【问题标题】:Minimal filebeat config: syslog -> file最小的 filebeat 配置:syslog -> 文件
【发布时间】:2018-07-07 05:14:32
【问题描述】:

为了在跑步前步行,我想我应该设置一个 filebeat 实例作为系统日志服务器,然后使用logger 向它发送日志消息。

我用于设置 filebeat 的 Docker Compose 配置是

filebeat:
  image: docker.elastic.co/beats/filebeat:6.3.1
  stdin_open: true
  tty: true
  command: filebeat -v -c /config-dir/filebeat.yml
  restart: always
  ports:
    - "5000:5000"
  volumes:
    - ./log-cfg/filebeat.yml:/config-dir/filebeat.yml
    - ./beat-out/:/beat-out/

文件filebeat.yml包含

filebeat.inputs:
  - type: syslog
    protocol.tcp.host: "localhost:5000"

output.file.path: "/beat-out"

logging:
  level: debug
  to_files: true

用docker-compose up filebeat 调出filebeat 成功。并且使用logger --server localhost --port 5000 --tcp --rfc3164 "An error" 发送日志消息也成功了。但是,./beat-out/ 中的任何文件都没有打印任何内容。

附加到正在运行的实例并检查日志 (/usr/share/filebeat/logs/filebeat) 并不能帮助我了解缺少的内容。可以在http://ix.io/1gdq 找到日志。此外,在发送带有logger 的系统日志消息时,filebeat 日志中不会出现任何内容。

我在这里错过了什么?

【问题讨论】:

    标签: syslog filebeat


    【解决方案1】:

    我在一些帮助下找到了答案。

    filebeat的配置应该是

    filebeat.inputs:
      - type: syslog
        protocol.tcp.host: ":5000"
    
    output.file.path: "/beat-out"
    
    logging:
      level: debug
      to_files: true
    

    【讨论】:

    • 谢谢,您是否设法在 docker 下获得了log.source.address?我有一台主机,但不同主机的端口不同。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2018-12-20
    • 1970-01-01
    • 1970-01-01
    • 2022-11-09
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多