Filebeat在Ubuntu上的部署流程如下:
安装Filebeat
sudo apt updatewget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.listsudo apt install filebeat配置Filebeat
sudo nano /etc/filebeat/filebeat.yml
filebeat.inputs: - type: log enabled: true paths: - /var/log/*.log。output.elasticsearch: hosts: ["localhost:9200"]。add_cloud_metadata)、模块(如system)或多行日志处理等。启动并启用服务
sudo systemctl start filebeatsudo systemctl enable filebeat验证部署
sudo systemctl status filebeatjournalctl -u filebeat -fcurl命令查看索引)说明:若需使用特定版本或手动安装,可参考官方文档调整仓库地址或下载对应版本的安装包。