zoukankan      html  css  js  c++  java
  • elk 分布式部署

    这个logstash 读取日志 是增量的 还是怎么读的?
    
    定时每秒读增量
    
    
    机器配置;
    
    elasticsearch-192.168.32.80
    
    
    elasticsearch-192.168.32.81
    
    
    elasticsearch-192.168.32.82
    
    
    redis-192.168.32.67
    
    
    logstash-192.168.32.76
    
    
    
    日志需要传送到logstash 对应的服务器
    
    nginx 配置:
    
    http {
        include       mime.types;
        default_type  application/octet-stream;
        log_format logstash '$http_host $server_addr $remote_addr [$time_local] "$request" '
                        '$request_body $status $body_bytes_sent "$http_referer" "$http_user_agent" '
                        '$request_time $upstream_response_time';
    
        #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
        #                  '$status $body_bytes_sent "$http_referer" '
        #                  '"$http_user_agent" "$http_x_forwarded_for"';
    
        access_log  /usr/local/nginx/logs/access.log  logstash;
    
    
    
    logstash 配置:
    
    
    
    
    
    /*** 写入redis
    [elk@zjtest7-frontend config]$ cat logstash_agent.conf 
    input {
            file {
                    type => "nginx_access"
                    path => ["/usr/local/nginx/logs/access.log"]
            }
    }
    filter {
        grok {
            match => {
                "message" => "%{IPORHOST:clientip} [%{HTTPDATE:time}] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:http_status_code} %{NUMBER:bytes} "(?
    
    <http_referer>S+)" "(?<http_user_agent>S+)" "(?<http_x_forwarded_for>S+)""
            }
        }   
    }
    output {
            redis {
                    host => "192.168.32.67"
                    data_type => "list"
                    key => "logstash:redis"
                    port=>"6379"
                    password => "1234567"
            }
    }
    
    
    /***从redis读取,发送到elasticsearch
    
    [elk@zjtest7-frontend config]$ cat logstash_indexer.conf 
    input {
            redis {
                    host => "192.168.32.67"
                    data_type => "list"
                    key => "logstash:redis"
                    type => "redis-input"
                    password => "1234567"
                    port =>"6379"
            }
    }
    output {
            elasticsearch {
                    hosts => "192.168.32.80:9200"
                    index => "logstash-nginx-%{+YYYY.MM.dd}"
            }
    		stdout {
    			codec => rubydebug
    		}
    }
    
    
    
    
    写入到redis的数据:
    
    127.0.0.1:6379> keys *
    1) "xacxedx00x05tx00x18contract_rebuild_qty:423"
    2) "logstash:redis"
    3) "xacxedx00x05tx00Dapp_permission_cache:com.zjzc.common.vo.permission.AppPermissionBean"
    4) "xacxedx00x05tx00x18contract_rebuild_qty:427"
    5) "xacxedx00x05tx00x18contract_rebuild_qty:422"
    6) "xacxedx00x05tx00!message_left:20160630:18158464881"
    7) "xacxedx00x05tx00x18contract_rebuild_qty:417"
    127.0.0.1:6379> LLEN "logstash:redis"
    (integer) 167
    
    

  • 相关阅读:
    QT 信号槽 异步事件驱动 单线程 多并发
    Qt 静态库与共享库(动态库)共享配置的一个小办法
    关于:有符号与无符号整数的大小比较
    QT信号槽 中的对象野指针
    Qt程序打包发布
    Qt程序打包发布
    SQL Server 2012 sa 用户登录 18456 错误 (转)
    QtCreator常用之快捷键
    opengl中相关的计算机图形变换矩阵之:模型视图几何变换
    opengl中相关的计算机图形变换矩阵之:齐次坐标 (摘编)
  • 原文地址:https://www.cnblogs.com/zhaoyangjian724/p/6199444.html
Copyright © 2011-2022 走看看