Filebeat处理CentOS日志文件步骤如下:
sudo yum install -y https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.14.0-x86_64.rpm。/etc/filebeat/filebeat.yml,在filebeat.inputs中指定要收集的日志文件路径,如paths: - /var/log/*.log;还可在output.elasticsearch中设置输出到Elasticsearch的地址等信息。sudo systemctl start filebeat并设置开机自启sudo systemctl enable filebeat。sudo systemctl status filebeat查看状态,或查看/var/log/filebeat/filebeat.log日志文件。ignore_older、scan_frequency等参数优化性能,或使用processors对日志进行预处理。