Filebeat实例07-使用多行合并采集tomcat错误日志

ES集群地址

10.0.0.91:9200
10.0.0.92:9200
10.0.0.93:9200

Filebeat实例

root@elk92:~# vim /etc/filebeat/config/07-modules-tomcat-err-to-es.yaml
filebeat.inputs:
- type: filestream
  paths:
    - /usr/local/apache-tomcat-11.0.5/logs/catalina*
  parsers:
  - multiline:
      type: pattern
      pattern: '^\d'
      negate: true
      match: after

output.elasticsearch:
  hosts:
  - 10.0.0.91:9200
  - 10.0.0.92:9200
  - 10.0.0.93:9200
  index: dezyan-filestream-tomcat-err-%{+yyyy.MM.dd}

setup.ilm.enabled: false
setup.template.name: "dezyan"
setup.template.pattern: "dezyan-*"
  
root@elk92:~# filebeat -e -c /etc/filebeat/config/07-modules-tomcat-err-to-es.yaml
posted @ 2025-03-24 16:31  丁志岩  阅读(75)  评论(0)    收藏  举报