标签:server oca codec 套件 replace var http 功能 创建
rpm -ivh jdk-8u161-linux-x64.rpm
2,下载elasticsearch-6.2.4.tar.gz
wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.2.4.tar.gz
3,安装
tar -zxvf elasticsearch-6.2.4.tar.gz -C /usr/local/ mv /usr/local/elasticsearch-6.2.4/ /usr/local/elasticsearch useradd elk chown -R elk.elk /usr/local/elasticsearch/
4,修改配置
#vim /usr/local/elasticsearch/config/elasticsearch.yml #修改 network.host: 0.0.0.0 #添加 http.cors.enabled: true http.cors.allow-origin: "*"
#vim /etc/security/limits.conf #添加 * soft nofile 65536 * hard nofile 131072 * soft nproc 2048 * hard nproc 4096 #vim /etc/sysctl.conf #添加 vm.max_map_count=655360 sysctl -p
6,测试
四,安装Logstash
1,下载logstash-6.2.4.tar.gz
wget https://artifacts.elastic.co/downloads/logstash/logstash-6.2.4.tar.gz
2,解压安装
tar -zxvf logstash-6.2.4.tar.gz -C /usr/local/ mv /usr/local/logstash-6.2.4/ /usr/local/logstash
3,创建logstash.conf配置文件
vim /usr/local/logstash/config/logstash.conf #输入 input { file { path => "/var/log/messages" type => "syslog_messages" } file { path => "/var/log/secure" type => "syslog_secure" } } #过滤 filter { mutate { # 替换元数据host的值 replace => ["host", "192.168.1.88"] } } #输出 output { elasticsearch { hosts => ["192.168.1.88:9200"] index => "system-%{+YYYY.MM.dd}" } #终端标准输出 #stdout { codec => rubydebug } }
4,启动
/usr/local/logstash/bin/logstash -f /usr/local/logstash/config/logstash.conf
wget https://artifacts.elastic.co/downloads/kibana/kibana-6.2.4-linux-x86_64.tar.gz
2,解压安装
tar -zxvf kibana-6.2.4-linux-x86_64.tar.gz -C /usr/local/ mv /usr/local/kibana-6.2.4-linux-x86_64 /usr/local/kibana
3,配置
vim /usr/local/kibana/config/kibana.yml server.port: 5601 server.host: "0.0.0.0" elasticsearch.url: "http://192.168.1.191:9200" kibana.index: ".kibana"
4,启动
nohup /usr/local/kibana/bin/kibana &
标签:server oca codec 套件 replace var http 功能 创建
原文地址:https://www.cnblogs.com/xiao2er/p/10490899.html