  • 1. 環境準備
  • 2. 安裝 Logstash
  • 3. 配置 Logstash
  • 4. Logstash 採集的日誌資料,在 Kibana 中顯示
  • 5. 安裝配置 Filebeat
  • 6. Filebeat 採集的日誌資料,在 Kibana 中顯示
  • 7. Filebeat 採集日誌資料,Logstash 過濾
  • 8. Filebeat 採集的日誌資料,Logstash 過濾後,在 Kibana 中顯示

上一篇主要說的是 Elasticsearch 和 Kibana 安裝配置,以及服務追蹤資料的處理和展示,日誌資料採集使用的 Spring Cloud Sleuth Zipkin + Stream/RabbitMQ 中介軟體(Service 端配置),然後 Zipkin Server 從佇列中獲取日誌資料,再使用 HTTP 的請求的方式,傳輸並存儲到 Elasticsearch 中,最後 Kibana 進行日誌資料展示。

在 ELK Stack 中,日誌資料採集有單獨的工具,就是 Logstash 和 Beats。

  • Logstash 主要是用來日誌的蒐集、分析、過濾日誌的工具,支援大量的資料獲取方式。一般工作方式為 c/s 架構,client 端安裝在需要收集日誌的主機上,server 端負責將收到的各節點日誌進行過濾、修改等操作在一併發往 Elasticsearch 上去。
  • Beats 在這裡是一個輕量級日誌採集器,其實 Beats 家族有 6 個成員,早期的 ELK 架構中使用 Logstash 收集、解析日誌,但是 Logstash 對記憶體、cpu、io 等資源消耗比較高。相比 Logstash,Beats 所佔系統的 CPU 和記憶體幾乎可以忽略不計。

目前 Beats 包含六種工具:

  • Packetbeat: 網路資料(收集網路流量資料)
  • Metricbeat: 指標(收集系統、程序和檔案系統級別的 CPU 和記憶體使用情況等資料)
  • Filebeat: 日誌檔案(收集檔案資料)
  • Winlogbeat: windows 事件日誌(收集 Windows 事件日誌資料)
  • Auditbeat:審計資料(收集審計日誌)
  • Heartbeat:執行時間監控(收集系統執行時的資料)


  • 1. Logstash 日誌資料採集,Elasticsearch 儲存,Kibana 展示
  • 2. Filebeat 日誌資料採集,Elasticsearch 儲存,Kibana 展示
  • 3. Filebeat 日誌資料採集,Logstash 過濾,Elasticsearch 儲存,Kibana 展示


1. 環境準備

伺服器環境:Centos 7.0(單機版)

Elasticsearch 和 Logstash 需要 Java,Elasticsearch 推薦的版本為 Java 8,安裝教程:確定穩定的 Spring Cloud 相關環境版本


[[email protected] ~]# vi /etc/hostname

[[email protected] ~]# vi /etc/hosts node1   node1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1         node1 localhost localhost.localdomain localhost6 localhost6.localdomain6

2. 安裝 Logstash

執行以下命令將 Elasticsearch 公共 GPG 金鑰匯入 rpm:

[[email protected] ~]# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch


name=Logstash repository for 5.x packages

然後安裝 Logstash:

[[email protected] ~]# yum makecache && yum install logstash -y
base                                                                          | 3.6 kB  00:00:00
elasticsearch-5.x                                                             | 1.3 kB  00:00:00
extras                                                                        | 3.4 kB  00:00:00
kibana-5.x                                                                    | 1.3 kB  00:00:00
logstash-5.x                                                                  | 1.3 kB  00:00:00
rabbitmq-erlang                                                               | 1.3 kB  00:00:00
updates                                                                       | 3.4 kB  00:00:00
Loading mirror speeds from cached hostfile
 * base: mirrors.163.com
 * extras: mirrors.163.com
 * updates: mirrors.163.com
Loading mirror speeds from cached hostfile
 * base: mirrors.163.com
 * extras: mirrors.163.com
 * updates: mirrors.163.com
--> 正在檢查事務
---> 軟體包 logstash.noarch. 將被 安裝
--> 解決依賴關係完成


 Package              架構               版本                    源                             大小
 logstash             noarch             1:5.6.9-1               elasticsearch-5.x              98 M

安裝  1 軟體包

總下載量:98 M
安裝大小:188 M
Downloading packages:
logstash-5.6.9.rpm                                                            |  98 MB  00:06:38
Running transaction check
Running transaction test
Transaction test succeeded
Running transaction
  正在安裝    : 1:logstash-5.6.9-1.noarch                                                        1/1
Using provided startup.options file: /etc/logstash/startup.options
/usr/share/logstash/vendor/jruby/bin/jruby:行388: /usr/bin/java: 沒有那個檔案或目錄
Unable to install system startup script for Logstash.
  驗證中      : 1:logstash-5.6.9-1.noarch                                                        1/1

  logstash.noarch 1:5.6.9-1


安裝報錯,具體問題:/usr/share/logstash/vendor/jruby/bin/jruby:行388: /usr/bin/java: 沒有那個檔案或目錄

對 Java 配置軟連結,連結到/usr/bin/java

[[email protected] ~]# ln -s /usr/local/java/bin/java /usr/bin/java

然後解除安裝 Logstash:

[[email protected] ~]# yum -y remove logstash


[[email protected] ~]# yum makecache && yum install logstash -y


[[email protected] ~]# sudo /bin/systemctl daemon-reload
[[email protected] ~]# sudo /bin/systemctl enable logstash.service

先不急啟動 Logstash,需要先配置下 Logstash。

3. 配置 Logstash

採集日誌資料,需要有個資料來源,這裡我們使用 rsyslog 進行測試。

Linux 日誌機制的核心是 rsyslog 守護程序,該服務負責監聽 Linux下 的日誌資訊,並把日誌資訊追加到對應的日誌檔案中,一般在 /var/log 目錄下。 它還可以把日誌資訊通過網路協議傳送到另一臺 Linux 伺服器上,或者將日誌儲存在 MySQL 或 Oracle 等資料庫中。

修改 rsyslog 配置:

[[email protected] ~]# vi /etc/rsyslog.conf
# remote host is: name/ip:port, e.g., port optional
*.* @@

重啟 rsyslog:

[[email protected] ~]# systemctl restart rsyslog


[[email protected] ~]# vi /etc/logstash/conf.d/syslog.conf
input {
  syslog {
    type => "system-syslog"
    port => 10514
output {
  elasticsearch {
    hosts => ["node1:9200"]  # 定義es伺服器的ip
    index => "system-syslog-%{+YYYY.MM}" # 定義索引


[[email protected] ~]# cd /usr/share/logstash/bin
[[email protected] bin]# ./logstash --path.settings /etc/logstash/ -f /etc/logstash/conf.d/syslog.conf --config.test_and_exit
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties
Configuration OK

啟動 Logstash:

[[email protected] ~]# systemctl start logstash


[[email protected] ~]# cat /var/log/logstash/logstash-plain.log
[2018-05-15T08:19:05,578][FATAL][logstash.runner          ] An unexpected error occurred! {:error=>#<ArgumentError: Path "/var/lib/logstash/queue" must be a writable directory. It is not writable.>, :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/settings.rb:439:in `validate'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:222:in `validate_value'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:138:in `validate_all'", "org/jruby/RubyHash.java:1342:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:137:in `validate_all'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:243:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:204:in `run'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132:in `run'", "/usr/share/logstash/lib/bootstrap/environment.rb:71:in `(root)'"]}

具體錯誤:Path "/var/lib/logstash/queue" must be a writable directory. It is not writable



[[email protected] ~]# chown -R logstash /var/log/logstash /var/lib/logstash

重新啟動 Logstash:

[[email protected] ~]# systemctl restart logstash

檢視 Logstash 啟動狀態:

[[email protected] ~]# systemctl status logstash
logstash.service - logstash
   Loaded: loaded (/etc/systemd/system/logstash.service; enabled)
   Active: active (running) since 二 2018-05-15 08:23:37 CEST; 1min 4s ago
 Main PID: 10855 (java)
   CGroup: /system.slice/logstash.service
           └─10855 /usr/bin/java -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupan...

5月 15 08:23:37 node1 systemd[1]: Starting logstash...
5月 15 08:23:37 node1 systemd[1]: Started logstash.
5月 15 08:23:46 node1 logstash[10855]: Sending Logstash's logs to /var/log/logstash which is ...ties
Hint: Some lines were ellipsized, use -l to show in full.


[[email protected] ~]# netstat -lntp |grep 9600
tcp6       0      0          :::*                    LISTEN      10855/java
[[email protected] ~]# netstat -lntp |grep 10514
tcp6       0      0 :::10514                :::*                    LISTEN      10855/java

Logstash 的監聽 IP 是127.0.0.1這個本地 IP,本地 IP 無法遠端通訊,所以需要修改一下配置檔案,配置一下監聽的 IP(需要設定 IP 地址,不能設定 Hostname):

[[email protected] ~]# vi /etc/logstash/logstash.yml
http.host: ""

重新啟動 Logstash:

[[email protected] ~]# systemctl restart logstash


[[email protected] ~]# netstat -lntp |grep 9600
tcp6       0      0       :::*                    LISTEN      11214/java

4. Logstash 採集的日誌資料,在 Kibana 中顯示

檢視 Elasticsearch 索引列表,可以看到生成了system-syslog-*型別的日誌資料:

[[email protected] ~]# curl http://node1:9200/_cat/indices?v
health status index                  uuid                   pri rep docs.count docs.deleted store.size pri.store.size
yellow open   twitter                k1KnzWyYRDeckjt7GASh8w   5   1          1            0      5.2kb          5.2kb
yellow open   .kibana                8zJGQkq8TwC4s3JJLMX44g   1   1          5            0     27.1kb         27.1kb
yellow open   system-syslog-2018.05  0aKfJeOmTZ6yen9eSlCOig   5   1         32            0    201.9kb        201.9kb
yellow open   zipkin:span-2018-05-15 8vnm9SJvSlK-cAtakK8VeQ   3   1          9            0     47.3kb         47.3kb
yellow open   zipkin:span-2018-05-14 TZ-MmJpoSs-NwjHjxEvhFQ   3   1        219            0    127.1kb        127.1kb
yellow open   student                iZPqPcwrQbifGOfE9DQYvg   5   1          0            0       955b           955b

然後在 Kibana 上面建立system-syslog-*索引:


其實這裡顯示的日誌資料就是/var/log/messages檔案裡的資料,因為 Logstash 裡配置的就是收集messages檔案裡的資料。

以上這就是如何使用 Logstash 收集系統日誌,輸出到 Elasticsearch 伺服器上,並在 Kibana 的頁面上進行檢視。

5. 安裝配置 Filebeat

執行以下命令將 Elasticsearch 公共 GPG 金鑰匯入 rpm:

[[email protected] ~]# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch


name=Elastic repository for 5.x packages

安裝 Filebeat:

[[email protected] ~]# yum makecache && yum install filebeat -y


[[email protected] ~]# sudo /bin/systemctl daemon-reload
[[email protected] ~]# sudo /bin/systemctl enable filebeat.service


[[email protected] ~]# vi /etc/filebeat/filebeat.yml
- type: log
      - /var/log/messages  # 指定需要收集的日誌檔案的路徑

  # Array of hosts to connect to.
  hosts: ["node:9200"]  # 配置 Elasticsearch 伺服器的 IP 地址

啟動 Filebeat 服務:

[[email protected] ~]# systemctl start filebeat

檢視 Filebeat 服務狀態:

[[email protected] ~]# systemctl status filebeat
filebeat.service - filebeat
   Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled)
   Active: active (running) since 二 2018-05-15 09:29:44 CEST; 1min 12s ago
     Docs: https://www.elastic.co/guide/en/beats/filebeat/current/index.html
 Main PID: 12332 (filebeat)
   CGroup: /system.slice/filebeat.service
           └─12332 /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/...

5月 15 09:29:44 node1 systemd[1]: Started filebeat.

6. Filebeat 採集的日誌資料,在 Kibana 中顯示

檢視 Elasticsearch 索引列表,可以看到生成了filebeat-*型別的日誌資料:

[[email protected] ~]# curl http://node1:9200/_cat/indices?v
health status index                  uuid                   pri rep docs.count docs.deleted store.size pri.store.size
yellow open   twitter                k1KnzWyYRDeckjt7GASh8w   5   1          1            0      5.2kb          5.2kb
yellow open   .kibana                8zJGQkq8TwC4s3JJLMX44g   1   1          6            0     33.3kb         33.3kb
yellow open   system-syslog-2018.05  0aKfJeOmTZ6yen9eSlCOig   5   1        689            0    652.3kb        652.3kb
yellow open   filebeat-2018.05.15    K852lKlgSaKG6-hE_GNB4w   5   1      27417            0      6.7mb          6.7mb
yellow open   zipkin:span-2018-05-15 8vnm9SJvSlK-cAtakK8VeQ   3   1          9            0     47.3kb         47.3kb
yellow open   zipkin:span-2018-05-14 TZ-MmJpoSs-NwjHjxEvhFQ   3   1        219            0    127.1kb        127.1kb
yellow open   student                iZPqPcwrQbifGOfE9DQYvg   5   1          0            0       955b           955b

然後在 Kibana 上面建立filebeat-*索引:


和上面 Logstash 收集 rsyslog 日誌資料一樣,Filebeat 配置的,也是收集的/var/log/messages日誌資料。

可以看到,system-syslogfilebeat-索引對應的日誌資料,是同步更新的(如果沒效果,重啟下 Logstash 和 Filebeat)。

7. Filebeat 採集日誌資料,Logstash 過濾

先停止 Logstash 和 Filebeat:

[[email protected] ~]# systemctl stop logstash && 
systemctl stop filebeat


[[email protected] ~]# curl -XDELETE http://node1:9200/system-syslog-2018.05 && 
curl -XDELETE http://node1:9200/filebeat-2018.05.15

建立新的 Logstash 配置檔案:

[[email protected] ~]# vi /etc/logstash/conf.d/logstash-filebeat-syslog.conf
input {
 beats {
   port => 10515
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => [ "received_at", "%{@timestamp}" ]
      add_field => [ "received_from", "%{host}" ]
    syslog_pri { }
    date {
      match => [ "syslog_timestamp", "MMM  d HH:mm:ss", "MMM dd HH:mm:ss" ]
output {
 elasticsearch {
  hosts => [ "node1:9200" ]
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

驗證 Logstash 配置檔案,是否有效:

[[email protected] ~]# cd /usr/share/logstash/bin
[[email protected] bin]# ./logstash --path.settings /etc/logstash/ -f /etc/logstash/conf.d/logstash-filebeat-syslog.conf --config.test_and_exit
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties
Configuration OK

編輯 Filebeat 配置檔案(註釋掉output.elasticsearch):

[[email protected] ~]# vi /etc/filebeat/filebeat.yml
- type: log
      - /var/log/messages  # 指定需要收集的日誌檔案的路徑
    log_type: syslog

  # The Logstash hosts
  hosts: ["node1:10515"]

重新啟動 Logstash 和 Filebeat:

[[email protected] ~]# systemctl restart logstash && 
systemctl restart filebeat

檢視 Logstash 是否正常監聽:

[[email protected] conf.d]# netstat -lnp|grep 10515
tcp6       0      0 :::10515                :::*                    LISTEN      22384/java

8. Filebeat 採集的日誌資料,Logstash 過濾後,在 Kibana 中顯示

可以看到生成了filebeat-*型別的日誌資料(system-syslog-2018.05索引日誌資料,是由 Logstash 的syslog.conf配置檔案採集的):

[[email protected] ~]# curl http://node1:9200/_cat/indices?v
health status index                           uuid                   pri rep docs.count docs.deleted store.size pri.store.size
yellow open   twitter                         k1KnzWyYRDeckjt7GASh8w   5   1          1            0      5.2kb          5.2kb
yellow open   .kibana                         8zJGQkq8TwC4s3JJLMX44g   1   1          7            1     57.4kb         57.4kb
yellow open   system-syslog-2018.05           dzRXf3eFQ_-hKqlGILTSJg   5   1        223            0    511.9kb        511.9kb
yellow open   zipkin:span-2018-05-15          8vnm9SJvSlK-cAtakK8VeQ   3   1         49            0    142.6kb        142.6kb
yellow open   filebeat-2018.05.15             eEuumW8pTdeXa7Ny1gLIPQ   5   1        177            0    300.2kb        300.2kb
yellow open   zipkin:span-2018-05-14          TZ-MmJpoSs-NwjHjxEvhFQ   3   1        219            0    127.1kb        127.1kb
yellow open   student                         iZPqPcwrQbifGOfE9DQYvg   5   1          0            0       955b           955b


以上是使用 ELK Logstash 和 Filebeat 採集日誌資料的過程(使用 rsyslog 日誌資料來源),後面需要將 ELK 整合到 Spring Cloud/Boot 中,用作整個微服務的集中日誌採集處理中心。



