[2019-09-07T02:53:03,506][INFO ][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://192.168.30.31:9200/, :path=>"/"}
[2019-09-07T02:53:03,508][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>#<URI::HTTP:0x66479443 URL:http://192.168.30.31:9200/>, :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://192.168.30.31:9200/'"}
======================
logstash.yml的配置:
xpack.monitoring.enabled: "true"
xpack.monitoring.elasticsearch.url: ["http://192.168.30.31:9200"]
xpack.monitoring.elasticsearch.username: "elastic"
xpack.monitoring.elasticsearch.password: "123456"
========================
logstash.conf配置:
input {
file {
path => ["/var/log/messages"]
type => "syslog"
}
}
filter {
grok {
match => [ "message", "%{SYSLOGBASE} %{GREEDYDATA:content}" ]
}
}
output {
elasticsearch {
hosts => ["192.168.30.31:9200"]
user => elastic
password => 123456
manage_template => true
index => "syslog-%{+YYY.MM.dd}"
}
}
~
~
~
~
[2019-09-07T02:53:03,508][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>#<URI::HTTP:0x66479443 URL:http://192.168.30.31:9200/>, :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://192.168.30.31:9200/'"}
======================
logstash.yml的配置:
xpack.monitoring.enabled: "true"
xpack.monitoring.elasticsearch.url: ["http://192.168.30.31:9200"]
xpack.monitoring.elasticsearch.username: "elastic"
xpack.monitoring.elasticsearch.password: "123456"
========================
logstash.conf配置:
input {
file {
path => ["/var/log/messages"]
type => "syslog"
}
}
filter {
grok {
match => [ "message", "%{SYSLOGBASE} %{GREEDYDATA:content}" ]
}
}
output {
elasticsearch {
hosts => ["192.168.30.31:9200"]
user => elastic
password => 123456
manage_template => true
index => "syslog-%{+YYY.MM.dd}"
}
}
~
~
~
~
0 个回复