filebeat -c config.yml -e -d “*”
Tag Archives: filebeat
filebeat custom index name
filebeat output to elasticsearch indices
filebeat separate index
filebeat log different index
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/some/path/*.log
fields:
type: "query"
- type: log
enabled: true
paths:
- /var/log/another.path/*.log
fields:
type: "error"
filebeat.config.modules:
path: ${path.config}/modules.d/*.yml
reload.enabled: false
setup.template.settings:
index.number_of_shards: 3
setup.kibana:
output.elasticsearch:
hosts: ["192.168.1.100:9200"]
index: "newindex-%{[fields.type]:other}-%{+yyyy.MM.dd}"
setup.template.name: "newindex"
setup.template.pattern: "newindex-*"
ERROR [input.filestream] filestream/input.go:138 File could not be opened for reading: failed opening
Problem too many open file
vim /lib/systemd/system/filebeat.service
[Service]
LimitNOFILE=infinity
systemctl daemon-reload
systemctl restart filebeat
ERROR instance/beat.go:951 Exiting: 1 error: setting ‘filebeat.prospectors’ has been removed
Change filebeat.prospectors:
to:
filebeat.inputs: