filebeat tcp input to elasticsea

2022-06-23  本文已影响0人  冥王星的卧底

filebeat.yaml:

filebeat.inputs:
- type: tcp
  enable: true
  host: "0.0.0.0:9400"

processors:
  - decode_json_fields:
      fields: ['message']
      target: ""
      overwrite_keys: true
  - drop_fields:
     fields: ['message', 'ecs', 'agent', log]

output.elasticsearch:
  hosts: ["192.168.10.10:59200"]
  index: "test"

setup.template.enabled: false
setup.ilm.enabled: auto

接收tcp输入json格式数据
代替logstash,减少系统负担
自定义输出到elasticsearch index

手动发送数据测试
echo -e '{"method":"HelloService.Hello","params":["hello"],"id":1}'| nc -v 192.168.10.10 9400

上一篇 下一篇

猜你喜欢

热点阅读