ÔõÑùÔÚLinuxÇéÐÎÖÐʹÓÃGraylog¾ÙÐÐÈÕÖ¾ÆÊÎö£¿
ÔõÑùÔÚlinuxÇéÐÎÖÐʹÓÃgraylog¾ÙÐÐÈÕÖ¾ÆÊÎö£¿
¸ÅÊö£º
GraylogÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄ¿ªÔ´ÈÕÖ¾ÖÎÀíºÍÆÊÎö¹¤¾ß£¬Ëü¿ÉÒÔ×ÊÖúÎÒÃÇÔÚLinuxÇéÐÎÖÐÍøÂç¡¢´æ´¢ºÍÆÊÎöÈÕÖ¾Êý¾Ý¡£ÔÚ±¾ÎÄÖУ¬ÎÒÃǽ«Ìṩһ¸ö¼òÆÓµÄÖ¸ÄÏ£¬ÒÔ×ÊÖúÄúÔÚLinuxÇéÐÎÖÐʹÓÃGraylog¾ÙÐÐÈÕÖ¾ÆÊÎö¡£
°ì·¨Ò»£º×°ÖÃGraylog
Ê×ÏÈ£¬ÎÒÃÇÐèÒªÔÚLinuxЧÀÍÆ÷ÉÏ×°ÖÃGraylog¡£ÒÔÏÂÊÇÔÚCentOSϵͳÉÏ×°ÖÃGraylogµÄ°ì·¨£º
ʹÓÃÒÔÏÂÏÂÁî×°ÖÃÐëÒªµÄÒÀÀµÏ
sudo yum install epel-release sudo yum install java-1.8.0-openjdk.x86_64
µÇ¼ºó¸´ÖÆ
ÏÂÔغÍ×°ÖÃMongoDB£º
sudo yum install mongodb sudo systemctl enable mongod sudo systemctl start mongod
µÇ¼ºó¸´ÖÆ
ÏÂÔغÍ×°ÖÃElasticsearch£º
sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch sudo vi /etc/yum.repos.d/elasticsearch.repo
µÇ¼ºó¸´ÖÆ
ÔÚÎļþÖÐÌí¼ÓÒÔÏÂÄÚÈÝ£º
[elasticsearch-6.x] name=Elasticsearch repository for 6.x packages baseurl=https://artifacts.elastic.co/packages/6.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md
µÇ¼ºó¸´ÖÆ
ÉúÑIJ¢Í˳öÎļþ£¬È»ºóÔËÐÐÒÔÏÂÏÂÁ
sudo yum install elasticsearch sudo systemctl enable elasticsearch sudo systemctl start elasticsearch
µÇ¼ºó¸´ÖÆ
ÏÂÔغÍ×°ÖÃGraylog£º
wget https://packages.graylog2.org/repo/packages/graylog-3.2-repository_latest.rpm sudo rpm -i graylog-3.2-repository_latest.rpm sudo yum install graylog-server sudo systemctl enable graylog-server sudo systemctl start graylog-server
µÇ¼ºó¸´ÖÆ
°ì·¨¶þ£ºÉèÖÃGraylog
·¿ªGraylogµÄÉèÖÃÎļþ/etc/graylog/server/server.conf£º
sudo vi /etc/graylog/server/server.conf
µÇ¼ºó¸´ÖÆ
ÉèÖÃÒÔϲÎÊý£¨Æ¾Ö¤ÄúµÄÐèÇó¾ÙÐÐÐ޸ģ©£º
rest_listen_uri = http://<your_server_ip>:9000/api/ web_listen_uri = http://<your_server_ip>:9000/ elasticsearch_hosts = http://<your_server_ip>:9200
µÇ¼ºó¸´ÖÆ
°ì·¨Èý£ºÆô¶¯Graylog
ÔÚÍê³ÉÉèÖúó£¬ÉúÑIJ¢Í˳öÎļþ¡£
ÖØÐÂÆô¶¯GraylogЧÀÍ£º
sudo systemctl restart graylog-server
µÇ¼ºó¸´ÖÆ
°ì·¨ËÄ£ºÊ¹ÓÃGraylog¾ÙÐÐÈÕÖ¾ÆÊÎö
·¿ªWebä¯ÀÀÆ÷²¢»á¼ûhttp:// :9000£¬ÓÃÄú֮ǰÉèÖõÄÓû§ÃûºÍÃÜÂëµÇ¼µ½Graylog¿ØÖÆ̨¡£
½¨ÉèÒ»¸öеÄÊäÈ룬ÓÃÓÚÎüÊÕÈÕÖ¾Êý¾Ý¡£Ñ¡ÔñÄúÏ£ÍûʹÓõÄÈÕÖ¾Ô´ÀàÐÍ£¬²¢Æ¾Ö¤Ö¸Ê¾¾ÙÐÐÉèÖá£
ÉèÖÃÄúµÄÈÕÖ¾·¢¼þÈË£¨ÀýÈ磬Îļþ»òÆäËûÓ¦ÓóÌÐò£©ÒÔ½«ÈÕÖ¾Êý¾Ý·¢Ë͵½GraylogЧÀÍÆ÷µÄÊäÈë¶Ë¿Ú¡£
Ò»µ©Graylog×îÏÈÎüÊպʹ¦Öóͷ£ÈÕÖ¾Êý¾Ý£¬Äú¿ÉÒÔʹÓÃGraylogµÄÅÌÎʺÍËÑË÷¹¦Ð§À´ÆÊÎöÈÕÖ¾Êý¾Ý¡£Äú¿ÉÒÔƾ֤ʱ¼ä¹æÄ£¡¢Òªº¦×Ö¡¢ÈªÔ´¡¢×ֶεÈÌõ¼þÀ´¹ýÂ˺ÍËÑË÷ÈÕÖ¾ÐÅÏ¢¡£
´úÂëʾÀý£º
ÒÔÏÂÊÇʹÓÃPython·¢ËÍÈÕÖ¾µ½GraylogµÄʾÀý´úÂ룬ÒÔÑÝʾÔõÑù½«Ó¦ÓóÌÐòµÄÈÕÖ¾Êý¾Ý·¢Ë͵½GraylogЧÀÍÆ÷£º
import logging import graypy logger = logging.getLogger('my_logger') logger.setLevel(logging.DEBUG) handler = graypy.GELFUDPHandler('localhost', 12201) logger.addHandler(handler) logger.debug('This is a debug message') logger.info('This is an info message') logger.warning('This is a warning message') logger.error('This is an error message')
µÇ¼ºó¸´ÖÆ
ͨ¹ýʹÓÃÉÏÊö´úÂëʾÀý£¬Äú¿ÉÒÔ½«Ó¦ÓóÌÐòµÄÈÕÖ¾·¢Ë͵½GraylogЧÀÍÆ÷£¬²¢Í¨¹ýGraylogµÄ¿ØÖÆ̨¾ÙÐÐÆÊÎöºÍËÑË÷¡£
×ܽ᣺
ͨ¹ý±¾Ö¸ÄÏ£¬ÎÒÃÇѧϰÁËÔõÑùÔÚLinuxÇéÐÎÖÐ×°ÖúÍÉèÖÃGraylog£¬²¢Ê¹ÓÃPythonʾÀý´úÂ뽫ÈÕÖ¾Êý¾Ý·¢Ë͵½GraylogЧÀÍÆ÷¡£Ï£ÍûÕâƪÎÄÕ¶ÔÄúÔÚLinuxÇéÐÎÖÐʹÓÃGraylog¾ÙÐÐÈÕÖ¾ÆÊÎöÌṩÁËһЩ×ÊÖúºÍÖ¸µ¼¡£Ê¹ÓÃGraylog£¬Äú¿ÉÒÔ¸üÇáËɵØÍøÂç¡¢´æ´¢ºÍÆÊÎö´ó×ÚµÄÈÕÖ¾Êý¾Ý£¬ÒÔ±ã¸üºÃµØÃ÷È·ºÍ¼à¿ØÄúµÄÓ¦ÓóÌÐòºÍϵͳ¡£
ÒÔÉϾÍÊÇÔõÑùÔÚLinuxÇéÐÎÖÐʹÓÃGraylog¾ÙÐÐÈÕÖ¾ÆÊÎö£¿µÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡