Logstash

From Leo's Notes
Revision as of 21:54, 9 October 2013 by Leo (talk | contribs)
This page was last edited on 9 October 2013, at 21:54.

Logstash is the open source version of splunk, using ElasticSearch as its search engine.

Installation

For detailed information, consult logstash's tutorial at http://logstash.net/docs/1.1.10/tutorials/getting-started-centralized

Elastic Search

Download and extract the archive. Install java:

wget jre-7u21-linux-x64.rpm
rpm -ivh jre-7u21-linux-x64.rpm

Then run elastic search. You probably want to specify a configuration file.

input {
  stdin {
    # A type is a label applied to an event. It is used later with filters
    # to restrict what filters are run against each event.
    type => "human"
  }

  syslog {
        type => syslog
        port => 5544
  }
}

output {
  # Print each event to stdout.
  stdout {
    # Enabling 'debug' on the stdout output will make logstash pretty-print the
    # entire event as something similar to a JSON representation.
#    debug => true
  }
  # You can have multiple outputs. All events generally to all outputs.
  # Output events to elasticsearch
  elasticsearch {
    # Setting 'embedded' will run  a real elasticsearch server inside logstash.
    # This option below saves you from having to run a separate process just
    # for ElasticSearch, so you can get started quicker!
    embedded => true
  }
}

Then, just run the monolithic jar with the agent and web enabled like so:

java -jar logstash-1.2.1-flatjar.jar agent -f hello.conf -- web


Integration with Clients

https://groups.google.com/forum/#!msg/logstash-users/X6kNHU0alBg/j95HZkTLo-EJ