elk + filebeat 6.1.0 安装与demo展示

2018-01-16  本文已影响0人  白衣如相

1.linux和jdk版本

[appadm@dev-biz-test04 comm]$ lsb_release -a
LSB Version:    :base-4.0-amd64:base-4.0-noarch:core-4.0-amd64:core-4.0-noarch:graphics-4.0-amd64:graphics-4.0-noarch:printing-4.0-amd64:printing-4.0-noarch
Distributor ID:
Description:     
Release:        n/a
Codename:       n/a
[appadm@dev-biz-test04 ~]$ java -version
java version "1.8.0_151"
Java(TM) SE Runtime Environment (build 1.8.0_151-b12)
Java HotSpot(TM) 64-Bit Server VM (build 25.151-b12, mixed mode)

2.elk + filebeat下载

wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.1.0.tar.gz
wget https://artifacts.elastic.co/downloads/kibana/kibana-6.1.0-linux-x86_64.tar.gz
wget https://artifacts.elastic.co/downloads/logstash/logstash-6.1.0.tar.gz
wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-6.1.0-linux-x86_64.tar.gz

  如果不能连接外网请自行去官网下载

https://www.elastic.co/downloads

3.elasticsearch解压及启动

groupadd elk
useradd -r -g elk elk001
passwd elk001
123456

  此时新建了elk001的用户名,群组为elk,密码为123456
  修改用户名、群组如下
chown -R elk001:elk /app/thfd/elasticsearch/
  此时如果你不修改配置文件的话,可以直接启动,但是我此次修改了配置文件里的ip,因此要改动一些地方。

cd /app/thfd/elasticsearch/config
vi elasticsearch.yml
cd /app/thfd/elasticsearch/config
vi jvm.options
ulimit -a
su root
vi /etc/security/limits.conf
su root
vi /etc/sysctl.conf
sysctl -p
cd /app/thfd/elasticsearch/config
vi elasticsearch.yml

4.kibana解压及安装

cd /app/thfd/kibana/config
vi kibana.yml 

http://your_ip:5601

5.logstash解压及安装

cd /app/thfd/logstash
./bin/logstash -f config/log4j_payment_website.conf &

5.filebeat解压及安装

上一篇下一篇

猜你喜欢

热点阅读