YUM 安装logstash

下载安装公钥:

rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch

创建logstash.repo: vim /etc/yum.repos.d/logstatsh.repo

[logstash-5.x]
name=Elastic repository for 5.x packages
baseurl=https://artifacts.elastic.co/packages/5.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md

使用yum安装logstash

sudo yum install elasticsearch logstash kibana

配置 vim /etc/logstash/conf.d/logstash-syslog.conf

日志收集+分析+报警 logstash _logstash



重启 logstash 应用变更 service logstash restart

打开浏览器访问 127.0.0.1:5601