centos 7 ELK簡易安裝
阿新 • • 發佈:2020-12-15
準備兩臺centos7
配置:2核心2G記憶體
第一臺配置
1. 關閉防火牆
systemctl stop firewalld
setenforce 0
2.安裝jdk
rpm -ivh jdk-8u131-linux-x64_.rpm
java -version#檢視版本
3.安裝elasticsearch和kibana
rpm -ivh elasticsearch-6.6.2.rpm kibana-6.6.2-x86_64.rpm
4.修改elasticsearch配置檔案
vim /etc/elasticsearch/elasticsearch.yml
#全部去掉# 換成本機ip
cluster.name: ELK-Cluster
node.name: elk-node1
http.port: 9200
network.host: 192.168.181.144
discovery.zen.ping.unicast.hosts: ["192.168.181.144"]
5.修改kibana配置檔案
vim /etc/kibana/kibana.conf
#全部去掉# 改成本機ip
server.port: 5601
server.host: "192.168.181.144"
elasticsearch.hosts: [ "http://192.168.181.144:9200"]
6.啟動kiban和elasticsearch
systemctl start kibana elasticsearch
檢視頁面是否啟動成功 ip+9200
第二臺配置
1.安裝jdk
rpm -ivh jdk-8u131-linux-x64_.rpm
java -version#檢視版本
2.安裝logstash
rpm -ivh logstash-6.6.0.rpm
3.收集系統日誌
vim /etc/logstash/conf.d/message.conf
#寫elasticsearch主機的ip
input{
file{
path => "/var/log/messages"
type => 'msg-log'
start_position => "beginning"
}
}
output{
elasticsearch{
hosts => "192.168.181.144:9200"
index => "msg_log-%{+YYYY.MM.dd}"
}
}
chmod +r /var/log/messages
systemctl start logstash
檢視日誌和埠
tail -f /var/log/messages
ss -nltp |grep 9600
在kibana裡新增索引<選擇時間戳<用圖形展示出來