1.修改配置文件

#vim /etc/logstash/conf.d/tcp.conf 
input {
        tcp {
                port => "5600"
                mode => "server"
                type => "tcplog"
        }
}

output {
        stdout {
                codec => rubydebug
        }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/tcp.conf -t 
logstash -f /etc/logstash/conf.d/tcp.conf 

3.nc发送日志

echo hello | nc 192.168.1.32 5600 

4.验证
logstash通过tcp收集日志

(2)日志输出到elasticsearch

1.修改配置文件

#vim /etc/logstash/conf.d/tcp.conf 
input {
        tcp {
                port => "5600"
                mode => "server"
                type => "tcplog"
        }
}

output {
        if [type] == "tcplog" {
                elasticsearch {
                        hosts => ["192.168.1.31:9200"]
                        index => "tcplog-%{+YYYY.MM.dd}"
                }
        }
}

2.检测配置文件语法和启动

logstash -f /etc/logstash/conf.d/tcp.conf -t 
logstash -f /etc/logstash/conf.d/tcp.conf 

3.nc发送日志

echo "hello world " | nc 192.168.1.32 5600 

4.head插件验证
logstash通过tcp收集日志
5.kibana添加索引
logstash通过tcp收集日志

相关文章:

  • 2021-08-31
  • 2021-11-24
  • 2022-02-26
  • 2022-12-23
  • 2021-07-12
  • 2021-10-26
  • 2021-08-04
  • 2022-12-23
猜你喜欢
  • 2021-08-21
  • 2022-01-25
  • 2021-08-16
  • 2022-01-10
  • 2021-09-08
  • 2022-12-23
  • 2022-12-23
相关资源
相似解决方案