搭建ELK集群 实时收集 jpress 项目日志

ELK介绍

1.什么是ELK

ELK是三个软件
1.E:elasticsearch		java程序		存储,查询日志
2.L: logstash			java程序		收集、过滤日志
3.K: kibana				java程序		提供web服务,将数据页面化

4.F: filebeat			go			收集、过滤日志

2.ELK作用

1.收集: 收集所有服务器的日志
2.传输: 把日志稳定的传输到ES或者其他地方
3.存储: ES能有效快速的存储日志数据
4.分析: 通过web页面分析数据
5.监控: 监控集群架构

3.ELK优点

1.处理方式灵活:elasticsearch是实时全文索引,具有强大的搜索功能
2.配置相对简单:elasticsearch全部使用JSON 接口,logstash使用模块配置,kibana的配置文件部分更简单。
3.检索性能高效:基于优秀的设计,虽然每次查询都是实时,但是也可以达到百亿级数据的查询秒级响应。
4.集群线性扩展:elasticsearch和logstash都可以灵活线性扩展
5.前端操作绚丽:kibana的前端设计比较绚丽,而且操作简单

4.为什么使用ELK

### ELK 集群服务版本必须一致
#收集所有的日志
web服务日志
业务服务日志
系统日志

#统计、分析:
1.统计访问量
2.统计访问量前10的IP
3.站点访问次数最多的URL
4.查询一上午以上三个值
5.查询一下午以上三个值
6.对比一下上下午用户访问量
7.对比这一周,每天用户增长还是减少

环境准备

实现功能

1. tomcat部署jpress项目
2. nginx代理jpress
3. 实时获取tomcat json格式日志
4. 实时获取nginx json格式日志
5. 实现 redis 消息队列
主机名 IP 服务 环境要求 内存
jojo01 10.0.0.20 tomcat nginx logstash MySQL Redis JDK 4G
jojo02 10.0.0.21 es kibana JDK 2G
jojo03 10.0.0.22 es JDK 2G

ES集群部署

1.时间同步
yum install -y ntpdate
ntpdate time1.aliyun.com
2.安装Java环境
rz jdk-8u181-linux-x64.rpm
rpm -ivh jdk-8u181-linux-x64.rpm
3.安装ES
rz elasticsearch-6.6.0.rpm
#下载地址:https://www.elastic.co/downloads/elasticsearch
rpm -ivh elasticsearch-6.6.0.rpm

# 根据提示继续操作
systemctl daemon-reload
systemctl enable elasticsearch.service
systemctl start elasticsearch.service
4.配置ES
# 配置文件
vim /etc/elasticsearch/elasticsearch.yml
# jojo02
cluster.name: escluster 
node.name: es1
path.data: /service/es/data
path.logs: /service/es/logs
bootstrap.memory_lock: true
bootstrap.system_call_filter: false
http.port: 9200
transport.tcp.port: 9300
transport.tcp.compress: true
network.host: 10.0.0.21,127.0.0.1
discovery.zen.minimum_master_nodes: 2
discovery.zen.ping.unicast.hosts: [10.0.0.21","10.0.0.22"]  # 集群ip
# jojo02
cluster.name: escluster 
node.name: es1
path.data: /service/es/data
path.logs: /service/es/logs
bootstrap.memory_lock: true
bootstrap.system_call_filter: false
http.port: 9200
transport.tcp.port: 9300
transport.tcp.compress: true
network.host: 10.0.0.21,127.0.0.1
discovery.zen.minimum_master_nodes: 2
discovery.zen.ping.unicast.hosts: [10.0.0.21","10.0.0.22"]  # 集群ip
# 创建数据目录
mkdir /service/es/{data,logs} -p
chown -R elasticsearch.elasticsearch /service/es/
5.配置启动文件中内存锁
 vim /usr/lib/systemd/system/elasticsearch.service
[Service]
LimitMEMLOCK=infinity
5.启动ES
systemctl daemon-reload
systemctl start elasticsearch.service

Kibana 部署(jojo02)

1. 上传代码包
rz kibana-6.6.0-x86_64.rpm
rpm -ivh kibana-6.6.0-x86_64.rpm

2. 配置kibana
vim /etc/kibana/kibana.yml
#进程的端口
server.port: 5601
#监听地址
server.host: "10.0.0.21"
#指定ES的地址
elasticsearch.hosts: ["http://10.0.0.21:9200"]
#kibana也会创建索引
kibana.index: ".kibana"

3. 启动kibana
systemctl start kibana.service

4. 访问页面
http://10.0.0.20:5601

Tomcat 部署(jojo01)

1. 时间同步
yum install -y ntpdate
ntpdate time1.aliyun.com
2. 安装Java环境
rz jdk-8u181-linux-x64.rpm
rpm -ivh jdk-8u181-linux-x64.rpm

3.tomcat
yum install tomcat tomcat-webapps tomcat-admin-webapps -y

4.挂载wer包
# 下载地址
https://gitee.com/fuhai/jpress/blob/alpha/wars/jpress-web-newest.war
cd /usr/share/tomcat/webapps/ rz 

4.启动
systemctl start tomcat

# 修改tomcat 默认页面
cp -rp /usr/share/tomcat/webapps/ /usr/share/tomcat/webapps-jpress
cd /usr/share/tomcat/webapps-jpress
rm -rf ROOT/*
mv jpress-v3.2.5/* ROOT/

# 修改默认地址及json格式
vim /usr/share/tomcat/conf/server.xml
<Service name="webapps-jpress">
<Engine name="webapps-jpress"   resourceName="UserDatabase"/>
<Host name="localhost"  appBase="webapps-jpress"

<Valve className="org.apache.catalina.valves.AccessLogValve" directory="logs"
               prefix="tomcat_access_json" suffix=".log"
               pattern="{&quot;clientip&quot;:&quot;%h&quot;,&quot;ClientUser&quot;:&quot;%l&quot;,&quot;authenticated&quot;:&quot;%u&quot;,&quot;AccessTime&quot;:&quot;%t&quot;,&quot;method&quot;:&quot;%r&quot;,&quot;status&quot;:&quot;%s&quot;,&quot;SendBytes&quot;:&quot;%b&quot;,&quot;Query?string&quot;:&quot;%q&quot;,&quot;partner&quot;:&quot;%{Referer}i&quot;,&quot;AgentVersion&quot;:&quot;%{User-Agent}i&quot;}"/>

部署MySQL(jojo01)

1. 安装依赖
yum install -y ncurses-devel libaio-devel gcc gcc-c++ glibc cmake autoconf openssl openssl-devel
2.上传
rz
tar xf mysql-5.6.46-linux-glibc2.12-x86_64.tar.gz
3.创建目录
mkdir /service
4.软链接
mv mysql-5.6.46-linux-glibc2.12-x86_64 /service/
ln -s /service/mysql-5.6.46-linux-glibc2.12-x86_64 /service/mysql
5.创建用户
useradd mysql -s /sbin/nologin -M
6.拷贝配置文件和启动脚本
cd /service/mysql/support-files/
cp my-default.cnf /etc/my.cnf
cp: overwrite '/etc/my.cnf'? y   
# 主库配置文件
vim /etc/my.cnf
[mysqld]
basedir = /service/mysql
datadir = /service/mysql/data
port=mysql
server_id=1
skip_name_resolve
log_err=/service/mysql/data/mysql.err
log_bin=/service/mysql/data/mysql-bin

cp mysql.server /etc/init.d/mysqld
7. 初始化
cd /service/mysql/scripts/
 ./mysql_install_db --user=mysql --basedir=/service/mysql --datadir=/service/mysql/data
 8.system管理
 vim /usr/lib/systemd/system/mysqld.service
[Unit]
Description=MySQL Server
Documentation=man:mysqld(8)
Documentation=https://dev.mysql.com/doc/refman/en/using-systemd.html
After=network.target
After=syslog.target
[Install]
WantedBy=multi-user.target
[Service]
User=mysql
Group=mysql
ExecStart=/service/mysql/bin/mysqld --defaults-file=/etc/my.cnf
LimitNOFILE = 5000

 systemctl daemon-reload
 systemctl start mysqld
 9.添加环境变量
vim /etc/profile.d/mysql.sh
export PATH=/service/mysql/bin:$PATH

source /etc/profile
10.操作数据库
mysql 
create database php;
grant all on php.* to 'lyw' identified by '123';

Nginx 部署(jojo01)

1. 更换官方源
vim /etc/yum.repos.d/nginx.repo
[nginx-stable]
name=nginx stable repo
baseurl=http://nginx.org/packages/centos/$releasever/$basearch/
gpgcheck=1
enabled=1
gpgkey=https://nginx.org/keys/nginx_signing.key
module_hotfixes=true
2. 安装nginx
yum install -y nginx
3.修改json格式日志
vim /etc/nginx/nginx.conf
user  nginx;
worker_processes  1;

error_log  /var/log/nginx/error.log warn;
pid        /var/run/nginx.pid;


events {
    worker_connections  1024;
}


http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';              
    log_format  json  '{"@timestamp":"$time_iso8601",'
                      '"host":"$server_addr",'
                      '"clientip":"$remote_addr",'
                      '"size":$body_bytes_sent,'
                      '"responsetime":$request_time,'
                      '"upstreamtime":"$upstream_response_time",'
                      '"upstreamhost":"$upstream_addr",'
                      '"http_host":"$host",'
                      '"url":"$uri",'
                      '"referer":"$http_referer",'
                      '"agent":"$http_user_agent",'
                      '"status":"$status"}';
    access_log  /var/log/nginx/access.log  json;

    sendfile        on;
    #tcp_nopush     on;

    keepalive_timeout  65;

    #gzip  on;

    include /etc/nginx/conf.d/*.conf;
}
4. 代理配置
vim /etc/nginx/conf.d/wp.conf
  server {
         listen 80;
         server_name jpress.com;
  location / {
    proxy_pass   http://127.0.0.1:8080;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
 }
}
5. 启动 
systemctl start nginx

Logstash 部署(jojo01)

1. 时间同步
yum install -y ntpdate
ntpdate time1.aliyun.com
2. 安装Java环境
rz jdk-8u181-linux-x64.rpm
rpm -ivh jdk-8u181-linux-x64.rpm
3. 安装Logstash
rz logstash-6.6.0.rpm
rpm -ivh logstash-6.6.0.rpm
4. 授权
chown -R logstash.logstash /usr/share/logstash/


# nginx 
/var/log/nginx/
access.log # json 格式
# tomcat
/usr/local/tomcat/logs/
tomcat_access # json 格式
vim /etc/logstash/conf.d/jpress_json.conf
input {
  file {
    type => "tomcat_access_json"
    path => "/usr/share/tomcat/logs/tomcat_access_json*.log"
    start_position => "beginning"
    codec => "json"
  }
}

input {
  file {
    type => "nginx_log_json"
    path => "/var/log/nginx/access.log"
    start_position => "beginning"
    codec => "json"
  }
}
output {
  elasticsearch {
    hosts => ["10.0.0.21:9200"]
    index => "%{type}_%{+YYYY-MM-dd}"
    codec => "json"
  }
}

# 启动
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/jpress_json.conf & 

实现 Reids 消息队列

yum install -y redis
vim /etc/redis.conf
bind 172.16.1.20  # redis 网络端口设置 

systemctl start redis
vim /etc/logstash/conf.d/redis_json.conf
input {
  file {
    type => "nginx_log"
    path => "/var/log/nginx/access.log"
    start_position => "beginning"
    codec => "json"
  }
  file {
    type => "tomcat_log"
    path => "/usr/share/tomcat/logs/tomcat_access_json.*.log"
    start_position => "beginning"
    codec => "json"
  }
}
output {
  if [type] == "nginx_log" {
    redis {
      host => "172.16.1.20"
      port => "6379"
      data_type => "list"
      db => "0"
      key => "nginx_log"
    }
  }
  if [type] == "tomcat_log" {
    redis {
      host => "172.16.1.20"
      port => "6379"
      data_type => "list"
      db => "1"
      key => "tomcat_log"
    }
  }
}

# 启动
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/tomcat_redis.conf & 

# 查看
172.16.1.20:6379> SELECT 1
OK
172.16.1.20:6379[1]> KEYS *
1) "tomcat_log"
172.16.1.20:6379[1]> KEYS *
1) "tomcat_log"
172.16.1.20:6379[1]> SELECT 0
OK
172.16.1.20:6379> KEYS *
1) "nginx_log"

实现 Reids 消息队列 到es集群

vim /etc/logstash/conf.d/redis_to_es.conf
input {
  redis {
    host => "172.16.1.20"
    port => "6379"
    db => "0"
    data_type => "list"
    key => "nginx_log"
  }
  redis {
    host => "172.16.1.20"
    port => "6379"
    db => "1"
    data_type => "list"
    key => "tomcat_log"
  }
}
output {
  if [type] == "nginx_log" {
    elasticsearch {
      hosts => ["10.0.0.21:9200"]
      index => "nginx_log_%{+YYYY-MM-dd}"
    }
  }
  if [type] == "tomcat_log" {
    elasticsearch {
      hosts => ["10.0.0.21:9200"]
      index => "tomcat_log_%{+YYYY-MM-dd}"
    }
  }
}

# 启动多实例
mkdir /data/logstash/redis_es

/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/redis_to_es.conf --path.data=/data/logstash/redis_es &


# 查看 (瞬间被消费)
172.16.1.20:6379> KEYS *
(empty list or set)
172.16.1.20:6379> 

posted @ 2020-08-18 16:45  JoJoblog  阅读(274)  评论(0)    收藏  举报