[filebeats] filebeats 설치해보자
설치
다운 → 압축해제 → 심볼릭링크
$ wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.9.2-linux-x86_64.tar.gz
$ tar -zxvf filebeat-7.9.2-linux-x86_64.tar.gz
$ ln -s filebeat-7.9.2-linux-x86_64.tar.gz filebeat
cofing
###################### Filebeat Configuration Example #########################
# ========================= Filebeat inputs ===============================
filebeat.inputs:
- type: log
enabled: true
paths:
- /home/ec2-user/data-lake/logs/beats_batch.log
fields:
index_name: "datalake-batch"
# ============================= Filebeat modules==========================
filebeat.config.modules:
path: ${path.config}/modules.d/*.yml
reload.enabled: false
# ====================== Elasticsearch template setting =======================
setup.template.name: "datalake-batch"
#setup.template.fields: "datalake-fields.yml"
setup.template.overwrite: false
setup.template.settings:
index.number_of_shards: 1
index.number_of_replicas: 1
Caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
위와 같은 에러 발생시 output.elasticsearch 부분 주석처리 아마도 이것은 x-pack security 관련 설정때문에..
로그스테시 설정 잡아주니까
들어감