一、logstash-7.10.2-linux-x86_64.tar.gz安装包下载
下载地址:https://www.elastic.co/cn/downloads/past-releases#logstash
二、logstash安装
1、将包logstash-7.10.2-linux-x86_64.tar.gz上传至服务器/data目录下,解压
tar xvf logstash-7.10.2-linux-x86_64.tar.gz
cd /data/logstash-7.10.2/config
cp logstash-sample.conf logstash.conf
vi logstash.conf
配置关键内容
input {
tcp {
port => 4560
codec => json_lines
}
}
output {
elasticsearch {
hosts => ["http://server12:9200","http://server13:9200","http://server14:9200"]
index => "%{[serverName]}-%{+YYYY.MM.dd}"
user => "elastic"
password => "elastic123456"
}
}
filter {
date {
match => ["PARAM_date", "yyyy.MM.dd.HH.mm","UNIX_MS"]
target => "@timestamp"
}
ruby {
code => "event.set('timestamp', event.get('@timestamp').time.localtime + 8*60*60)"
}
ruby {
code => "event.set('@timestamp',event.get('timestamp'))"
}
mutate {
remove_field => ["timestamp"]
}
}





专注JAVA系统优化、系统结构调整、系统问题排查医治、系统升级、架构设计、SQL语句优化、小程序、APP、企业应用软件开发,请 + hekf888,欢迎关注,时常发布技术分享博文