在Debian Syslog中集成ELK(Elasticsearch、Logstash、Kibana)可以实现日志的集中收集、存储、分析和可视化展示。以下是详细的步骤:
sudo apt-get update
sudo apt-get install elasticsearch
sudo apt-get install logstash
sudo apt-get install kibana
sudo nano /etc/logstash/conf.d/rsyslog.conf
input {
syslog {
port => 514
type => "syslog"
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
index => "syslog-%{YYYY.MM.dd}"
}
}
sudo systemctl restart logstash
sudo systemctl start elasticsearch
sudo systemctl start kibana
sudo nano /etc/kibana/kibana.yml
server.host: "localhost"
sudo systemctl restart kibana
通过以上步骤,您可以将Debian系统上的syslog日志收集并集成到ELK堆栈中,实现日志的集中收集、存储、分析和可视化展示。