Logstash 는 입력 → 필터 → 출력 파이프라인으로 로그를 모아 변환해 보내는 도구다. 현행은 Elasticsearch 와 같은 9.5.4 이고 JDK 가 내장돼 있다. 아래 절차는 2021년 7.x 에서 테스트한 것을 9.x 저장소로 바꾼 것이다. 파이프라인 문법은 같다.
Elasticsearch 9 는 TLS · 인증이 기본이라 elasticsearch 출력에 user · password · ssl_certificate_authorities 를 넣어야 한다.
$ sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
# .repo 파일 새로 생성
$ cd /etc/yum.repos.d/
$ sudo vi logstash.repo
logstash.repo
[logstash-9.x]
name=Elastic repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
$ sudo yum install logstash
# Logstash home : /usr/share/logstash
# Logstash bin : /usr/share/logstash/bin
# Logstash log : /var/log/logstash
# Logstash settings (logstash.yml, jvm.options, startup.options 등) : /etc/logstash
# Logstash pipeline config : /etc/logstash/conf.d/
Logstash pipeline
┌────────────┐ ┌────────────┐ ┌────────────┐
│ input │ ──▶ │ filter │ ──▶ │ output │
└────────────┘ └────────────┘ └────────────┘
file · beats grok · mutate elasticsearch
syslog · kafka date · drop stdout · kafka
stdin · http geoip file · s3
(생략 가능)
Logstash는 위의 그림과 같이 input, output 요소를 필요로하며, 필요하다면 filter 요소를 추가구성한다. input은 데이터를 받아오고, filter는 우리가 설정한대로 데이터를 재구성하며, output은 목적지로 데이터를 보낸다.
Logstash가 정상적으로 설치되었는지 확인하기 위해 기본적인 파이프라인을 이용한 메세지를 날려본다.
$ cd /usr/share/logstash/bin
$ ./logstash -e 'input { stdin { } } output { stdout {} }'
# ./logstash 실행시 권한 문제가 있을 수 있음
# 임시로 sudo chmod -R 777 /usr/share/logstash/data 로 해결함
# The stdin plugin is now waiting for input:
# [INFO ] 2021-01-06 15:38:49.148 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
# [INFO ] 2021-01-06 15:38:49.282 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=>9600}
# 이라는 문구가 뜨면, hello world를 입력하고 엔터를 누른다.
# 결과
{
"@version" => "1",
"host" => "pji-03",
"message" => "hello world",
"@timestamp" => 2021-01-06T06:41:00.974Z
}
# ctrl+D를 눌러 Logstash 종료
# 사전 준비 : log file을 준비한다.
$ cd /home/pji/kafka/logdata/pgServer.public.test_table-0
$ wget https://download.elastic.co/demos/logstash/gettingstarted/logstash-tutorial.log.gz
$ gzip -d logstash-tutorial.log.gz
# Logstash에 log파일을 보내기 위해선 filebeat가 필요하다.
# Filebeat는 데이타를 읽어올 서버에 설치한다. (예: Kafka가 설치된 서버)
$ sudo rpm --import https://packages.elastic.co/GPG-KEY-elasticsearch
$ cd /etc/yum.repos.d/
$ sudo vi elastic.repo
elastic.repo
[elastic-9.x]
name=Elastic repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
$ sudo yum install filebeat
$ sudo systemctl enable filebeat
# Filebeat home : /usr/share/filebeat
# Filebeat bin : /usr/share/filebeat/bin
# Filebeat config : /etc/filebeat
# Filebeat log : /var/log/filebeat
$ cd /etc/filebeat
$ sudo vi filebeat.yml
filebeat.yml
filebeat.inputs:
- type: log
paths:
- /home/pji/kafka/logdata/pgServer.public.test_table-0/*.log => 읽어오려는 log 파일이 있는 디렉토리 주소를 넣는다.
# output.elasticsearsh:
# hosts: ["$Logstash_Server_IP:9200"]
output.logstash:
hosts: ["$Logstash_Server_IP:5044"] => Logstash가 설치된 서버의 IP 주소를 넣는다.
$ cd /usr/share/filebeat/bin
$ sudo ./filebeat -e -c /etc/filebeat/filebeat.yml -d "publish"
# 다시 Logstash를 설치한 서버로 돌아와서, Pipeline config 파일을 새로 작성한다.
$ cd /etc/logstash/conf.d
$ sudo vi first-pipeline.conf
pipeline config 파일을 구성하는 기본 골자는 다음과 같다.
# The # character at the beginning of a line indicates a comment. Use
# comments to describe your configuration.
input {
}
# The filter part of this file is commented out to indicate that it is
# optional.
# filter {
#
# }
output {
}
first-pipeline.conf
# The # character at the beginning of a line indicates a comment. Use
# comments to describe your configuration.
input {
beats {
port => "5044"
}
}
# The filter part of this file is commented out to indicate that it is
# optional.
# filter {
#
# }
output {
stdout { ==> 아직 logstash에서 다른 곳으로 보내지 않을 것이기 때문에 바로 출력을 위한 stdout을 입력
codec => rubydebug
}
}
# 파이프라인에 오류가 없는지 테스트해본다.
# --config.test_and_exit 은 config 파일을 파싱하여 오류를 알려주는 옵션이다.
$ cd /usr/share/logstash/bin
$ ./logstash -f /etc/logstash/conf.d/first-pipeline.conf --config.test_and_exit
# 오류가 검출되지 않았다면, logstash를 다음과 같이 실행한다.
# --config.reload.automatic 은 config 파일을 수정할때마다 자동으로 Logstash를 stop - restart 해주는 옵션이다.
$ ./logstash -f /etc/logstash/conf.d/first-pipeline.conf --config.reload.automatic
$ cd /etc/logstash/conf.d
$ sudo vi first-pipeline.conf
first-pipline.conf
# The # character at the beginning of a line indicates a comment. Use
# comments to describe your configuration.
input {
beats {
port => "5044"
}
}
# The filter part of this file is commented out to indicate that it is
# optional.
# filter {
#
# }
output {
elasticsearch {
hosts => ["https://192.168.113.138:9200"]
user => "elastic"
password => "${ELASTIC_PASSWORD}"
ssl_certificate_authorities => ["/etc/logstash/http_ca.crt"]
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
}
stdout {} ==> 로그에 찍히는지 확인하기 위한 용도의 출력
}
# 파이프라인에 오류가 없는지 테스트해본다.
$ cd /usr/share/logstash/bin
$ ./logstash -f /etc/logstash/conf.d/first-pipeline.conf --config.test_and_exit
# 오류가 검출되지 않았다면, logstash를 다음과 같이 실행한다.
$ ./logstash -f /etc/logstash/conf.d/first-pipeline.conf --config.reload.automatic