在CentOS下收集Filebeat日志可按以下步骤进行:
wget命令下载,再用rpm命令安装,如wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.16.3-x86_64.rpm,然后sudo rpm -ivh filebeat-7.16.3-x86_64.rpm。也可通过EPEL仓库安装,命令为sudo yum install filebeat。/etc/filebeat/filebeat.yml文件,指定要监控的日志路径,如filebeat.inputs: - type: log enabled: true paths: - /var/log/*.log,还可设置输出目标,如发送到Elasticsearch的地址和索引名称output.elasticsearch: hosts: [ "localhost:9200" ] index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"。sudo systemctl start filebeat命令启动服务,并设置为开机自启动sudo systemctl enable filebeat。/var/log/filebeat/filebeat.log,或使用journalctl -u filebeat命令查看服务日志来验证配置是否正确。