Logstash: Difference between revisions

From Leo's Notes
This page was last edited on 9 October 2013, at 21:54.
No edit summary
No edit summary
Line 6: Line 6:


=== Elastic Search ===
=== Elastic Search ===
Download and extract the archive. Ensure Java is installed, then run elastic search:
Download and extract the archive. Install java:
  wget jre-7u21-linux-x64.rpm
  wget jre-7u21-linux-x64.rpm
  rpm -ivh jre-7u21-linux-x64.rpm
  rpm -ivh jre-7u21-linux-x64.rpm
   
   
~/elasticsearch-0.20.6//bin/elasticsearch -f
Then run elastic search. You probably want to specify a configuration file.  


=== Redis ===
<syntaxhighlight lang="bash" line start="1" enclose="div">
input {
  stdin {
    # A type is a label applied to an event. It is used later with filters
    # to restrict what filters are run against each event.
    type => "human"
  }


'''This may not be necessary if we are going to be using syslog to log everything'''
  syslog {
        type => syslog
        port => 5544
  }
}


Download and compile redis:
output {
yum install make gcc
  # Print each event to stdout.
  stdout {
wget redis-2.6.12.tar.gz
    # Enabling 'debug' on the stdout output will make logstash pretty-print the
tar -xzf redis-2.6.12.tar.gz
    # entire event as something similar to a JSON representation.
cd redis-2.6.12
#    debug => true
make
  }
# You can run `make install`, or just run the binary from the src directory
  # You can have multiple outputs. All events generally to all outputs.
# like `./src/redis-server` if you decide to not run the following two lines:
  # Output events to elasticsearch
make install
  elasticsearch {
  redis-server
    # Setting 'embedded' will run a real elasticsearch server inside logstash.
 
    # This option below saves you from having to run a separate process just
=== Logstash ===
    # for ElasticSearch, so you can get started quicker!
 
    embedded => true
Download logstash
  }
wget http://logstash.objects.dreamhost.com/release/logstash-1.1.10-flatjar.jar
}
 
</syntaxhighlight>
'''note: (for 1.1.10) if you want to use logstash's web ui, you need to use the monolothic jar file at http://build.logstash.net/job/logstash.jar.daily/237/artifact/build/logstash-1.1.10-monolithic.jar'''
'''note2: if you want to use what that google groups person said, you also need grok. see https://github.com/jordansissel/grok/blob/master/INSTALL'''
 
You will then need to configure logstash by creating a config file, then running the jar file with <code>-f config.cfg</code>


Then, just run the monolithic jar with the agent and web enabled like so:


=== Kibana ===
java -jar logstash-1.2.1-flatjar.jar agent -f hello.conf -- web
Kibana is the nice looking web UI that looks similar to splunk.


More info at http://kibana.org/intro.html
Get it at https://github.com/rashidkpc/Kibana.git





Revision as of 21:54, 9 October 2013

Logstash is the open source version of splunk, using ElasticSearch as its search engine.

Installation

For detailed information, consult logstash's tutorial at http://logstash.net/docs/1.1.10/tutorials/getting-started-centralized

Elastic Search

Download and extract the archive. Install java:

wget jre-7u21-linux-x64.rpm
rpm -ivh jre-7u21-linux-x64.rpm

Then run elastic search. You probably want to specify a configuration file.

input {
  stdin {
    # A type is a label applied to an event. It is used later with filters
    # to restrict what filters are run against each event.
    type => "human"
  }

  syslog {
        type => syslog
        port => 5544
  }
}

output {
  # Print each event to stdout.
  stdout {
    # Enabling 'debug' on the stdout output will make logstash pretty-print the
    # entire event as something similar to a JSON representation.
#    debug => true
  }
  # You can have multiple outputs. All events generally to all outputs.
  # Output events to elasticsearch
  elasticsearch {
    # Setting 'embedded' will run  a real elasticsearch server inside logstash.
    # This option below saves you from having to run a separate process just
    # for ElasticSearch, so you can get started quicker!
    embedded => true
  }
}

Then, just run the monolithic jar with the agent and web enabled like so:

java -jar logstash-1.2.1-flatjar.jar agent -f hello.conf -- web


Integration with Clients

https://groups.google.com/forum/#!msg/logstash-users/X6kNHU0alBg/j95HZkTLo-EJ