Labor 2: Keskne logiserver: Difference between revisions

From ICO wiki
Jump to navigationJump to search
Kvainast (talk | contribs)
No edit summary
Kvainast (talk | contribs)
Line 36: Line 36:
mv logstash-1.1.12-flatjar.jar /etc/logstash/logstash.jar</source>
mv logstash-1.1.12-flatjar.jar /etc/logstash/logstash.jar</source>


...
Loon Logstashi konfifaili logstash.conf ning asukoht on /etc/logstash
 
Konfifaili sisu:
 
<source lang="bash">
 
input {
        #Windowsi logid
        tcp {
                type => "eventlog"
                port => 10515
        }
     
        #Logiserveri enda logid
        file {
                type => "logserver"
                path => [ "/var/log/syslog", "/var/log/*.log" ]
        }
}
output {
        #Saadetakse andmebaasi
        elasticsearch {
        }
}
 
</source>
 
Kasutajad!
 
 
 
=='''Elasticsearch'''==
 
Paigaldame Elasticsearch'i
 
<source lang="bash">
wget https://download.elasticsearch.org/elasticsearch/elasticsearch/elasticsearch-0.90.0.deb
dpkg -i elasticsearch-0.90.0.deb
rm elasticsearch-0.90.0.deb</source>

Revision as of 14:19, 16 January 2014

Ülesande püstitus

Keskse logiserveri paigaldus

Serveri ja kliendi seadistus

Server: Ubuntu Server 12.04 (32bit) (Võib kasutada teisi versioone)

Serveri ip muutsime 192.168.56.201 (Kasutaja võib endale sobiva ip panna)


Logstash´i paigaldamine ja seadistamine

Kõik käsud tuleb sisestada root kasutaja õigustes.


Openjdk paigaldus:

apt-get install openjdk-7-jre

Logstashi kausta loomine:

mkdir /etc/logstash

Logstashi allalaadimine:

wget https://logstash.objects.dreamhost.com/release/logstash-1.1.12-flatjar.jar

Allalaaditud faili tõstmine Logstash´i jaoks loodud kausta:

mv logstash-1.1.12-flatjar.jar /etc/logstash/logstash.jar

Loon Logstashi konfifaili logstash.conf ning asukoht on /etc/logstash

Konfifaili sisu:

input {
        #Windowsi logid
        tcp {
                type => "eventlog"
                port => 10515
        }
       
        #Logiserveri enda logid
        file {
                type => "logserver"
                path => [ "/var/log/syslog", "/var/log/*.log" ]
        }
}
 
output {
        #Saadetakse andmebaasi
        elasticsearch {
        }
}

Kasutajad!


Elasticsearch

Paigaldame Elasticsearch'i

wget https://download.elasticsearch.org/elasticsearch/elasticsearch/elasticsearch-0.90.0.deb
dpkg -i elasticsearch-0.90.0.deb
rm elasticsearch-0.90.0.deb