Logstash
From Leo's Notes
This page was last edited on 9 October 2013, at 21:54.
Logstash is the open source version of splunk, using ElasticSearch as its search engine.
Installation
For detailed information, consult logstash's tutorial at http://logstash.net/docs/1.1.10/tutorials/getting-started-centralized
Elastic Search
Download and extract the archive. Install java:
wget jre-7u21-linux-x64.rpm rpm -ivh jre-7u21-linux-x64.rpm
Then run elastic search. You probably want to specify a configuration file.
input {
stdin {
# A type is a label applied to an event. It is used later with filters
# to restrict what filters are run against each event.
type => "human"
}
syslog {
type => syslog
port => 5544
}
}
output {
# Print each event to stdout.
stdout {
# Enabling 'debug' on the stdout output will make logstash pretty-print the
# entire event as something similar to a JSON representation.
# debug => true
}
# You can have multiple outputs. All events generally to all outputs.
# Output events to elasticsearch
elasticsearch {
# Setting 'embedded' will run a real elasticsearch server inside logstash.
# This option below saves you from having to run a separate process just
# for ElasticSearch, so you can get started quicker!
embedded => true
}
}
Then, just run the monolithic jar with the agent and web enabled like so:
java -jar logstash-1.2.1-flatjar.jar agent -f hello.conf -- web
Integration with Clients
https://groups.google.com/forum/#!msg/logstash-users/X6kNHU0alBg/j95HZkTLo-EJ