×ðÁú¿­Ê±¹ÙÍøµÇ¼

ÔõÑùÔÚLinuxÉÏÉèÖø߿ÉÓõÄÈÝÆ÷ÈÕÖ¾ÖÎÀí

ÔõÑùÔÚlinuxÉÏÉèÖø߿ÉÓõÄÈÝÆ÷ÈÕÖ¾ÖÎÀí

Ëæ×ÅÈÝÆ÷ÊÖÒÕµÄѸËÙÉú³¤£¬Ô½À´Ô½¶àµÄÆóÒµ½ÓÄÉÈÝÆ÷»¯°²ÅÅÀ´Ìá¸ßϵͳµÄ¿ÉÉìËõÐԺͿɿ¿ÐÔ ¡£ÔÚÈÝÆ÷»¯ÇéÐÎÖУ¬ÎªÁËÀû±ãÖÎÀíºÍ¼à¿ØÈÝÆ÷µÄÔËÐÐÇéÐΣ¬¹ØÓÚÈÝÆ÷ÈÕÖ¾¾ÙÐм¯ÖÐÖÎÀíÊǺÜÊÇÖ÷ÒªµÄ ¡£

±¾ÎĽ«ÏÈÈÝÔõÑùÔÚlinuxÉÏÉèÖø߿ÉÓõÄÈÝÆ÷ÈÕÖ¾ÖÎÀí£¬²¢¸½´ø´úÂëʾÀý£¬×ÊÖú¶ÁÕ߸üºÃµØÃ÷È·ºÍʵ¼ù ¡£

Ò»¡¢Ñ¡ÔñºÏÊʵÄÈÕÖ¾ÖÎÀí¹¤¾ß

ÔÚÑ¡ÔñÈÝÆ÷ÈÕÖ¾ÖÎÀí¹¤¾ßʱ£¬ÐèҪ˼Á¿ÒÔϼ¸¸ö·½Ã棺

Ö§³ÖÈÝÆ÷»¯ÇéÐΣºÑ¡ÔñÒ»¸öÄܹ»Ö§³ÖÈÝÆ÷»¯ÇéÐεÄÈÕÖ¾ÖÎÀí¹¤¾ß£¬Äܹ»Àû±ãµØÍøÂçºÍÆÊÎöÈÝÆ÷µÄÈÕÖ¾Êý¾Ý ¡£

¸ß¿ÉÓÃÐÔ£ºÎªÁËÈ·±£ÈÝÆ÷ÈÕÖ¾µÄÒ»Á¬¿ÉÓÃÐÔ£¬ÐèҪѡÔñÒ»¸öÖ§³Ö¸ß¿ÉÓõÄÈÕÖ¾ÖÎÀí¹¤¾ß£¬ÒÔ±ÜÃâÈÕÖ¾Êý¾Ýɥʧ»òÖÐÖ¹ ¡£

Ò×ÓÚʹÓúͰ²ÅÅ£ºÑ¡ÔñÒ»¸öÒ×ÓÚʹÓúͰ²ÅŵÄÈÕÖ¾ÖÎÀí¹¤¾ß£¬¿ÉÒÔ¼õÇáϵͳÖÎÀíÔ±µÄÊÂÇéѹÁ¦ ¡£

³£¼ûµÄÈÝÆ÷ÈÕÖ¾ÖÎÀí¹¤¾ßÓÐELK£¨Elasticsearch, Logstash, Kibana£©¡¢FluentdÒÔ¼°PrometheusµÈ ¡£

¶þ¡¢×°ÖúÍÉèÖÃELK£¨Elasticsearch, Logstash, Kibana£©

ELKÊÇÒ»¸öÊ¢ÐеÄÈÝÆ÷ÈÕÖ¾ÖÎÀí¹¤¾ß£¬ÓÉElasticsearch¡¢LogstashºÍKibanaÈý¸ö×é¼þ×é³É ¡£ÏÂÃæÒÔCentOSΪÀý£¬ÏÈÈÝÔõÑù×°ÖúÍÉèÖÃELK ¡£

×°ÖÃElasticsearch

sudo yum install java-1.8.0-openjdk -y
sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
sudo tee /etc/yum.repos.d/elasticsearch.repo <<EOF
[elasticsearch]
name=Elasticsearch repository for 7.x packages
baseurl=https://artifacts.elastic.co/packages/7.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF

sudo yum install elasticsearch -y
sudo systemctl enable elasticsearch
sudo systemctl start elasticsearch

µÇ¼ºó¸´ÖÆ

×°ÖÃLogstash

sudo tee /etc/yum.repos.d/logstash.repo <<EOF
[logstash]
name=Elastic repository for 7.x packages
baseurl=https://artifacts.elastic.co/packages/7.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF

sudo yum install logstash -y
sudo systemctl enable logstash
sudo systemctl start logstash

µÇ¼ºó¸´ÖÆ

×°ÖÃKibana

sudo tee /etc/yum.repos.d/kibana.repo <<EOF
[kibana]
name=Kibana repository for 7.x packages
baseurl=https://artifacts.elastic.co/packages/7.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF

sudo yum install kibana -y
sudo systemctl enable kibana
sudo systemctl start kibana

µÇ¼ºó¸´ÖÆ

ÉèÖÃLogstash

ÔÚLogstashµÄÉèÖÃÎļþ/etc/logstash/conf.d/logstash.confÖУ¬Ìí¼ÓÒÔÏÂÄÚÈÝ£º

input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
  }
}

µÇ¼ºó¸´ÖÆ

ÉèÖÃKibana

ÔÚKibanaµÄÉèÖÃÎļþ/etc/kibana/kibana.ymlÖУ¬Ìí¼ÓÒÔÏÂÄÚÈÝ£º

server.host: "0.0.0.0"
elasticsearch.hosts: ["http://localhost:9200"]

µÇ¼ºó¸´ÖÆ

ÖØÆôLogstashºÍKibanaЧÀÍ£º

sudo systemctl restart logstash
sudo systemctl restart kibana

µÇ¼ºó¸´ÖÆ

ÏÖÔÚ£¬ELKÒѾ­×°ÖÃÍê³É²¢ÉèÖúÃÁË£¬¿ÉÒÔͨ¹ýKibanaµÄWeb½çÃæ»á¼ûºÍÅÌÎÊÈÝÆ÷ÈÕÖ¾Êý¾Ý ¡£

Èý¡¢Ê¹ÓÃFluentd¾ÙÐÐÈÝÆ÷ÈÕÖ¾ÖÎÀí

FluentdÊÇÁíÒ»¸öÊ¢ÐеÄÈÝÆ÷ÈÕÖ¾ÖÎÀí¹¤¾ß£¬ËüµÄÉè¼ÆÀíÄîÊǼòÆÓ¡¢ÇáÁ¿¼¶ºÍ¿ÉÀ©Õ¹µÄ ¡£ÏÂÃæÒÔUbuntuΪÀý£¬ÏÈÈÝÔõÑù×°ÖúÍÉèÖÃFluentd ¡£

×°ÖÃFluentd

curl -L https://toolbelt.treasuredata.com/sh/install-ubuntu-focal-td-agent4.sh | sh
sudo systemctl enable td-agent
sudo systemctl start td-agent

µÇ¼ºó¸´ÖÆ

ÉèÖÃFluentd

±à¼­FluentdµÄÉèÖÃÎļþ/etc/td-agent/td-agent.conf£¬Ìí¼ÓÒÔÏÂÄÚÈÝ£º

<source>
  @type tail
  path /var/log/containers/*.log
  pos_file /var/log/td-agent/td-agent.log.pos
  tag kube.*
  format json
  time_format %Y-%m-%dT%H:%M:%S.%NZ
  read_from_head true
</source>

<match label1.**>
  @type elasticsearch
  host localhost
  port 9200
  logstash_format true
  flush_interval 5s
</match>

µÇ¼ºó¸´ÖÆ

ÖØÆôFluentdЧÀÍ£º

sudo systemctl restart td-agent

µÇ¼ºó¸´ÖÆ

ÏÖÔÚ£¬FluentdÒѾ­×°ÖÃÍê³É²¢ÉèÖúÃÁË£¬¿ÉÒÔÍøÂçºÍ´æ´¢ÈÝÆ÷ÈÕÖ¾Êý¾Ý ¡£

½áÓï

ÈÝÆ÷ÈÕÖ¾ÖÎÀí¹ØÓÚ°ü¹ÜÈÝÆ÷ÇéÐεÄÎȹÌÔËÐк͹ÊÕÏÅŲéºÜÊÇÖ÷Òª ¡£±¾ÎÄÏÈÈÝÁËÔõÑùÔÚlinuxÉÏÉèÖø߿ÉÓõÄÈÝÆ÷ÈÕÖ¾ÖÎÀí£¬²¢ÌṩÁËELKºÍFluentdµÄ×°ÖúÍÉèÖÃʾÀý ¡£¶ÁÕß¿ÉÒÔƾ֤×ÔÉíÐèÇóÑ¡ÔñºÏÊʵŤ¾ß¾ÙÐÐÈÝÆ÷ÈÕÖ¾ÖÎÀí£¬²¢Æ¾Ö¤Ê¾Àý¾ÙÐÐÉèÖúÍʹÓà ¡£

²Î¿¼×ÊÁÏ£º

https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-install.html

https://www.elastic.co/guide/en/logstash/current/installing-logstash.html

https://www.elastic.co/guide/en/kibana/current/rpm.html

https://fluentbit.io/

https://docs.fluentd.org/v1.0/articles/docker-logging-efk-compose

ÒÔÉϾÍÊÇÔõÑùÔÚLinuxÉÏÉèÖø߿ÉÓõÄÈÝÆ÷ÈÕÖ¾ÖÎÀíµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡

ÃâÔð˵Ã÷£ºÒÔÉÏչʾÄÚÈÝȪԴÓÚÏàÖúýÌå¡¢ÆóÒµ»ú¹¹¡¢ÍøÓÑÌṩ»òÍøÂçÍøÂçÕûÀí£¬°æȨÕùÒéÓë±¾Õ¾Î޹أ¬ÎÄÕÂÉæ¼°¿´·¨Óë¿´·¨²»´ú±í×ðÁú¿­Ê±¹ÙÍøµÇ¼ÂËÓÍ»úÍø¹Ù·½Ì¬¶È£¬Çë¶ÁÕß½ö×ö²Î¿¼ ¡£±¾ÎĽӴýתÔØ£¬×ªÔØÇë˵Ã÷À´ÓÉ ¡£ÈôÄúÒÔΪ±¾ÎÄÇÖÕ¼ÁËÄúµÄ°æȨÐÅÏ¢£¬»òÄú·¢Ã÷¸ÃÄÚÈÝÓÐÈκÎÉæ¼°ÓÐÎ¥¹«µÂ¡¢Ã°·¸Ö´·¨µÈÎ¥·¨ÐÅÏ¢£¬ÇëÄúÁ¬Ã¦ÁªÏµ×ðÁú¿­Ê±¹ÙÍøµÇ¼ʵʱÐÞÕý»òɾ³ý ¡£

Ïà¹ØÐÂÎÅ

ÁªÏµ×ðÁú¿­Ê±¹ÙÍøµÇ¼

18523999891

¿É΢ÐÅÔÚÏß×Éѯ

ÊÂÇéʱ¼ä£ºÖÜÒ»ÖÁÖÜÎ壬9:30-18:30£¬½ÚãåÈÕÐÝÏ¢

QR code
ÍøÕ¾µØͼ