1. 程式人生 > 其它 >centos 7 ELK簡易安裝

centos 7 ELK簡易安裝

技術標籤:linuxelasticsearchcentos

準備兩臺centos7
配置:2核心2G記憶體

第一臺配置
1. 關閉防火牆
	systemctl stop firewalld
	setenforce 0
	
2.安裝jdk
	rpm -ivh jdk-8u131-linux-x64_.rpm 
	java -version#檢視版本

3.安裝elasticsearch和kibana
	rpm -ivh elasticsearch-6.6.2.rpm  kibana-6.6.2-x86_64.rpm

4.修改elasticsearch配置檔案
	vim /etc/elasticsearch/elasticsearch.yml
	#全部去掉# 換成本機ip
cluster.name: ELK-Cluster node.name: elk-node1 http.port: 9200 network.host: 192.168.181.144 discovery.zen.ping.unicast.hosts: ["192.168.181.144"] 5.修改kibana配置檔案 vim /etc/kibana/kibana.conf #全部去掉# 改成本機ip server.port: 5601 server.host: "192.168.181.144" elasticsearch.hosts: [
"http://192.168.181.144:9200"] 6.啟動kiban和elasticsearch systemctl start kibana elasticsearch 檢視頁面是否啟動成功 ip+9200 第二臺配置 1.安裝jdk rpm -ivh jdk-8u131-linux-x64_.rpm java -version#檢視版本 2.安裝logstash rpm -ivh logstash-6.6.0.rpm 3.收集系統日誌 vim /etc/logstash/conf.d/message.conf #寫elasticsearch主機的ip
input{ file{ path => "/var/log/messages" type => 'msg-log' start_position => "beginning" } } output{ elasticsearch{ hosts => "192.168.181.144:9200" index => "msg_log-%{+YYYY.MM.dd}" } } chmod +r /var/log/messages systemctl start logstash 檢視日誌和埠 tail -f /var/log/messages ss -nltp |grep 9600 在kibana裡新增索引<選擇時間戳<用圖形展示出來