1.配置
filebeat.inputs:
- type: log
enable: true
paths:
- /var/log/nginx/access.log
output.elasticsearch:
hosts: ["10.0.0.51:9200"]
2.启动
[root@web01 ~]# systemctl restart filebeat.service
#验证
[root@web01 ~]# ps -ef | grep filebeat
3.测试
#访问Nginx
http://10.0.0.7:8081/
#查看ES页面