ELK with Filebeat by Docker-compose - Simple & Easy way to file logging
ELK with Filebeat by Docker-compose - Simple & Easy way to file logging
# Docker install
curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
sudo usermod -aG docker $(whoami)
# Docker-compose install
sudo apt-get install docker-compose
git clone https://github.com/gnokoheat/elk-with-filebeat-by-docker-compose
cd elk-with-filebeat-by-docker-compose/
docker-compose up -d
# Make your own log index
{
...
"mappings": {
"properties": {
"name": {
"type": "keyword"
},
"class": {
"type": "keyword"
},
"state": {
"type": "integer"
},
"@timestamp": {
"type": "date"
}
}
}
}
# Change 'timestamp' to your log custom timestamp key
filter {
...
date{
match => ["timestamp", "UNIX_MS"]
target => "@timestamp"
}
}
# Change 'time.localtime' to your location time
filter {
...
ruby {
code => "event.set('indexDay', event.get('[@timestamp]').time.localtime('+09:00').strftime('%Y%m%d'))"
}
}
Create Index pattern
Search Log