{"id":40996,"date":"2023-07-30T21:53:51","date_gmt":"2023-06-03T19:55:52","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/"},"modified":"2024-04-30T16:09:17","modified_gmt":"2024-04-30T08:09:17","slug":"%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/","title":{"rendered":"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808]"},"content":{"rendered":"<h2>\u9996\u5148<\/h2>\n<p>\u5728\u4e0a\u4e00\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u4f7f\u7528fluentd\u6355\u6349\u4e86\u4f4d\u4e8e\u5c40\u57df\u7f51\u5185\u7684\u6811\u8393\u6d3e\u53d1\u9001\u7684syslog\u548cHTTP\u901a\u4fe1\u3002<\/p>\n<p>\u91cd\u70b9\u5728\u4e8e\u4f7f\u7528Docker\u5bb9\u5668\u521b\u5efa\u4e86fluentd\u3002\u4e3a\u4e86\u5c06syslog\u548chttp\u901a\u4fe1\u53d1\u9001\u5230Windows\u673a\u5668\u5185\u7684Docker\u5bb9\u5668\uff0c\u9700\u8981\u8fdb\u884cWindows\u673a\u5668\u7684\u7aef\u53e3\u8f6c\u53d1\u8bbe\u7f6e\u3002<\/p>\n<h3>This article is about.<\/h3>\n<p>\u4f5c\u4e3a\u524d\u4e00\u4e2a\u4f1a\u8bdd\u7684\u5ef6\u7eed\uff0c\u5c06\u7531fluentd\u6355\u83b7\u7684\u6570\u636e\u4e0eElasticsearch\u548cKibana\u8fdb\u884c\u534f\u4f5c\uff0c<br \/>\n\u5728Kibana\u4e0a\u6d4f\u89c8\u4ece\u5c40\u57df\u7f51\u4e2d\u6811\u8393\u6d3e\u53d1\u9001\u7684syslog\u5185\u5bb9\u3002<\/p>\n<p>\u901a\u8fc7\u4f7f\u7528Kibana\uff0cFluentd\u53ef\u4ee5\u5c06syslog\u7684\u5185\u5bb9\u4ee5\u56fe\u5f62\u5316\u3001\u6613\u4e8e\u4eba\u4eec\u9605\u8bfb\u7684\u5f62\u5f0f\u5448\u73b0\uff0c\u800c\u4e0d\u4ec5\u4ec5\u662f\u7b80\u5355\u5730\u4ee5\u6587\u672c\u5f62\u5f0f\u6d41\u52a8\u5728\u5c4f\u5e55\u4e0a\u3002<\/p>\n<h2>\u6811\u8393\u6d3e\u7684syslog\u8bbe\u7f6e<\/h2>\n<p>\u5728\u6811\u8393\u6d3e\u7684syslog\u914d\u7f6e\u4e2d\uff0c\u5df2\u7ecf\u5c06\u65e5\u5fd7\u8bbe\u7f6e\u4e3a\u901a\u8fc7TCP\u901a\u4fe1\u53d1\u9001\u81f3Windows\u673a\u5668\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>vim \/etc\/rsyslog.conf\r\n<\/code><\/pre>\n<p>Docker\u7684flunetd\u66b4\u9732\u4e865140\u7aef\u53e3\uff0c\u56e0\u6b64\u9700\u8981\u6307\u5b9a5140\u7aef\u53e3\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/10-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u6811\u8393\u6d3e\u7684\u8bbe\u7f6e\u5c31\u662f\u4ee5\u4e0a\u5185\u5bb9\u3002<\/p>\n<h2>Docker Compose\u6587\u4ef6<\/h2>\n<p>\u91cd\u70b9\u662f\u8bbe\u5b9a\u65f6\u533a\u3002<br \/>\n\u5373\u4f7f\u6811\u8393\u6d3e\u7684\u65f6\u95f4\u51c6\u786e\u65e0\u8bef\uff0c\u5982\u679cfluentd\u7684\u65f6\u95f4\u662f\u6807\u51c6\u65f6\u95f4\uff0c<br \/>\n\u90a3\u4e48\u6811\u8393\u6d3e\u7684\u65e5\u5fd7\u5728fluentd\u770b\u6765\u5c06\u6210\u4e3a\u672a\u6765\u4e8b\u4ef6\uff0c<br \/>\n\u5bfc\u81f4Kibana\u65e0\u6cd5\u663e\u793a\u65e5\u5fd7\uff08\u53ef\u80fd\u662f9\u5c0f\u65f6\u4e4b\u540e\u624d\u80fd\u663e\u793a\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">3\"<\/span>\r\n<span class=\"na\">services<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">fluentd<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">build<\/span><span class=\"pi\">:<\/span> <span class=\"s\">.\/fluentd<\/span>\r\n    <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">.\/fluentd\/conf:\/fluentd\/etc<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">24224:24224\"<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">24224:24224\/udp\"<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">5140:5140\"<\/span>\r\n    <span class=\"na\">networks<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">efk-net<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">ipv4_address<\/span><span class=\"pi\">:<\/span> <span class=\"s\">172.22.0.10<\/span>\r\n    <span class=\"na\">environment<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">TZ<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Asia\/Tokyo<\/span>\r\n  \r\n  <span class=\"na\">web<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">nginx:alpine-slim<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">8000:80<\/span>\r\n    <span class=\"na\">logging<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">driver<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">fluentd\"<\/span>\r\n      <span class=\"na\">options<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">fluentd-address<\/span><span class=\"pi\">:<\/span> <span class=\"s\">172.22.0.10:24224<\/span>\r\n        <span class=\"na\">fluentd-async-connect<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">true\"<\/span>\r\n        <span class=\"na\">fluentd-retry-wait<\/span><span class=\"pi\">:<\/span> <span class=\"s\">2s<\/span>\r\n        <span class=\"na\">fluentd-max-retries<\/span><span class=\"pi\">:<\/span> <span class=\"m\">30<\/span>\r\n        <span class=\"na\">tag<\/span><span class=\"pi\">:<\/span> <span class=\"s\">httpd.access<\/span>\r\n    <span class=\"na\">networks<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">efk-net<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">ipv4_address<\/span><span class=\"pi\">:<\/span> <span class=\"s\">172.22.0.20<\/span>\r\n    <span class=\"na\">depends_on<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">fluentd<\/span>\r\n    <span class=\"na\">environment<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">TZ<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Asia\/Tokyo<\/span>\r\n\r\n  <span class=\"na\">elasticsearch<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">docker.elastic.co\/elasticsearch\/elasticsearch:8.1.2<\/span>\r\n    <span class=\"na\">container_name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">elasticsearch<\/span>\r\n    <span class=\"na\">environment<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">discovery.type=single-node\"<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">xpack.security.enabled=false<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">TZ=Asia\/Tokyo\"<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">9200:9200\"<\/span>\r\n    <span class=\"na\">networks<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">efk-net<\/span>\r\n\r\n  <span class=\"na\">kibana<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">docker.elastic.co\/kibana\/kibana:8.1.2<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">5601:5601\"<\/span>\r\n    <span class=\"na\">networks<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">efk-net<\/span>\r\n    <span class=\"na\">environment<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">TZ=Asia\/Tokyo\"<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">i18n.locale=ja-JP<\/span>\r\n\r\n<span class=\"na\">networks<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">efk-net<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">driver<\/span><span class=\"pi\">:<\/span> <span class=\"s\">bridge<\/span>\r\n    <span class=\"na\">ipam<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">driver<\/span><span class=\"pi\">:<\/span> <span class=\"s\">default<\/span>\r\n      <span class=\"na\">config<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">subnet<\/span><span class=\"pi\">:<\/span> <span class=\"s\">172.22.0.0\/16<\/span>\r\n<\/code><\/pre>\n<p>\u53e6\u5916\uff0c\u7531\u4e8eWeb\u5bb9\u5668\u662f\u4e0a\u4e00\u6b21\u7684\u9057\u7559\u7269\uff0c\u6240\u4ee5\u5373\u4f7f\u6ca1\u6709\u5b83\u4e5f\u53ef\u4ee5\u8fd0\u884c\u3002<\/p>\n<h2>\u6d41\u5229\u7684.conf<\/h2>\n<p>syslog\u7684\u9ed8\u8ba4\u534f\u8bae\u662fUDP\uff0c\u56e0\u6b64\u9700\u8981\u6307\u5b9a\u534f\u8bae\u7c7b\u578b\u4e3aTCP\uff08protocol_type tcp\uff09\u3002<\/p>\n<p>logstash_prefix \u5c06\u6210\u4e3a Kibana \u7aef\u7684\u7d22\u5f15<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30e9\u30ba\u30d1\u30a4\u304b\u3089\u306esyslog\u306fmysyslog\u304b\u3089\u59cb\u307e\u308b\u30a4\u30f3\u30c7\u30c3\u30af\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Docker\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306eweb\u30b3\u30f3\u30c6\u30ca\u304b\u3089\u306e\u30ed\u30b0\u306ffluentd\u304b\u3089\u59cb\u307e\u308b\u30a4\u30f3\u30c7\u30c3\u30af\u30b9<\/ul>\n<p>\u53ef\u4ee5\u6839\u636e\u4e2a\u4eba\u559c\u597d\u6307\u5b9a\u65e5\u671f\u683c\u5f0f\u3002\u53ea\u9700\u6309\u7167\u4ee5\u4e0b\u65b9\u5f0f\u64cd\u4f5c\uff0c\u65e5\u671f\u548c\u65f6\u95f4\u4e4b\u95f4\u5c06\u4e0d\u4f1a\u51fa\u73b0\u591a\u4f59\u7684\u8fde\u5b57\u7b26\u6216\u5176\u4ed6\u7b26\u53f7\uff0c\u800c\u662f\u4ee5\u8fde\u7eed\u7684\u6570\u5b57\u663e\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nt\">&lt;source&gt;<\/span>\r\n  @type forward\r\n  port 24224\r\n  bind 0.0.0.0\r\n<span class=\"nt\">&lt;\/source&gt;<\/span>\r\n\r\n<span class=\"nt\">&lt;source&gt;<\/span>\r\n  @type syslog\r\n  port 5140\r\n  bind 0.0.0.0\r\n  protocol_type tcp\r\n  tag raspi\r\n\r\n  source_hostname_key true  \r\n<span class=\"nt\">&lt;\/source&gt;<\/span>\r\n\r\n<span class=\"nt\">&lt;match<\/span> <span class=\"err\">raspi.*.**<\/span><span class=\"nt\">&gt;<\/span>\r\n  @type copy\r\n\r\n  <span class=\"nt\">&lt;store&gt;<\/span>\r\n    @type elasticsearch\r\n    host elasticsearch\r\n    port 9200\r\n    logstash_format true\r\n    logstash_prefix mysyslog\r\n    logstash_dateformat %Y%m%d\r\n    flush_interval 1s\r\n  <span class=\"nt\">&lt;\/store&gt;<\/span>\r\n\r\n  <span class=\"nt\">&lt;store&gt;<\/span>\r\n    @type stdout\r\n  <span class=\"nt\">&lt;\/store&gt;<\/span>\r\n<span class=\"nt\">&lt;\/match&gt;<\/span>\r\n\r\n<span class=\"nt\">&lt;match<\/span> <span class=\"err\">httpd.**<\/span><span class=\"nt\">&gt;<\/span>\r\n  @type copy\r\n\r\n  <span class=\"nt\">&lt;store&gt;<\/span>\r\n    @type elasticsearch\r\n    host elasticsearch\r\n    port 9200\r\n    logstash_format true\r\n    logstash_prefix fluentd\r\n    logstash_dateformat %Y%m%d\r\n    include_tag_key true\r\n    type_name access_log\r\n    tag_key @log_name\r\n    flush_interval 1s\r\n  <span class=\"nt\">&lt;\/store&gt;<\/span>\r\n\r\n  <span class=\"nt\">&lt;store&gt;<\/span>\r\n    @type stdout\r\n  <span class=\"nt\">&lt;\/store&gt;<\/span>\r\n<span class=\"nt\">&lt;\/match&gt;<\/span>\r\n<\/code><\/pre>\n<h2>\u542f\u52a8Docker\u5bb9\u5668<\/h2>\n<p>\u540c\u65f6\u542f\u52a8\u5bb9\u5668\u5e76\u5728\u5c4f\u5e55\u4e0a\u663e\u793a\u65e5\u5fd7\u3002<\/p>\n<pre class=\"post-pre\"><code>docker compose up <span class=\"nt\">-d<\/span> <span class=\"o\">&amp;&amp;<\/span> docker compose logs <span class=\"nt\">-f<\/span>\r\n<\/code><\/pre>\n<h3>\u521b\u5efaKibana\u7d22\u5f15<\/h3>\n<p>\u8bbf\u95ee http:\/\/localhost:5601\/app\/management\/kibana\/dataViews<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/27-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u70b9\u51fb&#8221;\u521b\u5efa\u6570\u636e\u89c6\u56fe&#8221;<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/29-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u73b0\u5728\u80fd\u770b\u5230\u4e24\u4e2a\u4ee5fluentd\u5f00\u5934\u7684\u7d22\u5f15\uff0c\u4f46\u662f\u627e\u4e0d\u5230\u4ee5mysyslog\u5f00\u5934\u7684\u7d22\u5f15\u3002<\/p>\n<h4>\u4f7f\u7528\u6811\u8393\u6d3e\u53d1\u9001 syslog<\/h4>\n<p>\u4e3a\u4e86\u901a\u8fc7Fluentd\uff08Elasticsearch\uff1f\uff09\u521b\u5efa\u7d22\u5f15\uff0c\u4ece\u6811\u8393\u6d3e\u53d1\u9001\u4e00\u6b21syslog\u3002<\/p>\n<pre class=\"post-pre\"><code>logger <span class=\"nt\">-p<\/span> local0.info <span class=\"s2\">\"Message from RaspberryPi\"<\/span>\r\n<\/code><\/pre>\n<p>\u5f53\u91cd\u65b0\u52a0\u8f7dKibana\u7f51\u7ad9\u65f6\uff0c\u5c06\u521b\u5efa\u4ee5mysyslog\u5f00\u5934\u7684\u7d22\u5f15\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/35-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u8f93\u5165&#8221;mysyslog-*&#8221;\u6765\u521b\u5efa\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/37-0.png\" alt=\"image.png\" \/><\/div>\n<h2>Kibana\u7684Discover\u529f\u80fd<\/h2>\n<p>\u53ef\u4ee5\u770b\u5230\u4ece\u5c40\u57df\u7f51\u5185\u7684\u6811\u8393\u6d3e\u63a5\u6536\u5230\u7684\u6d88\u606f<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/40-0.png\" alt=\"image.png\" \/><\/div>\n<h3>\u91cd\u65b0\u542f\u52a8\u6811\u8393\u6d3e\u670d\u52a1\u65f6\u7684\u65e5\u5fd7<\/h3>\n<p>\u5c1d\u8bd5\u91cd\u65b0\u542f\u52a8\u6811\u8393\u6d3e\u7684syslog\u670d\u52a1\u3002<\/p>\n<pre class=\"post-pre\"><code>systemctl restart rsyslog.service\r\n<\/code><\/pre>\n<p>\u91cd\u65b0\u52a0\u8f7dKibana<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/45-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u65e5\u5fd7\u5df2\u8bb0\u5f55<\/p>\n<h2>\u603b\u7ed3<\/h2>\n<p>\u5728LAN\u7f51\u7edc\u4e2d\uff0c\u5c06\u6811\u8393\u6d3e\u7684\u7cfb\u7edf\u65e5\u5fd7\u901a\u8fc7Kibana\u53ef\u89c6\u5316\u3002<\/p>\n<p>\u8fd9\u6b21\u53ea\u6709\u4e00\u53f0\u6811\u8393\u6d3e\uff0c\u4f46\u5982\u679c\u6709\u66f4\u591a\u53f0\u7684\u8bdd\uff0c\u770b\u8d77\u6765\u4f1a\u66f4\u6709\u8da3\u3002<\/p>\n<p>\u5f88\u907a\u61be\u7684\u662f\uff0csyslog \u662f\u57fa\u65bcUDP\u5354\u8b70\uff0c\u800cWSL2\u7121\u6cd5\u9032\u884cUDP\u7aef\u53e3\u8f49\u767c&#8230;\u6211\u5e0c\u671b\u9019\u500b\u554f\u984c\u80fd\u76e1\u5feb\u5f97\u5230\u6539\u5584\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2>\u51ac\u5929\u5230\u4e86\uff01\uff01<\/h2>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u5728\u4e0a\u4e00\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u4f7f\u7528fluentd\u6355\u6349\u4e86\u4f4d\u4e8e\u5c40\u57df\u7f51\u5185\u7684\u6811\u8393\u6d3e\u53d1\u9001\u7684syslog\u548cHTTP\u901a\u4fe1\u3002 \u91cd\u70b9 [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-40996","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808] - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5728kibana\u4e0a\u67e5\u770braspberry-pi\u7684syslog\u65e5\u5fd7-\u4f7f\u7528efk\u5806\u6808\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808]\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u5728\u4e0a\u4e00\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u4f7f\u7528fluentd\u6355\u6349\u4e86\u4f4d\u4e8e\u5c40\u57df\u7f51\u5185\u7684\u6811\u8393\u6d3e\u53d1\u9001\u7684syslog\u548cHTTP\u901a\u4fe1\u3002 \u91cd\u70b9 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5728kibana\u4e0a\u67e5\u770braspberry-pi\u7684syslog\u65e5\u5fd7-\u4f7f\u7528efk\u5806\u6808\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-03T19:55:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T08:09:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/10-0.png\" \/>\n<meta name=\"author\" content=\"\u97f5, \u79d1\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u97f5, \u79d1\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/\",\"name\":\"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808] - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-06-03T19:55:52+00:00\",\"dateModified\":\"2024-04-30T08:09:17+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808]\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\",\"name\":\"\u97f5, \u79d1\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"caption\":\"\u97f5, \u79d1\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808] - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u5728kibana\u4e0a\u67e5\u770braspberry-pi\u7684syslog\u65e5\u5fd7-\u4f7f\u7528efk\u5806\u6808\/","og_locale":"zh_CN","og_type":"article","og_title":"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808]","og_description":"\u9996\u5148 \u5728\u4e0a\u4e00\u7bc7\u6587\u7ae0\u4e2d\uff0c\u6211\u4eec\u4f7f\u7528fluentd\u6355\u6349\u4e86\u4f4d\u4e8e\u5c40\u57df\u7f51\u5185\u7684\u6811\u8393\u6d3e\u53d1\u9001\u7684syslog\u548cHTTP\u901a\u4fe1\u3002 \u91cd\u70b9 [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u5728kibana\u4e0a\u67e5\u770braspberry-pi\u7684syslog\u65e5\u5fd7-\u4f7f\u7528efk\u5806\u6808\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-06-03T19:55:52+00:00","article_modified_time":"2024-04-30T08:09:17+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442437434c4406c9e4eb\/10-0.png"}],"author":"\u97f5, \u79d1","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u97f5, \u79d1","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"2 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/","name":"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808] - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-06-03T19:55:52+00:00","dateModified":"2024-04-30T08:09:17+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u5728[Kibana]\u4e0a\u67e5\u770b[Raspberry Pi]\u7684syslog\u65e5\u5fd7 [\u4f7f\u7528EFK\u5806\u6808]"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e","name":"\u97f5, \u79d1","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","caption":"\u97f5, \u79d1"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8braspberry-pi%e7%9a%84syslog%e6%97%a5%e5%bf%97-%e4%bd%bf%e7%94%a8efk%e5%a0%86%e6%a0%88\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=40996"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40996\/revisions"}],"predecessor-version":[{"id":92917,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40996\/revisions\/92917"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=40996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=40996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=40996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}