首页 文章 精选 留言 我的

精选列表

搜索[日志框架],共10000篇文章
优秀的个人博客,低调大师

ELK日志分析平台搭建全程

环境: OS:Centos 6.6 elasticsearch-5.6.3.tar.gz jdk-8u151-linux-x64.tar.gz kibana-5.6.3-linux-x86_64.tar.gz logstash-5.6.3.tar.gz node-v6.11.4-linux-x64.tar.xz 一、准备环境: 1、创建用户,并给安装目录设置权限 1 2 3 4 [root@1inux~]#groupaddelk [root@1inux~]#useradd-gelkelk [root@1inux~]#mkdir/elk [root@1inux~]#chown-Relk:elk/elk 修改系统某些参数值:【如不修改启动时会报错】 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 [root@1inux~]#vim/etc/security/limits.conf //添加一下内容 --------------------------- *softnofile 65536 *hardnofile 65536 *softnproc 2048 *hardnproc 4096 ---------------------------- [root@bogonelk]#vim/etc/security/limits.d/ 90 -nproc.conf //添加如下内容 *softnproc 2048 [root@1inux~]#vim/etc/sysctl.conf //添加以下内容 ------------------ fs.file- max = 65536 vm.max_map_count= 655360 ---------------------- [root@1inux~]#sysctl-p //查看vm.max_map_count值是否修改成功 修改进程数: [root@1inux~]#ulimit-u 2048 安装Java [root@1inux elk]# mkdir /usr/local/Java [root@1inux elk]# tar -zxvf jdk-8u151-linux-x64.tar.gz -C /usr/local/Java 添加环境变量: [root@1inux jdk1.8.0_151]# vim /etc/profile 添加如下: 1 2 3 exportJAVA_HOME=/usr/local/Java/jdk1.8.0_151 exportPATH=$PATH:$JAVA_HOME/bin exportCLASSPATH=.:$JAVA_HOME/lib/tools.jar:$JAVA_HOME/lib/dt.jar:$CLASSPAT 重新加载 [root@1inux jdk1.8.0_151]# source /etc/profile 查看是否安装成功: 1 2 3 4 [root@1inuxjdk1 .8. 0_151]#java-version javaversion" 1.8. 0_151" Java(TM)SERuntimeEnvironment(build 1.8. 0_151-b12) JavaHotSpot(TM) 64 -BitServerVM(build 25.151 -b12,mixedmode) 二:安装ELK 1、安装elasticsearch 1 2 3 4 5 6 #tar-zxvfelasticsearch-5.6.3.tar.gz 修改配置文件: vim./elasticsearch-5.6.3/config/elasticsearch.yml //设置监听IP及监听端口: network.host:0.0.0.0//设置监听IP http.port:9200//设置监听端口 注:elasticsearch不能使用root用户启动 启动elasticsearch//第一次启动有点慢: 1 2 3 4 5 6 7 [elk@1inuxroot]$cd/elk/elasticsearch-5.6.3/bin [elk@1inuxbin]$./elasticsearch 然后查看端口: [root@1inux~]#ss-tnl|grep9200 LISTEN0128::ffff:192.168.159.130:9200:::* [root@1inux~]# 1.1安装部署head 编辑elasticsearch配置文件做如下修改: 1 2 3 4 5 6 #vim/elk/elasticsearch-5.6.3/config/elasticsearch.yml node.name:node-1inux//修改集群名字 cluster.name:my-1inux//修改节点名字 //增加新的参数,这样head插件可以访问es http.cors.enabled:true http.cors.allow-origin: "*" 1)安装git 1 [root@ 1 inux/]#yum-yinstallgit 下载代码: 1 [root@ 1 inuxelk]#gitclonegit://github.com/mobz/elasticsearch-head.git 修改head目录权限: 1 [root@1inuxelk]#chown-Relk:elkelasticsearch-head 2)下载安装node https://nodejs.org/en/download/ 然后下载xz进行解压 1 2 3 #yum-yinstallxz [root@1inuxelk]#xz-dnode-v6.11.4-linux-x64.tar.xz [root@1inuxelk]#tar-xvfnode-v6.11.4-linux-x64.tar 添加node的环境变量 1 2 3 4 5 6 7 [root@ 1 inuxnode-v 6.11 . 4 -linux-x 64 ]#vim/etc/profile 添加如下: exportNODE_HOME=/elk/node-v 6.11 . 4 -linux-x 64 exportPATH=$PATH:$NODE_HOME/bin 重新加载 [root@ 1 inuxnode-v 6.11 . 4 -linux-x 64 ]#source/etc/profile 查看是否生效: 1 2 3 4 5 6 [root@1inuxnode-v6.11.4-linux-x64]#echo$NODE_HOME /elk/node-v6.11.4-linux-x64 [root@1inuxnode-v6.11.4-linux-x64]#node-v v6.11.4 [root@1inuxnode-v6.11.4-linux-x64]#npm-v 3.10.10 1 2 3 切换国内镜像源: npmconfig set registryhttps: //registry.npm.taobao.org npmconfig set disturlhttps: //npm.taobao.org/dist 3)安装grunt 1 2 [root@1inuxnode_modules]#npminstall-ggrunt [root@1inuxnode-v6.11.4-linux-x64]#npminstallgrunt-cli-g 查看是否安装成功: 1 2 [root@1inuxnode-v6 .11.4 -linux-x64]#grunt-version grunt-cliv1 .2.0 修改服务器监听地址 1 2 [root@1inuxelk]#vim/elk/elasticsearch-head/Gruntfile.js hostname:'*', 修改链接地址: 1 2 3 4 [root@1inuxelk]#vim/elk/elasticsearch-head/_site/app.js this .base_uri= this .config.base_uri|| this .prefs.get( "app-base_uri" )||" 修改为: this .base_uri= this .config.base_uri|| this .prefs.get( "app-base_uri" )|| "http://192.168.159.130:9200" ; 运行head 1 2 3 4 在head目录中执行 [root@1inuxelasticsearch-head]#npminstall 启动: [root@1inuxelasticsearch-head]#gruntserver 2、安装kibana [root@1inux elk]# tar -zxvf kibana-5.6.3-linux-x86_64.tar.gz 1 2 3 4 5 6 7 解压后编辑配置文件; [root@ 1 inuxbin]#vim../config/kibana.yml//修改为elasticsearch的访问地址及端口如下 #server.host: "localhost" server.host: "192.168.159.130" #elasticsearch.url: "http://localhost:9200" elasticsearch.url:" 然后保存启动如下; 1 2 3 4 5 6 7 8 [root@1inuxbin]#./kibana log [15:45:26.952][info][status][plugin:kibana@5.6.3]Statuschangedfromuninitializedtogreen-Ready log [15:45:27.067][info][status][plugin:elasticsearch@5.6.3]Statuschangedfromuninitializedtoyellow-WaitingforElasticsearch log [15:45:27.118][info][status][plugin:console@5.6.3]Statuschangedfromuninitializedtogreen-Ready log [15:45:27.136][info][status][plugin:metrics@5.6.3]Statuschangedfromuninitializedtogreen-Ready log [15:45:27.566][info][status][plugin:timelion@5.6.3]Statuschangedfromuninitializedtogreen-Ready log [15:45:27.697][info][listening]Serverrunningathttp://localhost:5601 log [15:45:27.699][info][status][uisettings]Statuschangedfromuninitializedtoyellow-Elasticsearchpluginisyellow 3、安装logstash-5.6.3.tar.gz 1 2 3 [root@ 1 inuxelk]#tar-zxvflogstash -5.6 . 3 .tar.gz 解压后编辑配置文件,然后就可以使用了 编写文件 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 编辑文件#vim/config/test.conf input{ file{ type=> "nginx_log" path=> "/var/log/nginx/access.log" start_position=> "beginning" } } output{ elasticsearch{ hosts=> "192.168.159.130" index=> "1inux" } stdout{codec=>rubydebug} } 启动: root@1inuxbin]#./logstash-f../config/test.conf 报错: 1、 1 2 3 [root@bogonelk]#./elasticsearch- 5.6.3 /bin/elasticsearch [ 2017 - 10 -25T06: 29 : 04 , 996 ][WARN][o . e . b . ElasticsearchUncaughtExceptionHandler][]uncaughtexception in thread[main] org . elasticsearch . bootstrap . StartupException:java . lang . RuntimeException:can not runelasticsearch as root 解决方案:使用elk用户启动 问题二、 1 2 3 4 5 6 ERROR:[4]bootstrapchecksfailed [1]:maxfiledescriptors[4096] for elasticsearchprocess is toolow,increasetoatleast[65536] [2]:maxnumberofthreads[1024] for user[elk] is toolow,increasetoatleast[2048] [3]:max virtual memoryareasvm.max_map_count[65530] is toolow,increasetoatleast[262144] 参考上面系统修改 问题三、 1 2 3 4 编辑elasticsearch配置文件 [ 4 ]:systemcallfiltersfailedtoinstall;checkthelogsandfixyourconfigurationordisablesystemcallfiltersatyourownrisk 在bootstrap.memory_lock下面添加: bootstrap.system_call_filter:false 本文转自 1inux 51CTO博客,原文链接:http://blog.51cto.com/1inux/1976229

资源下载

更多资源
Mario

Mario

马里奥是站在游戏界顶峰的超人气多面角色。马里奥靠吃蘑菇成长,特征是大鼻子、头戴帽子、身穿背带裤,还留着胡子。与他的双胞胎兄弟路易基一起,长年担任任天堂的招牌角色。

腾讯云软件源

腾讯云软件源

为解决软件依赖安装时官方源访问速度慢的问题,腾讯云为一些软件搭建了缓存服务。您可以通过使用腾讯云软件源站来提升依赖包的安装速度。为了方便用户自由搭建服务架构,目前腾讯云软件源站支持公网访问和内网访问。

Spring

Spring

Spring框架(Spring Framework)是由Rod Johnson于2002年提出的开源Java企业级应用框架,旨在通过使用JavaBean替代传统EJB实现方式降低企业级编程开发的复杂性。该框架基于简单性、可测试性和松耦合性设计理念,提供核心容器、应用上下文、数据访问集成等模块,支持整合Hibernate、Struts等第三方框架,其适用范围不仅限于服务器端开发,绝大多数Java应用均可从中受益。

Rocky Linux

Rocky Linux

Rocky Linux(中文名:洛基)是由Gregory Kurtzer于2020年12月发起的企业级Linux发行版,作为CentOS稳定版停止维护后与RHEL(Red Hat Enterprise Linux)完全兼容的开源替代方案,由社区拥有并管理,支持x86_64、aarch64等架构。其通过重新编译RHEL源代码提供长期稳定性,采用模块化包装和SELinux安全架构,默认包含GNOME桌面环境及XFS文件系统,支持十年生命周期更新。

用户登录
用户注册