=>"5s"}, "mappings"=>{"_default_"=>{"_all"=>{"enabled"=>true, "norms"=>false}, "dynamic_templates"=>[{"message_field"=>{"path_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=>"keyword", "ignore_above"=>256}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date", "include_in_all"=>false}, "@version"=>{"type"=>"keyword", "include_in_all"=>false}, "geoip"=>{"dynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_point"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}}}}}}
[2017-12-09T00:39:35,708][INFO ][logstash.outputs.elasticsearch] Installing elasticsearch template to _template/logstash
[2017-12-09T00:39:35,764][INFO ][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://127.0.0.1:9200"]}
[2017-12-09T00:39:35,775][INFO ][logstash.pipeline        ] Starting pipeline {"id"=>"main", "pipeline.workers"=>4, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>5, "pipeline.max_inflight"=>500}
[2017-12-09T00:39:40,987][INFO ][logstash.pipeline        ] Pipeline main started
[2017-12-09T00:39:41,069][INFO ][logstash.agent           ] Successfully started Logstash API endpoint {:port=>9600}
image.png

3. 安裝kibana

server.port: 5601
server.host: "localhost"
elasticsearch.url: "http://localhost:9200"
kibana.index: ".kibana"
  • 啟動
MacBook-Pro:bin makun$ ./kibana
  log   [02:41:35.307] [info][status][plugin:kibana@5.6.4] Status changed from uninitialized to green - Ready
  log   [02:41:35.415] [info][status][plugin:elasticsearch@5.6.4] Status changed from uninitialized to yellow - Waiting for Elasticsearch
  log   [02:41:35.456] [info][status][plugin:console@5.6.4] Status changed from uninitialized to green - Ready
  log   [02:41:35.517] [info][status][plugin:metrics@5.6.4] Status changed from uninitialized to green - Ready
  log   [02:41:35.761] [info][status][plugin:timelion@5.6.4] Status changed from uninitialized to green - Ready
  log   [02:41:35.766] [info][listening] Server running at http://localhost:5601
  log   [02:41:35.768] [info][status][ui settings] Status changed from uninitialized to yellow - Elasticsearch plugin is yellow
  log   [02:41:35.995] [info][status][plugin:elasticsearch@5.6.4] Status changed from yellow to green - Kibana index ready
  log   [02:41:35.996] [info][status][ui settings] Status changed from yellow to green - Ready
image.png
最后編輯于
?著作權歸作者所有,轉載或內容合作請聯系作者
平臺聲明:文章內容(如有圖片或視頻亦包括在內)由作者上傳并發布,文章內容僅代表作者本人觀點,簡書系信息發布平臺,僅提供信息存儲服務。

推薦閱讀更多精彩內容