logstash通过tcp收集日志

(1)标准输入输出tcp模块

1.修改配置文件

#vim /etc/logstash/conf.d/tcp.conf 
input {
        tcp {
                port => "5600"
                mode => "server"
                type => "tcplog"
        }
}

output {
        stdout {
                codec => rubydebug
        }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/tcp.conf -t 
logstash -f /etc/logstash/conf.d/tcp.conf 

3.nc发送日志

echo hello | nc 192.168.1.32 5600 

4.验证

(2)日志输出到elasticsearch

1.修改配置文件

#vim /etc/logstash/conf.d/tcp.conf 
input {
        tcp {
                port => "5600"
                mode => "server"
                type => "tcplog"
        }
}

output {
        if [type] == "tcplog" {
                elasticsearch {
                        hosts => ["192.168.1.31:9200"]
                        index => "tcplog-%{+YYYY.MM.dd}"
                }
        }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/tcp.conf -t 
logstash -f /etc/logstash/conf.d/tcp.conf 

3.nc发送日志

echo "hello world " | nc 192.168.1.32 5600 

4.head插件验证

5.kibana添加索引

posted @ 2018-05-29 17:56  你很棒  阅读(1088)  评论(0)    收藏  举报