Logstash

From Leo's Notes
Revision as of 05:00, 24 April 2013 by Leo (talk | contribs)
This page was last edited on 24 April 2013, at 05:00.

Logstash is the open source version of splunk, using ElasticSearch as its search engine.

Installation

For detailed information, consult logstash's tutorial at http://logstash.net/docs/1.1.10/tutorials/getting-started-centralized

Elastic Search

Download and extract the archive. Ensure Java is installed, then run elastic search:

wget jre-7u21-linux-x64.rpm
rpm -ivh jre-7u21-linux-x64.rpm

~/elasticsearch-0.20.6//bin/elasticsearch -f

Redis

Download and compile redis:

yum install make gcc

wget redis-2.6.12.tar.gz
tar -xzf redis-2.6.12.tar.gz
cd redis-2.6.12
make
# You can run `make install`, or just run the binary from the src directory
# like `./src/redis-server` if you decide to not run the following two lines:
make install
redis-server

Configuration

Integration with Clients

https://groups.google.com/forum/#!msg/logstash-users/X6kNHU0alBg/j95HZkTLo-EJ