加入收藏 | 设为首页 | 会员中心 | 我要投稿 李大同 (https://www.lidatong.com.cn/)- 科技、建站、经验、云计算、5G、大数据,站长网!
当前位置: 首页 > 编程开发 > Java > 正文

EFK日志搭建

发布时间:2020-12-15 07:51:51 所属栏目:Java 来源:网络整理
导读:安装java 安装java1.8以上的版本并验证 [[email?protected] ~]# yum install java [[email?protected] ~]# java - versionopenjdk version " 1.8.0_222 " OpenJDK Runtime Environment (build 1.8 .0_222- b10)OpenJDK 64 -Bit Server VM (build 25.222 -b10

安装java

安装java1.8以上的版本并验证

[[email?protected] ~]# yum install java
[[email?protected] ~]# java -version
openjdk version "1.8.0_222"
OpenJDK Runtime Environment (build 1.8.0_222-b10)
OpenJDK 64-Bit Server VM (build 25.222-b10,mixed mode)

安装Elasticsearch

安装Elasticsearch(Elasticsearch、Kibana、FileBeat版本最好一致)

[[email?protected] ~]# wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.2.4.tar.gz
[[email?protected] ~]# tar -zxvf elasticsearch-6.2.4.tar.gz
[[email?protected] ~]# mv elasticsearch-6.2.4 /usr/local/elasticsearch-6.2.4
[[email?protected] ~]# cd /usr/local/elasticsearch-6.2.4 [[email?protected]
~]# vi config/elasticsearch.yml network.host: 0.0.0.0 http.port: 9200 #由于这里不能直接用root用户运行elasticsearch,所以要创建一个新用户 [[email?protected] ~]# adduser fengzi [[email?protected] ~]# passwd fengzi [[email?protected] ~]# chmod -R 777 /usr/local/elasticsearch-6.2.4 [[email?protected] ~]# su fengzi

#启动elasticsearch
[[email?protected] ~]# ./bin/elasticsearch

如果服务启动不起来,以下是解决办法

#添加以下4行内容
[[email?protected] local]# vim /etc/security/limits.conf
        * soft nofile 65536
        * hard nofile 65536
        efk soft nproc 8192
        efk hard nproc 8192            

#修改成以下内容
[[email?protected] local]# vim /etc/security/limits.d/20-nproc.conf
        *          soft    nproc    4096
        root       soft    nproc     unlimited    

#添加如下一行
[[email?protected] local]# vim /etc/sysctl.conf 
        vm.max_map_count=655360
[[email?protected] local]# sysctl -p
#查看一下9200和9300端口有没有启
[[email?protected] local]# ss -tnl
State       Recv-Q Send-Q              Local Address:Port                             Peer Address:Port              
LISTEN      0      128                             *:22                                          *:*                  
LISTEN      0      100                     127.0.0.1:25                                          *:*                
LISTEN      0      80                             :::3306                                       :::*                  
LISTEN      0      128                            :::9200                                       :::*                  
LISTEN      0      128                            :::9300                                       :::*                  
LISTEN      0      128                            :::22                                         :::*                  
LISTEN      0      100                           ::1:25                                         :::*                  

?

安装Kibana

[[email?protected] local]# wget https://artifacts.elastic.co/downloads/kibana/kibana-6.2.4-linux-x86_64.tar.gz
[[email?protected] local]# tar -zxvf kibana-6.2.4-linux-x86_64.tar.gz
[[email?protected] local]# vi config/kibana.yml
        elasticsearch.url: "http://0.0.0.0:9200"
        server.host: "0.0.0.0"
        kibana.index: ".kibana"
#启动kibana服务
[[email?protected] local]# .
/bin/kibana

#查看5601端口有没有启动 [[email?protected] local]# ss
-tnl State Recv-Q Send-Q Local Address:Port Peer Address:Port LISTEN 0 128 *:22 *:* LISTEN 0 100 127.0.0.1:25 *:* LISTEN 0 128 *:5601 *:* LISTEN 0 80 :::3306 :::* LISTEN 0 128 :::9200 :::* LISTEN 0 128 :::9300 :::* LISTEN 0 128 :::22 :::* LISTEN 0 100 ::1:25 :::*

安装FileBeat

[[email?protected] local]# wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-6.2.4-linux-x86_64.tar.gz
[[email?protected] local]# tar -zxvf filebeat-6.2.4-linux-x86_64.tar.gz
[[email?protected] local]# vi filebeat.yml
        enabled: true
[[email?protected] local]# ./filebeat -c filebeat.yml

?

配置Kibana

?

?

?

?

(编辑:李大同)

【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容!

    推荐文章
      热点阅读