天天看點

ELK安裝

wget https://download.elastic.co/elasticsearch/release/org/elasticsearch/distribution/tar/elasticsearch/2.4.0/elasticsearch-2.4.0.tar.gz

wget https://download.elastic.co/logstash/logstash/logstash-2.4.0.tar.gz

wget https://download.elastic.co/kibana/kibana/kibana-4.6.0-linux-x86_64.tar.gz

tar zxvf elasticsearch-2.4.0.tar.gz

tar zxvf kibana-4.6.0-linux-x86_64.tar.gz

tar zxvf logstash-2.4.0.tar.gz

mv elasticsearch-2.4.0 elasticsearch

mv kibana-4.6.0-linux-x86_64 kibana

mv logstash-2.4.0 logstash

groupadd elasticsearch

useradd -g elasticsearch -d /usr/local/elasticsearch elasticsearch

mv elasticsearch/* /usr/local/elasticsearch

chown -R elasticsearch.elasticsearch /usr/local/elasticsearch

chown -R elasticsearch.elasticsearch /data/elasticsearch

./bin/plugin install mobz/elasticsearch-head

vi config/elasticsearch.yml

cluster.name: niudingfeng

node.name: node-1

path.data: /data/elasticsearch/data

path.logs: /data/elasticsearch/logs

network.host: 10.10.16.193

http.port: 9200

啟動:./bin/elasticsearch &

檢視位址:http://10.10.16.194:9200/_plugin/head/   http://10.10.16.194:9200/

vim config/kibana.yml

server.port: 5601

server.host: "10.10.16.194"

elasticsearch.url: "http://10.10.16.194:9200"

kibana.index: ".kibana"

啟動:./bin/kibana &

檢視:

<a href="http://10.10.16.194:5601/" target="_blank">http://10.10.16.194:5601/</a>

nohup /root/logstash/bin/logstash agent -f /root/logstash_agent.conf &amp;

input {

  file {

    type =&gt; "logtest"

    path =&gt; ["/root/access_log"]

  }

}

output {

  elasticsearch {

    action =&gt; "index"

    hosts =&gt; "10.10.16.194:9200"

    index  =&gt; "applog"

     本文轉自aaron428 51CTO部落格,原文連結:http://blog.51cto.com/aaronsa/1846947,如需轉載請自行聯系原作者