{"id":41300,"date":"2023-08-23T10:53:14","date_gmt":"2023-12-04T14:24:27","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/"},"modified":"2024-04-30T19:45:38","modified_gmt":"2024-04-30T11:45:38","slug":"%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/","title":{"rendered":"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316"},"content":{"rendered":"<h1>\u7ec4\u6210<\/h1>\n<p>\u30aa\u30f3\u30d7\u30ec\u5074<br \/>\n\u30c6\u30b9\u30c8\u7528\u30b5\u30fc\u30d02\u53f0\u3068Cisco\u30b9\u30a4\u30c3\u30c1\u3092\u7528\u610f\u3002\u5404\u6a5f\u5668\u306e\u30ed\u30b0\u306fSyslog\u30b5\u30fc\u30d0\u306b\u8ee2\u9001\u3059\u308b\u3002<br \/>\nSyslog\u30b5\u30fc\u30d0\u306e\u30ed\u30b0\u3092Logstash\u3067ETL\u51e6\u7406\u3057Elasticsearch\u306b\u4fdd\u5b58\u3059\u308b\u3002<br \/>\n\u6700\u5f8c\u306bKibana\u3067\u5404\u7a2e\u8a2d\u5b9a\u3084\u30b0\u30e9\u30d5\u4f5c\u6210\u3092\u3059\u308b\u3002<\/p>\n<p>AWS\u5074<br \/>\nCloudTrail\u3001VPC Flowlogs\u3092Cloudwatch\u306b\u9001\u4fe1\u3059\u308b\u3002<br \/>\nLogstash\u304b\u3089Cloudwatch\u306e\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u3092\u6307\u5b9a\u3057\u3066\u30ed\u30b0\u3092\u53d6\u308a\u306b\u884c\u304f\u3002<br \/>\nKibana\u3067\u5404\u7a2e\u8a2d\u5b9a\u3084\u30b0\u30e9\u30d5\u3092\u4f5c\u6210\u3059\u308b\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/2-0.png\" alt=\"ES2-1.png\" \/><\/div>\n<h1>\u7ed3\u675f\u540e<\/h1>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/4-1.png\" alt=\"ES2.png\" \/><\/div>\n<h1>\u73af\u5883\u548c\u524d\u63d0\u6761\u4ef6<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">AlmaLinux release 8.5 (Arctic Sphynx)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u4e0b\u8a18\u306e\u8a2d\u5b9a\u306f\u8a2d\u5b9a\u6e08\u307f<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">CloudTrail,VPCFlowlogs,CloudWatch\u306e\u8a2d\u5b9a<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Logstash\u304b\u3089CloudWatch\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308bIAM\u30e6\u30fc\u30b6\u306e\u4f5c\u6210\u53ca\u3073IAM\u30ed\u30fc\u30eb\u306e\u8a2d\u5b9a<\/ul>\n<h1>\u8bf7\u63d0\u4f9b\u5177\u4f53\u7684\u53e5\u5b50\u6216\u5185\u5bb9\uff0c\u6211\u5c06\u4e3a\u60a8\u63d0\u4f9b\u4e2d\u6587\u7684\u540c\u4e49\u8f6c\u8ff0\u3002<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Logstash\u306efilter\u7b87\u6240\u306e\u8a18\u8f09\u65b9\u6cd5\uff08CloudTrail\u3001VPCFlowlogs\uff09\u306f\u4e0b\u8a18\u30b5\u30a4\u30c8\u3092\u53c2\u8003\u306b\u3055\u305b\u3066\u9802\u304d\u307e\u3057\u305f\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">VPC FlowLogs\u3092Logstash\u3067\u6b63\u898f\u5316\u3057\u3066\u307f\u305f<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">CloudTrail\u3092Elasticsearch\u306b\u53d6\u308a\u8fbc\u3093\u3067\u307f\u305f<\/ul>\n<h1>\u5efa\u7acb\u6b65\u9a5f\uff08On-premise\u7aef\u7684\u65e5\u8a8c\u6536\u96c6\uff09<\/h1>\n<h2>\u642d\u5efaElasticsearch\u670d\u52a1\u5668<\/h2>\n<ul class=\"post-ul\">Elasticsearch\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/ul>\n<pre class=\"post-pre\"><code>wget https:\/\/artifacts.elastic.co\/downloads\/elasticsearch\/elasticsearch-7.10.1-x86_64.rpm\r\nrpm <span class=\"nt\">--install<\/span> elasticsearch-7.10.1-x86_64.rpm\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Elasticsearch\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code>vim elasticsearch.yml\r\nnetwork.host: 0.0.0.0\r\nnode.name: node-1\r\ncluster.initial_master_nodes: <span class=\"o\">[<\/span><span class=\"s2\">\"node-1\"<\/span><span class=\"o\">]<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">vm.max_map_count\u30d1\u30e9\u30e1\u30fc\u30bf\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code>vm.max_map_count<span class=\"o\">=<\/span>262144\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>sysctl <span class=\"nt\">-q<\/span> <span class=\"nt\">-w<\/span>  vm.max_map_count<span class=\"o\">=<\/span>262144\r\nsystemctl <span class=\"nb\">enable <\/span>elasticsearch\r\nsystemctl start elasticsearch\r\n<\/code><\/pre>\n<p>\u5c06Kibana\u4e5f\u5b89\u88c5\u5728\u540c\u4e00\u53f0\u670d\u52a1\u5668\u4e0a\u3002<\/p>\n<ul class=\"post-ul\">Kibana\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/ul>\n<pre class=\"post-pre\"><code>wget https:\/\/artifacts.elastic.co\/downloads\/kibana\/kibana-7.10.1-x86_64.rpm\r\nrpm <span class=\"nt\">--install<\/span> kibana-7.10.1-x86_64.rpm\r\n\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Kibana\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code>server.host: <span class=\"s2\">\"0.0.0.0\"<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Kibana\u8d77\u52d5<\/ul>\n<pre class=\"post-pre\"><code>systemctl <span class=\"nb\">enable <\/span>kibana\r\nsystemctl start kibana\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Kibana\u52d5\u4f5c\u78ba\u8a8d<\/ul>\n<p>\u8bbf\u95ee http:\/\/xx.xx.xx.xx:5601\/<\/p>\n<h2>\u642d\u5efaLogstash\u670d\u52a1\u5668<\/h2>\n<ul class=\"post-ul\">OpenJDK\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/ul>\n<pre class=\"post-pre\"><code>yum <span class=\"nt\">-y<\/span> <span class=\"nb\">install <\/span>java-1.8.0-openjdk\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Logstash\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/ul>\n<pre class=\"post-pre\"><code>rpm <span class=\"nt\">--import<\/span> https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"o\">[<\/span>logstash-7.x]\r\n<span class=\"nv\">name<\/span><span class=\"o\">=<\/span>Elastic repository <span class=\"k\">for <\/span>7.x packages\r\n<span class=\"nv\">baseurl<\/span><span class=\"o\">=<\/span>https:\/\/artifacts.elastic.co\/packages\/7.x\/yum\r\n<span class=\"nv\">gpgcheck<\/span><span class=\"o\">=<\/span>1\r\n<span class=\"nv\">gpgkey<\/span><span class=\"o\">=<\/span>https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch\r\n<span class=\"nv\">enabled<\/span><span class=\"o\">=<\/span>1\r\n<span class=\"nv\">autorefresh<\/span><span class=\"o\">=<\/span>1\r\n<span class=\"nb\">type<\/span><span class=\"o\">=<\/span>rpm-md\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>yum <span class=\"nt\">-y<\/span> <span class=\"nb\">install <\/span>logstash-7.10.1\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Logstash\u8d77\u52d5<\/ul>\n<pre class=\"post-pre\"><code>systemctl <span class=\"nb\">enable <\/span>logstash\r\nsystemctl restart logstash\r\n<\/code><\/pre>\n<h2>\u5efa\u7acbSyslog\u670d\u52a1\u5668<\/h2>\n<ul class=\"post-ul\">Syslog\u8a2d\u5b9a<\/ul>\n<p>\u4f7f\u7528IP\u5730\u5740\u5c06\u65e5\u5fd7\u6587\u4ef6\u5206\u79bb\u7684\u8bbe\u7f6e<\/p>\n<pre class=\"post-pre\"><code>module<span class=\"o\">(<\/span><span class=\"nv\">load<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"imudp\"<\/span><span class=\"o\">)<\/span> <span class=\"c\"># needs to be done just once<\/span>\r\ninput<span class=\"o\">(<\/span><span class=\"nb\">type<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"imudp\"<\/span> <span class=\"nv\">port<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"514\"<\/span><span class=\"o\">)<\/span>\r\n\r\nmodule<span class=\"o\">(<\/span><span class=\"nv\">load<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"imtcp\"<\/span><span class=\"o\">)<\/span> <span class=\"c\"># needs to be done just once<\/span>\r\ninput<span class=\"o\">(<\/span><span class=\"nb\">type<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"imtcp\"<\/span> <span class=\"nv\">port<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"514\"<\/span><span class=\"o\">)<\/span>\r\n\r\n<span class=\"c\">#### RULES ####<\/span>\r\n:fromhost-ip, isequal, <span class=\"s2\">\"xxx.xxx.xxx.xxx\"<\/span> -\/var\/log\/server\/pst.log\r\n&amp; ~\r\n:fromhost-ip, isequal, <span class=\"s2\">\"xxx.xxx.xxx.xxx\"<\/span> -\/var\/log\/server\/redmine.log\r\n&amp; ~\r\n:fromhost-ip, isequal, <span class=\"s2\">\"xxx.xxx.xxx.xxx\"<\/span> -\/var\/log\/server\/ciscosw.log\r\n&amp; ~\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>\/var\/log\/server\/<span class=\"k\">*<\/span>.log <span class=\"o\">{<\/span>\r\nweekly\r\nrotate 54\r\ncompress\r\ncreate 0664 root root\r\npostrotate\r\n\/bin\/systemctl restart rsyslog\r\nendscript\r\n<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>systemctl restart rsyslog\r\n<\/code><\/pre>\n<h2>Syslog\u8f6c\u53d1\u7aef\u8bbe\u7f6e<\/h2>\n<ul class=\"post-ul\">\u30b5\u30fc\u30d0\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code><span class=\"k\">*<\/span>.<span class=\"k\">*<\/span> @@xxx.xxx.xxx.xxx:514\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>systemctl restart rsyslog\r\n<\/code><\/pre>\n<ul class=\"post-ul\">\u30b9\u30a4\u30c3\u30c1\u8a2d\u5b9a<\/ul>\n<p>\u4e3a\u4e86\u6d4b\u8bd5\u76ee\u7684\uff0c\u5728\u8c03\u8bd5\u4e2d\u8bbe\u7f6e\u7ea7\u522b\u3002<\/p>\n<pre class=\"post-pre\"><code>logging host xxx.xxx.xxx.xxx\r\nlogging <span class=\"nb\">trap <\/span>debugging\r\n<\/code><\/pre>\n<h2>NFS\u914d\u7f6e<\/h2>\n<p>\u4f7fLogstash\u670d\u52a1\u5668\u80fd\u591f\u770b\u5230Syslog\u670d\u52a1\u5668\u3002<\/p>\n<ul class=\"post-ul\">Syslog\u30b5\u30fc\u30d0\u5074\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code>yum <span class=\"nt\">-y<\/span> <span class=\"nb\">install <\/span>nfs-utils\r\nsystemctl <span class=\"nb\">enable <\/span>nfs-server\r\nsystemctl start nfs-server\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>\/var\/log xxx.xxx.xxx.xxx\/xx<span class=\"o\">(<\/span>rw,no_root_squash<span class=\"o\">)<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Logstash\u30b5\u30fc\u30d0\u5074\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code>yum <span class=\"nt\">-y<\/span> <span class=\"nb\">install <\/span>nfs-utils\r\nsystemctl <span class=\"nb\">enable <\/span>nfs-server\r\nsystemctl start nfs-server\r\nmount <span class=\"nt\">-t<\/span> nfs xxx.xxx.xxx.xxx:\/var\/log \/mnt\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>xxx.xxx.xxx.xxx:\/var\/log \/mnt               nfs     defaults        0 0\r\n<\/code><\/pre>\n<h2>Logstash\u914d\u7f6e<\/h2>\n<p>\u53c2\u8003\u8d44\u6599\uff1alogstash\u6a21\u5f0f<\/p>\n<ul class=\"post-ul\">Conf\u30d5\u30a1\u30a4\u30eb\u4f5c\u6210<\/ul>\n<pre class=\"post-pre\"><code>input <span class=\"o\">{<\/span>\r\n     file <span class=\"o\">{<\/span>\r\n        path <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"\/mnt\/server\/redmine.log\"<\/span>\r\n        path <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"\/mnt\/server\/pst.log\"<\/span>\r\n        path <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"\/mnt\/server\/ciscosw.log\"<\/span>\r\n        start_position <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"beginning\"<\/span>\r\n     <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\nfilter <span class=\"o\">{<\/span>\r\n    grok <span class=\"o\">{<\/span>\r\n      match <span class=\"o\">=&gt;<\/span> <span class=\"o\">{<\/span>\r\n        <span class=\"s2\">\"message\"<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"%{SYSLOGBASE}%{SPACE}%{GREEDYDATA:SYSLOGMESSAGE}\"<\/span>\r\n      <span class=\"o\">}<\/span>\r\n    <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\noutput <span class=\"o\">{<\/span>\r\n     elasticsearch <span class=\"o\">{<\/span>\r\n         hosts <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span><span class=\"s2\">\"xxx.xxx.xxx.xxx:9200\"<\/span><span class=\"o\">]<\/span>\r\n         index <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"syslog-%{+YYYY-MM-dd}\"<\/span>\r\n     <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Logstash\u518d\u8d77\u52d5<\/ul>\n<pre class=\"post-pre\"><code>systemctl restart logstash\r\n<\/code><\/pre>\n<h2>Kibana\u914d\u7f6e<\/h2>\n<ul class=\"post-ul\">Develper Tool\u306e\u753b\u9762\u306b\u30a2\u30af\u30bb\u30b9<\/ul>\n<p>\u8bf7\u7528\u4e2d\u6587\u5c06\u4ee5\u4e0b\u5185\u5bb9\u8fdb\u884c\u6539\u8ff0\uff0c\u53ea\u9700\u63d0\u4f9b\u4e00\u79cd\u9009\u9879\uff1a<br \/>\nhttp:\/\/xx.xx.xx.xx:5601\/app\/dev_tools#\/console<\/p>\n<p>\u8fd9\u662f\u63a7\u5236\u53f0\u7684\u7f51\u5740\uff1ahttp:\/\/xx.xx.xx.xx:5601\/app\/dev_tools#\/console\u3002<\/p>\n<ul class=\"post-ul\">Index\u304c\u767b\u9332\u3055\u308c\u3066\u3044\u308b\u304b\u78ba\u8a8d<\/ul>\n<pre class=\"post-pre\"><code>GET \/_cat\/indices?v\r\n\r\nhealth status index                           uuid                   pri rep docs.count docs.deleted store.size pri.store.size\r\nyellow open   syslog-2022-02-21               KfyhDKVjRwGGVk2TWuGD1A   1   1        407            0    145.2kb        145.2kb\r\nyellow open   syslog-2022-02-22               lmZFW50vTveDW2wriHFW_w   1   1        381\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Document\u60c5\u5831\u78ba\u8a8d<\/ul>\n<pre class=\"post-pre\"><code>GET \/syslog-2022-02-<span class=\"k\">*<\/span> \/_search\r\n<span class=\"o\">{<\/span>\r\n  <span class=\"s2\">\"query\"<\/span>: <span class=\"o\">{<\/span> <span class=\"s2\">\"match_all\"<\/span>: <span class=\"o\">{}<\/span> <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Index Patterns\u767b\u9332<\/ul>\n<p>\u6309\u7167\u4ee5\u4e0b\u987a\u5e8f\u9009\u62e9\uff1aStack Management -&gt; Index Patterns<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/72-0.png\" alt=\"kibana1.png\" \/><\/div>\n<p>\u8f93\u5165Syslog-*\u540e\uff0c\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<br \/>\n\u8f93\u5165Syslog-*\u540e\uff0c\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<br \/>\n\u8f93\u5165Syslog-*\u540e\uff0c\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<br \/>\n\u8f93\u5165Syslog-*\u5e76\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<br \/>\n\u5728\u8f93\u5165Syslog-*\u540e\uff0c\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<br \/>\n\u8f93\u5165Syslog-*\u7136\u540e\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/74-0.png\" alt=\"kibana2.png\" \/><\/div>\n<p>\u9009\u62e9\u65f6\u95f4\u6233\u540e\uff0c\u70b9\u51fb&#8221;\u521b\u5efa\u7d22\u5f15\u6a21\u5f0f&#8221;\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/76-0.png\" alt=\"kibana3.png\" \/><\/div>\n<ul class=\"post-ul\">Syslog\u78ba\u8a8d<\/ul>\n<p>\u70b9\u51fb\u201cDiscover\u201d\u6309\u94ae<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/79-0.png\" alt=\"kibana4.png\" \/><\/div>\n<p>\u786e\u8ba4\u662f\u5426\u663e\u793a\u4e86Syslog\u7684\u5185\u5bb9\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/81-0.png\" alt=\"ES3.png\" \/><\/div>\n<ul class=\"post-ul\">\u30b0\u30e9\u30d5\u4f5c\u6210<\/ul>\n<p>\u9009\u62e9Visualize\u540e\uff0c\u521b\u5efa\u559c\u6b22\u7684\u56fe\u8868\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/84-0.png\" alt=\"kibana5.png\" \/><\/div>\n<h1>AWS\u5074\u306e\u30ed\u30b0\u53d6\u8fbc\u307f\u306e\u624b\u9806\u3092\u69cb\u7bc9\u3059\u308b\u3002<\/h1>\n<h2>Logstash\u914d\u7f6e<\/h2>\n<ul class=\"post-ul\">CloudWatch\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/ul>\n<pre class=\"post-pre\"><code>\/usr\/share\/logstash\/bin\/logstash-plugin <span class=\"nb\">install <\/span>logstash-input-cloudwatch_logs\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Flowlogs\u306egrok\u30d1\u30bf\u30fc\u30f3\u4f5c\u6210<\/ul>\n<pre class=\"post-pre\"><code>VPCFLOWLOG %<span class=\"o\">{<\/span>NUMBER:version<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:account-id<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:interface-id<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>IP:srcaddr<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>IP:dstaddr<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:srcport<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:dstport<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:protocol<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NUMBER:packets:float<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NUMBER:bytes:float<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:start<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:end<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:action<span class=\"o\">}<\/span> %<span class=\"o\">{<\/span>NOTSPACE:log-status<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Conf\u30d5\u30a1\u30a4\u30eb\u4f5c\u6210\uff08VPC Flowlogs\uff09<\/ul>\n<pre class=\"post-pre\"><code>input <span class=\"o\">{<\/span>\r\n  cloudwatch_logs <span class=\"o\">{<\/span>\r\n    region <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"ap-northeast-1\"<\/span>\r\n    log_group <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"vpcflowlogs\"<\/span> <span class=\"o\">]<\/span>\r\n    access_key_id <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"xxxxxxxxx\"<\/span>\r\n    secret_access_key <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"xxxxxxxxx\"<\/span>  <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\nfilter <span class=\"o\">{<\/span>\r\n    grok <span class=\"o\">{<\/span>\r\n      patterns_dir <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"\/etc\/logstash\/patterns\/vpcflowlogs_patterns\"<\/span> <span class=\"o\">]<\/span>\r\n      match <span class=\"o\">=&gt;<\/span> <span class=\"o\">{<\/span> <span class=\"s2\">\"message\"<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"%{VPCFLOWLOG}\"<\/span><span class=\"o\">}<\/span>\r\n    <span class=\"o\">}<\/span>\r\n    <span class=\"nb\">date<\/span> <span class=\"o\">{<\/span>\r\n      match <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"start\"<\/span>,<span class=\"s2\">\"UNIX\"<\/span> <span class=\"o\">]<\/span>\r\n      target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"@timestamp\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n    <span class=\"nb\">date<\/span> <span class=\"o\">{<\/span>\r\n      match <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"start\"<\/span>,<span class=\"s2\">\"UNIX\"<\/span> <span class=\"o\">]<\/span>\r\n      target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"start_time\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n    <span class=\"nb\">date<\/span> <span class=\"o\">{<\/span>\r\n      match <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"end\"<\/span>,<span class=\"s2\">\"UNIX\"<\/span> <span class=\"o\">]<\/span>\r\n      target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"end_time\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n    geoip <span class=\"o\">{<\/span>\r\n      <span class=\"nb\">source<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"srcaddr\"<\/span>\r\n      target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"src_geoip\"<\/span>\r\n      tag_on_failure <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"src_geoip_lookup_failure\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n    geoip <span class=\"o\">{<\/span>\r\n      <span class=\"nb\">source<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"dstaddr\"<\/span>\r\n      target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"dst_geoip\"<\/span>\r\n      tag_on_failure <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"dst_geoip_lookup_failure\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n    mutate <span class=\"o\">{<\/span>\r\n      remove_field <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"start\"<\/span>, <span class=\"s1\">'end'<\/span> <span class=\"o\">]<\/span>\r\n    <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n\r\noutput <span class=\"o\">{<\/span>\r\n  elasticsearch <span class=\"o\">{<\/span>\r\n    hosts <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"xx.xx.xx.xx:9200\"<\/span> <span class=\"o\">]<\/span>\r\n    index <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"vpcflowlogs-%{+YYYY-MM-dd}\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Conf\u30d5\u30a1\u30a4\u30eb\u4f5c\u6210\uff08CloudTrail\uff09<\/ul>\n<pre class=\"post-pre\"><code>\r\ninput <span class=\"o\">{<\/span>\r\n  cloudwatch_logs <span class=\"o\">{<\/span>\r\n    region <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"ap-northeast-1\"<\/span>\r\n    log_group <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"ClouTrail-LogGroup\"<\/span> <span class=\"o\">]<\/span>\r\n    access_key_id <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"xxxxxxxxx\"<\/span>\r\n    secret_access_key <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"xxxxxxxxx\"<\/span>\r\n    sincedb_path <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"\/var\/lib\/logstash\/sincedb_cloudtrail\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n\r\nfilter <span class=\"o\">{<\/span>\r\n  json <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">source<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"message\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n  <span class=\"nb\">date<\/span> <span class=\"o\">{<\/span>\r\n    match <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"eventTime\"<\/span>, <span class=\"s2\">\"ISO8601\"<\/span> <span class=\"o\">]<\/span>\r\n    target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"@timestamp\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n  ruby <span class=\"o\">{<\/span>\r\n    code <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"event.set('[@metadata][local_time]',event.get('[@timestamp]').time.localtime.strftime('%Y-%m-%d'))\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n  useragent <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">source<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"userAgent\"<\/span>\r\n    target <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"useragent\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n  geoip <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">source<\/span> <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"sourceIPAddress\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n  mutate <span class=\"o\">{<\/span>\r\n    remove_field <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"message\"<\/span> <span class=\"o\">]<\/span>\r\n  <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n\r\noutput <span class=\"o\">{<\/span>\r\n  elasticsearch <span class=\"o\">{<\/span>\r\n    hosts <span class=\"o\">=&gt;<\/span> <span class=\"o\">[<\/span> <span class=\"s2\">\"xx.xx.xx.xx:9200\"<\/span> <span class=\"o\">]<\/span>\r\n    index <span class=\"o\">=&gt;<\/span> <span class=\"s2\">\"cloudtrail-%{+YYYY-MM-dd}\"<\/span>\r\n  <span class=\"o\">}<\/span>\r\n<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Pipeline\u30d5\u30a1\u30a4\u30eb\u8a2d\u5b9a<\/ul>\n<p>\u8a2d\u5b9a\u8907\u6578\u6b21\u8b80\u53d6conf\u6a94\u6848\u7684\u65b9\u5f0f<\/p>\n<pre class=\"post-pre\"><code><span class=\"c\">#- pipeline.id: main<\/span>\r\n<span class=\"c\">#  path.config: \"\/etc\/logstash\/conf.d\/*.conf\"<\/span>\r\n\r\n- pipeline.id: syslog\r\n  pipeline.batch.size: 125\r\n  path.config: <span class=\"s2\">\"\/etc\/logstash\/conf.d\/syslog.conf\"<\/span>\r\n  pipeline.workers: 1\r\n- pipeline.id: vpcflowlogs\r\n  pipeline.batch.size: 125\r\n  path.config: <span class=\"s2\">\"\/etc\/logstash\/conf.d\/vpcflowlogs.conf\"<\/span>\r\n  pipeline.workers: 1\r\n- pipeline.id: cloudtrail\r\n  pipeline.batch.size: 125\r\n  path.config: <span class=\"s2\">\"\/etc\/logstash\/conf.d\/cloudtrail.conf\"<\/span>\r\n  pipeline.workers: 1\r\n<\/code><\/pre>\n<ul class=\"post-ul\">Logstash\u518d\u8d77\u52d5<\/ul>\n<pre class=\"post-pre\"><code>systemctl restart logstash\r\n<\/code><\/pre>\n<h2>Kibana\u7684\u914d\u7f6e<\/h2>\n<p>\u8bbe\u5b9a\u65b9\u6cd5\u4e0e\u4e0a\u8ff0\u7684\u672c\u5730\u73af\u5883\u76f8\u540c\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7ec4\u6210 \u30aa\u30f3\u30d7\u30ec\u5074 \u30c6\u30b9\u30c8\u7528\u30b5\u30fc\u30d02\u53f0\u3068Cisco\u30b9\u30a4\u30c3\u30c1\u3092\u7528\u610f\u3002\u5404\u6a5f\u5668\u306e\u30ed\u30b0\u306fSyslog\u30b5\u30fc\u30d0\u306b\u8ee2\u9001\u3059\u308b\u3002  [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-41300","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch-logstash-kibana\u5c06\u672c\u5730\u548caws\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\" \/>\n<meta property=\"og:description\" content=\"\u7ec4\u6210 \u30aa\u30f3\u30d7\u30ec\u5074 \u30c6\u30b9\u30c8\u7528\u30b5\u30fc\u30d02\u53f0\u3068Cisco\u30b9\u30a4\u30c3\u30c1\u3092\u7528\u610f\u3002\u5404\u6a5f\u5668\u306e\u30ed\u30b0\u306fSyslog\u30b5\u30fc\u30d0\u306b\u8ee2\u9001\u3059\u308b\u3002 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch-logstash-kibana\u5c06\u672c\u5730\u548caws\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-04T14:24:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T11:45:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/2-0.png\" \/>\n<meta name=\"author\" content=\"\u97f5, \u79d1\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u97f5, \u79d1\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/\",\"name\":\"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-12-04T14:24:27+00:00\",\"dateModified\":\"2024-04-30T11:45:38+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\",\"name\":\"\u97f5, \u79d1\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"caption\":\"\u97f5, \u79d1\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch-logstash-kibana\u5c06\u672c\u5730\u548caws\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316","og_description":"\u7ec4\u6210 \u30aa\u30f3\u30d7\u30ec\u5074 \u30c6\u30b9\u30c8\u7528\u30b5\u30fc\u30d02\u53f0\u3068Cisco\u30b9\u30a4\u30c3\u30c1\u3092\u7528\u610f\u3002\u5404\u6a5f\u5668\u306e\u30ed\u30b0\u306fSyslog\u30b5\u30fc\u30d0\u306b\u8ee2\u9001\u3059\u308b\u3002 [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch-logstash-kibana\u5c06\u672c\u5730\u548caws\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-12-04T14:24:27+00:00","article_modified_time":"2024-04-30T11:45:38+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d464c37434c4406ca4b8d\/2-0.png"}],"author":"\u97f5, \u79d1","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u97f5, \u79d1","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"4 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/","name":"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-12-04T14:24:27+00:00","dateModified":"2024-04-30T11:45:38+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528Elasticsearch\/Logstash\/Kibana\u5c06\u672c\u5730\u548cAWS\u7684\u65e5\u5fd7\u6570\u636e\u8fdb\u884c\u53ef\u89c6\u5316"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e","name":"\u97f5, \u79d1","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","caption":"\u97f5, \u79d1"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch-logstash-kibana%e5%b0%86%e6%9c%ac%e5%9c%b0%e5%92%8caws%e7%9a%84%e6%97%a5%e5%bf%97%e6%95%b0%e6%8d%ae%e8%bf%9b%e8%a1%8c%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=41300"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41300\/revisions"}],"predecessor-version":[{"id":93922,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41300\/revisions\/93922"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=41300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=41300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=41300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}