Logstash收集Tomcat日志


1.安裝Tomcat

1.安裝java環境
[root@web01 ~]# rpm -ivh jdk-8u181-linux-x64.rpm

2.上傳包
[root@web01 ~]# rz apache-tomcat-10.0.0-M7.tar.gz

3.解壓
[root@web01 ~]# tar xf apache-tomcat-10.0.0-M7.tar.gz -C /usr/local/

4.做軟連接
[root@web01 ~]# ln -s /usr/local/apache-tomcat-10.0.0-M7 /usr/local/tomcat

5.啟動Tomcat
[root@web01 ~]# /usr/local/tomcat/bin/startup.sh

6.訪問頁面 10.0.0.7:8080

2.配置Logstash收集Tomcat日志到文件

[root@web01 ~]# vim /etc/logstash/conf.d/tomcat_file.conf
input {
  file {
    path => "/usr/local/tomcat/logs/localhost_access_log.*.txt"
    start_position => "beginning"
  }
}
output {
  file {
    path => "/tmp/tomcat_%{+YYYY-MM-dd}.log"
  }
}

3.配置Logstash收集Tomcat日志到ES

[root@web01 ~]# vim /etc/logstash/conf.d/tomcat_es.conf
input {
  file {
    path => "/usr/local/tomcat/logs/localhost_access_log.*.txt"
    start_position => "beginning"
  }
}
output {
  elasticsearch {
    hosts => ["10.0.0.51:9200"]
    index => "tomcat_%{+YYYY-MM-dd}.log"
  }
}

三、收集Tomcat日志修改格式

#收集tomcat日志,當遇到報錯時,一條報錯會被分割成很多條數據,不方便查看

解決方法:
1.修改tomcat日志格式為json
	1)開發修改輸出日志為json
	2)修改tomcat配置,日志格式為json
2.使用logstash的input插件下的mutiline模塊

1.方法一:修改tomcat日志格式

1)配置tomcat日志為json格式

[root@web01 ~]# vim /usr/local/tomcat/conf/server.xml
#把原來的日志格式注釋,添加我們的格式
<Valve className="org.apache.catalina.valves.AccessLogValve" directory="logs"
               prefix="tomcat_access_json" suffix=".log"
               pattern="{&quot;clientip&quot;:&quot;%h&quot;,&quot;ClientUser&quot;:&quot;%l&quot;,&quot;authenticated&quot;:&quot;%u&quot;,&quot;AccessTime&quot;:&quot;%t&quot;,&quot;method&quot;:&quot;%r&quot;,&quot;status&quot;:&quot;%s&quot;,&quot;SendBytes&quot;:&quot;%b&quot;,&quot;Query?string&quot;:&quot;%q&quot;,&quot;partner&quot;:&quot;%{Referer}i&quot;,&quot;AgentVersion&quot;:&quot;%{User-Agent}i&quot;}"/>

2)重啟tomcat

[root@web01 ~]# /usr/local/tomcat/bin/shutdown.sh
[root@web01 ~]# /usr/local/tomcat/bin/startup.sh

3)配置收集新的tomcat日志

[root@web01 ~]# vim /etc/logstash/conf.d/tomcat_json_es.conf
input {
  file {
    path => "/usr/local/tomcat/logs/tomcat_access_json.*.log"
    start_position => "beginning"
  }
}
output {
  elasticsearch {
    hosts => ["10.0.0.51:9200"]
    index => "tomcat_json_%{+YYYY-MM-dd}.log"
  }
}

2.方法二:使用mutiline模塊收集日志

1)配置收集日志測試

[root@web01 ~]# vim /etc/logstash/conf.d/test_mutiline.conf
input {
  stdin {
    codec => multiline {
	  #以[開頭
      pattern => "^\["
      #匹配到
      negate => true
      #向上合並,向下合並是next
      what => "previous"
    }
  }
}
output {
  stdout {
    codec => json
  }
}

#測試,輸入內容不會直接輸出,當遇到以 [ 開頭才會收集以上的日志

2)配置收集tomcat錯誤日志

[root@web01 ~]# vim /etc/logstash/conf.d/tomcat_mutiline.conf 
input {
  file {
    path => "/usr/local/tomcat/logs/tomcat_access_json.*.log"
    start_position => "beginning"
    codec => multiline {
      pattern => "^\["
      negate => true
      what => "previous"
    }
  }
}

output {
  elasticsearch {
    hosts => ["10.0.0.51:9200"]
    index => "tomcat_json_%{+YYYY-MM-dd}"
    codec => "json"
  }
}

3)將錯誤日志寫入

[root@web01 ~]# cat 1.txt >> /usr/local/tomcat/logs/tomcat_access_json.2020-08-14.log

4)頁面查看數據


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM