Logstash: Difference between revisions
From Leo's Notes
This page was last edited on 9 October 2013, at 21:54.
No edit summary |
No edit summary |
||
| Line 6: | Line 6: | ||
=== Elastic Search === | === Elastic Search === | ||
Download and extract the archive. | Download and extract the archive. Install java: | ||
wget jre-7u21-linux-x64.rpm | wget jre-7u21-linux-x64.rpm | ||
rpm -ivh jre-7u21-linux-x64.rpm | rpm -ivh jre-7u21-linux-x64.rpm | ||
Then run elastic search. You probably want to specify a configuration file. | |||
=== | <syntaxhighlight lang="bash" line start="1" enclose="div"> | ||
input { | |||
stdin { | |||
# A type is a label applied to an event. It is used later with filters | |||
# to restrict what filters are run against each event. | |||
type => "human" | |||
} | |||
syslog { | |||
type => syslog | |||
port => 5544 | |||
} | |||
} | |||
output { | |||
# Print each event to stdout. | |||
stdout { | |||
# Enabling 'debug' on the stdout output will make logstash pretty-print the | |||
# entire event as something similar to a JSON representation. | |||
# debug => true | |||
} | |||
# You can have multiple outputs. All events generally to all outputs. | |||
# Output events to elasticsearch | |||
elasticsearch { | |||
# Setting 'embedded' will run a real elasticsearch server inside logstash. | |||
# This option below saves you from having to run a separate process just | |||
# for ElasticSearch, so you can get started quicker! | |||
embedded => true | |||
} | |||
} | |||
</syntaxhighlight> | |||
Then, just run the monolithic jar with the agent and web enabled like so: | |||
java -jar logstash-1.2.1-flatjar.jar agent -f hello.conf -- web | |||
Revision as of 21:54, 9 October 2013
Logstash is the open source version of splunk, using ElasticSearch as its search engine.
Installation
For detailed information, consult logstash's tutorial at http://logstash.net/docs/1.1.10/tutorials/getting-started-centralized
Elastic Search
Download and extract the archive. Install java:
wget jre-7u21-linux-x64.rpm rpm -ivh jre-7u21-linux-x64.rpm
Then run elastic search. You probably want to specify a configuration file.
input {
stdin {
# A type is a label applied to an event. It is used later with filters
# to restrict what filters are run against each event.
type => "human"
}
syslog {
type => syslog
port => 5544
}
}
output {
# Print each event to stdout.
stdout {
# Enabling 'debug' on the stdout output will make logstash pretty-print the
# entire event as something similar to a JSON representation.
# debug => true
}
# You can have multiple outputs. All events generally to all outputs.
# Output events to elasticsearch
elasticsearch {
# Setting 'embedded' will run a real elasticsearch server inside logstash.
# This option below saves you from having to run a separate process just
# for ElasticSearch, so you can get started quicker!
embedded => true
}
}
Then, just run the monolithic jar with the agent and web enabled like so:
java -jar logstash-1.2.1-flatjar.jar agent -f hello.conf -- web
Integration with Clients
https://groups.google.com/forum/#!msg/logstash-users/X6kNHU0alBg/j95HZkTLo-EJ