forked from spujadas/elk-docker
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
promoting Filebeat as preferred way to forward logs
added sample Filebeat configuration, working with server-side Beats plugin 2.0.3 (see spujadas#12)
- Loading branch information
Showing
13 changed files
with
239 additions
and
66 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,8 @@ | ||
input { | ||
beats { | ||
port => 5044 | ||
ssl => true | ||
ssl_certificate => "/etc/pki/tls/certs/logstash-beats.crt" | ||
ssl_key => "/etc/pki/tls/private/logstash-beats.key" | ||
} | ||
} |
File renamed without changes.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -12,3 +12,4 @@ elk: | |
- "5601:5601" | ||
- "9200:9200" | ||
- "5000:5000" | ||
- "5044:5044" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
-----BEGIN CERTIFICATE----- | ||
MIIC6zCCAdOgAwIBAgIJANPZwuf+5wTLMA0GCSqGSIb3DQEBCwUAMAwxCjAIBgNV | ||
BAMMASowHhcNMTUxMjI4MTA0NTMyWhcNMjUxMjI1MTA0NTMyWjAMMQowCAYDVQQD | ||
DAEqMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp+jHFvhyYKiPXc7k | ||
0c33f2QV+1hHNyW/uwcJbp5jG82cuQ41v70Z1+b2veBW4sUlDY3yAIEOPSUD8ASt | ||
9m72CAo4xlwYKDvm/Sa3KJtDk0NrQiz6PPyBUFsY+Bj3xn6Nz1RW5YaP+Q1Hjnks | ||
PEyQu4vLgfTSGYBHLD4gvs8wDWY7aaKf8DfuP7Ov74Qlj2GOxnmiDEF4tirlko0r | ||
qQcvBgujCqA7rNoG+QDmkn3VrxtX8mKF72bxQ7USCyoxD4cWV2mU2HD2Maed3KHj | ||
KAvDAzSyBMjI+qi9IlPN5MR7rVqUV0VlSKXBVPct6NG7x4WRwnoKjTXnr3CRADD0 | ||
4uvbQQIDAQABo1AwTjAdBgNVHQ4EFgQUVFurgDwdcgnCYxszc0dWMWhB3DswHwYD | ||
VR0jBBgwFoAUVFurgDwdcgnCYxszc0dWMWhB3DswDAYDVR0TBAUwAwEB/zANBgkq | ||
hkiG9w0BAQsFAAOCAQEAaLSytepMb5LXzOPr9OiuZjTk21a2C84k96f4uqGqKV/s | ||
okTTKD0NdeY/IUIINMq4/ERiqn6YDgPgHIYvQheWqnJ8ir69ODcYCpsMXIPau1ow | ||
T8c108BEHqBMEjkOQ5LrEjyvLa/29qJ5JsSSiULHvS917nVgY6xhcnRZ0AhuJkiI | ||
ARKXwpO5tqJi6BtgzX/3VDSOgVZbvX1uX51Fe9gWwPDgipnYaE/t9TGzJEhKwSah | ||
kNr+7RM+Glsv9rx1KcWcx4xxY3basG3/KwvsGAFPvk5tXbZ780VuNFTTZw7q3p8O | ||
Gk1zQUBOie0naS0afype5qFMPp586SF/2xAeb68gLg== | ||
-----END CERTIFICATE----- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
-----BEGIN PRIVATE KEY----- | ||
MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQCn6McW+HJgqI9d | ||
zuTRzfd/ZBX7WEc3Jb+7BwlunmMbzZy5DjW/vRnX5va94FbixSUNjfIAgQ49JQPw | ||
BK32bvYICjjGXBgoO+b9Jrcom0OTQ2tCLPo8/IFQWxj4GPfGfo3PVFblho/5DUeO | ||
eSw8TJC7i8uB9NIZgEcsPiC+zzANZjtpop/wN+4/s6/vhCWPYY7GeaIMQXi2KuWS | ||
jSupBy8GC6MKoDus2gb5AOaSfdWvG1fyYoXvZvFDtRILKjEPhxZXaZTYcPYxp53c | ||
oeMoC8MDNLIEyMj6qL0iU83kxHutWpRXRWVIpcFU9y3o0bvHhZHCegqNNeevcJEA | ||
MPTi69tBAgMBAAECggEAGh1xQZhYqcHtsmhoXF1NfinB5XrAcMpVPLCGfgbyYTOk | ||
iX+1SmIN7++DNtr6iICjF62ZEwz/evET4LPJnsd5SpzUYb2XIELY1Uy9NfqYEwJs | ||
XzmBnhSjxCy3AHdZqiyqv7FdZot8Pv8avwUHpUU/SXwfpdG/D6pM54uuKh8tWRfp | ||
6Fun0x3tFLhr1iY/jwxXx+V5zZ1A7AyHnelSv1u7gnxd2WPNJsyoYp7iWkSbdmjr | ||
fThE8CsTSgL/ndKOmxnPLs7l7ZUipyBgwjmUoZxCZk1I4w9njXY9mti67+6/SAj7 | ||
i26/c7p6H31C+FAqksdKOHWh+zCg8zf1kMW3x3P3MQKBgQDUncHjIZ2rDuoWrOIc | ||
ng6IbuyuSHjUDCs59Z2HQbAVe/0IgDKNspdfddgC5XSN8q5GIWvNQtJjQzuCBRJC | ||
SxKkncOcTH6J3eQ4e4+sqDbHIagHQwuSBQRYkjd/KN63HEEJoh5UB/r/77CRdOhT | ||
m6dBm7QvrlXUpcm+z2V3TwvahQKBgQDKK7Qg0mBKm8QVneZUqGRbzaLcOsDefzdP | ||
IKRhWphAia70z6eoPHgR5MaqCFTPAajFaX6xBzIkPT8g8YUMPHhnw5eJRh/58hbU | ||
84KBw9jNGjE+H+OTT8+qLicP9EoMOeSVknYIX/zPj7xww0w2mF6tYroKKsiQHZhv | ||
eB16YjqAjQKBgD1BCffm2mbK0DQiMK5v9t3lnziC1pS4wMdc9Lpf+VvnMbn+PRJH | ||
roapC8eh1ZeDoCPCQy2Kn9RLLVzDG0SQHlngvddMznPnwnVnW7gxaj6qep9E+JNj | ||
8KGX1ndDDg8RC8e7tiMdfXm401TEqp5TzLcBJcNK5Z1y+hGH7MKXumGFAoGATmkI | ||
4bn2Url7IY8uKCNvWRO2WIgJCcJ5Zx0X5BJI/q7nxldLhTp+ryH10ziL/AV+uaIi | ||
2vIZhmiitVo26foCEOyRN1KVUFGOfWU8dqvIyDOiaZ/gmd/YgP6Jc+yhU4CYoVI+ | ||
qRzhZncu9OUqB/qsrb6evRa+1vZDiughNrgmTHkCgYBggzulPfHEBqhlcg6PCsUj | ||
W6YcxEEPojkPPBsG/aMkGOmCr75I2w81lcjyUv54AiVXpSKqgvs+Zg3nF1WRxMVG | ||
vevXsCc4wdJPn669J68uh34eHvMBJQ8I00P7tBcW1RjXpvaH/HLUMO51vnfMwBtR | ||
OrW1ssSF9AvUG1VUmnMSgA== | ||
-----END PRIVATE KEY----- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,65 @@ | ||
# Dockerfile to illustrate how Filebeat can be used with nginx | ||
# Filebeat 1.0.1 | ||
|
||
# Build with: | ||
# docker build -t <repo-user>/filebeat-nginx-example . | ||
|
||
# Run with: | ||
# docker run -p 80:80 -it --link <elk-container-name>:elk \ | ||
# --name filebeat-nginx-example <repo-user>/filebeat-nginx-example | ||
|
||
FROM nginx | ||
MAINTAINER Sebastien Pujadas http://pujadas.net | ||
ENV REFRESHED_AT 2015-11-28 | ||
|
||
|
||
############################################################################### | ||
# INSTALLATION | ||
############################################################################### | ||
|
||
### install Filebeat | ||
|
||
RUN apt-get update -qq \ | ||
&& apt-get install -qqy curl \ | ||
&& apt-get clean | ||
|
||
RUN curl -L -O https://download.elastic.co/beats/filebeat/filebeat_1.0.1_amd64.deb \ | ||
&& dpkg -i filebeat_1.0.1_amd64.deb \ | ||
&& rm filebeat_1.0.1_amd64.deb | ||
|
||
|
||
############################################################################### | ||
# CONFIGURATION | ||
############################################################################### | ||
|
||
### tweak nginx image set-up | ||
|
||
# remove log symlinks | ||
RUN rm /var/log/nginx/access.log /var/log/nginx/error.log | ||
|
||
|
||
### configure Filebeat | ||
|
||
# config file | ||
ADD filebeat.yml /etc/filebeat/filebeat.yml | ||
|
||
# CA cert | ||
RUN mkdir -p /etc/pki/tls/certs | ||
ADD logstash-beats.crt /etc/pki/tls/certs/logstash-beats.crt | ||
|
||
############################################################################### | ||
# DATA | ||
############################################################################### | ||
|
||
### add dummy HTML file | ||
|
||
COPY html /usr/share/nginx/html | ||
|
||
|
||
############################################################################### | ||
# START | ||
############################################################################### | ||
|
||
ADD ./start.sh /usr/local/bin/start.sh | ||
RUN chmod +x /usr/local/bin/start.sh | ||
CMD [ "/usr/local/bin/start.sh" ] |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,21 @@ | ||
output: | ||
logstash: | ||
enabled: true | ||
hosts: | ||
- elk:5044 | ||
timeout: 15 | ||
tls: | ||
certificate_authorities: | ||
- /etc/pki/tls/certs/logstash-beats.crt | ||
|
||
filebeat: | ||
prospectors: | ||
- | ||
paths: | ||
- /var/log/syslog | ||
- /var/log/auth.log | ||
document_type: syslog | ||
- | ||
paths: | ||
- "/var/log/nginx/*.log" | ||
document_type: nginx-access |
Binary file not shown.
Oops, something went wrong.