启动之后,filebeat.conf里配置的日志路径里可以copy一些文件做测试,或者已经有一些日志文件的话,都可以在kabana里看到配置的index被自动创建: 创建一个DataView就可以查看index里的文档内容: 在Discover里选择配置的dataview查看数据:
5Pleaseselecta country.1) Afghanistan18) Israel35) Palestine2) Armenia19) Japan36) Philippines3) Azerbaijan20) Jordan37) Qatar4) Bahrain21) Kazakhstan38) Russia5) Bangladesh22) Korea (North)39) Saudi Arabia6) Bhutan23) Korea (South)40) Singapore7) Brunei24) Kuwait41) Sri Lanka8) Cambodia2...
{"@timestamp":"2023-05-30T07:15:16.913Z","log.level":"WARN","message":"flood stage disk watermark [95%] exceeded on [3dcHXXVrSA25e9kysjIvBQ][elasticsearch][/usr/share/elasticsearch/data] free: 1.2gb[2%], all indices on this node will be marked read-only","ecs.version":"1.2.0"...
解决方案二: 修改linux服务器时间和本地一致,重启系统即可 下面选择的是北京时间 [root@arebirth ~]# tzselect Please identify a location so that time zone rules can besetcorrectly. Pleaseselecta continent or ocean.1) Africa2) Americas3) Antarctica4) Arctic Ocean5) Asia6) Atlantic Ocean7) Australia...