Filebeat在Ubuntu上的部署流程如下:
安装Filebeat
sudo apt update
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt install filebeat
配置Filebeat
sudo nano /etc/filebeat/filebeat.yml
filebeat.inputs: - type: log enabled: true paths: - /var/log/*.log
。output.elasticsearch: hosts: ["localhost:9200"]
。add_cloud_metadata
)、模块(如system
)或多行日志处理等。启动并启用服务
sudo systemctl start filebeat
sudo systemctl enable filebeat
验证部署
sudo systemctl status filebeat
journalctl -u filebeat -f
curl
命令查看索引)说明:若需使用特定版本或手动安装,可参考官方文档调整仓库地址或下载对应版本的安装包。