[root@k8-node2-dc ~]#cat /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/lib/docker/containers/*/*.log
processors:
- drop_fields:
fields: ["beat","input","source","offset"]
output.kafka:
enable: true
hosts: ["10.12.12.45:9092","10.12.12.46:9092","10.12.12.47:9092"]
topic: es-tmslogs
worker: 2
required_acks: 1
compression: gzip
max_message_bytes: 100000
?
?logstash
input{
kafka{
bootstrap_servers => "10.12.12.45:9092","10.12.12.46:9092","10.12.12.47:9092"
topics => ["es-tmslogs"]
codec => json
}
}
output{
elasticsearch {
hosts => ["10.12.12.45:9200"]
index => "logstash-%{+YYYY.MM.dd}"
}
}
|