Skip to main content

An Experiment with Filebeat and ELK Stack

ELK Stack is one of the best distributed systems to centralize lots of servers' logs. Filebeat is a log shipper that keeps track of the given logs and pushes them to the Logstash. Then logstash outputs these logs to elasticsearch. I am not going to explain how to install ELK Stack but experiment about sending multiple log types (document_type) using filebeat log shipper to logstash server.

So there is one server (agent) filebeat and apache http server installed on it. Agent is going to send syslogs, http access logs and http error logs to Logstash.

Here is the contents of the /etc/filebeat/filebeat.yml config file:

There is one server (backend) logstash installed on it.
Here is the contents of the files located in the /etc/logstash directory:


Popular posts from this blog

Find and replace with sed command in Linux

Find and replace feature is always handy. It can turn into a torture when it comes to change or delete a simple constant string in a text file. There is a handy tool in linux for doing these kind of tihngs. Actually sed is not a text editor but it is used outside of the text file to make changes.