标签:ash unsafe 队列 enabled tor 火墙 repo repos for
logstash7.10安装机器初始化
参考ES安装,安装java,关闭防火墙,selinux等
下载并安装GPG-KEY
sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
添加yum仓库
vim /etc/yum.repos.d/logstash.repo
[logstash-7.x]
name=Elastic repository for 7.x packages
baseurl=https://artifacts.elastic.co/packages/7.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
安装logstash
yum install logstash
配置logstash
cd /etc/logstash/
cp logstash.yml logstash.yml.bak
vim logstash.yml
--------------------------------------------------
pipeline.workers: 8 #CPU内核数(或几倍cpu内核数)
pipeline.batch.size: 5000 #每次发送的事件数
pipeline.batch.delay: 3 #发送延时
pipeline.unsafe_shutdown: false #设置在Logstash正常退出时,如果还有未处理事件是否强制退出
pipeline.ordered: auto #管道事件排序
path.config: "/etc/logstash/conf.d" #配置文件地址
config.reload.automatic: true #自动加载配置文件
config.reload.interval: 3s #配置刷时间
http.host: 192.168.110.68 #监听的地址
http.port: 9600 #监听端口
queue.type: memory #启用持久队列 存在在memory 当中
path.logs: /var/log/logstash #日志输出路径
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.hosts: ["http://192.168.110.61:9200", "http://192.168.110.62:9200","http://192.168.110.63:9200"]
启动logstash
systemctl enable logstash.service
systemctl start logstash.service
标签:ash unsafe 队列 enabled tor 火墙 repo repos for
原文地址:https://blog.51cto.com/11258494/2565130