±à¼ÍƼö: |
±¾ÎÄÖ÷Òª½éÉÜSplunk°²×°ºÍʹÓÃ,´Ó°²×°×°±¸-·þÎñÆ÷°²×°-¿Í»§¶Ë°²×°£¬ÒÔ¼°²é¿´Ê¹ÓÃÇé¿ö£¬Ï£Íû¶ÔÄúµÄѧϰÓÐËù°ïÖú¡£
±¾ÎÄÀ´×ÔÓÚcsdn£¬ÓÉ»ðÁú¹ûÈí¼þAlice±à¼¡¢ÍƼö¡£ |
|
Splunk¸ÅÄî
Splunk ÊÇ»úÆ÷Êý¾ÝµÄÒýÇæ¡£ ʹÓà Splunk
¿ÉÊÕ¼¯¡¢Ë÷ÒýºÍÀûÓÃËùÓÐÓ¦ÓóÌÐò¡¢·þÎñÆ÷ºÍÉ豸£¨ÎïÀí¡¢ÐéÄâºÍÔÆÖУ©Éú³ÉµÄ¿ìËÙÒÆ¶¯ÐͼÆËã»úÊý¾Ý ¡£´ÓÒ»¸öλÖÃ
ËÑË÷²¢·ÖÎöËùÓÐʵʱºÍÀúÊ·Êý¾Ý¡£
ʹÓà Splunking
´¦Àí¼ÆËã»úÊý¾Ý£¬¿ÉÈÃÄúÔÚ¼¸·ÖÖÓÄÚ£¨¶ø²»ÊǼ¸¸öСʱ»ò¼¸Ì죩½â¾öÎÊÌâºÍµ÷²é°²È«Ê¼þ¡£¼àÊÓÄúµÄ¶Ë¶Ô¶Ë»ù´¡½á¹¹£¬±ÜÃâ·þÎñÐÔÄܽµµÍ»òÖжϡ£ÒԽϵͳɱ¾Âú×ãºÏ¹æÐÔÒªÇó¡£¹ØÁª²¢·ÖÎö¿çÔ½¶à¸öϵͳ
ÕûÌå¼Ü¹¹¸ÅÄî
Splunk·ÖΪ·þÎñÆ÷(Splunk)ºÍ¿Í»§¶Ë£¨Splunkforwarder£©¡£SplunkµÄ·þÎñÆ÷¾ÍÊÇË÷ÒýÆ÷ºÍ½ÓÊÕÆ÷¡£¿Í»§¶Ë¾ÍÊÇÊý¾ÝµÄת·¢Æ÷¡£¹ËÃû˼Òå¾ÍÊÇÊý¾Ý¿ÉÓɿͻ§¶Ëת·¢ÖÁserver¶Ë½øÐÐË÷Òý¡£¿Í»§¶ËÖ»Æðµ½×ª·¢Êý¾ÝµÄ×÷Óá£
°²×°×°±¸
°²×°°üÁ½¸ö£º
1.·þÎñÆ÷£ºsplunk-6.5.2-67571ef4b87d-linux-2.6-x86_64.rpm
2.¿Í»§¶Ë£ºsplunkforwarder-6.5.2-67571ef4b87d-linux-2.6-x86_64.rpm
ÏÂÔØµØÖ·£º¹ÙÍøhttps://www.splunk.com/ ÒªÏÈ×¢²á
·þÎñÆ÷°²×°
°²×°(ʹÓÃrootȨÏÞ)£º rpm -ivh ¨Cprefix=/home/splunk splunk_package_name.rpm
¨Cprefix=ºóÃæÊÇÄãÒª°²×°µÄ·¾¶£¬²»¼ÓÕâ¸öĬÈÏÊÇ/opt/splunk
Æô¶¯£º$SPLUNK_HOME/bin/splunk start ¨Caccept-license
Èç¹ûÄãÒªÓ÷ÇrootÆô¶¯ÐèÒª½«splunk°²×°Â·¾¶¸³ÓèȨÏÞ¸øÐÂÓû§
ÉèÖÿª»úÆô¶¯£º$SPLUNK_HOME/bin/splunk enable boot-start
ÐÞ¸ÄË÷ÒýλÖÃÉèÖã¨Èç¹ûÄãÒª°ÑË÷Òý·ÅÔÚÆäËûÖ¸¶¨µÄĿ¼µÄ»°£©£º
//¿½±´ÔªÊý¾ÝµÄÈÕÖ¾µ½Ö¸¶¨Ä¿Â¼
cp -fr /opt/splunk/var/lib/splunk/* /¡./¡.
ÐÞ¸Ä$SPLUNK_HOME/etc/splunk-launch.conf Îļþ¡£
ÐÞ¸ÄÀïÃæSPLUNK_DB=/з¾¶£¬ÖØÆôsplunk¡£
ÔËÐÐÆô¶¯ºóÔÚwebÊäÈ룺http://127.0.0.1:8000 ²é¿´serverµÇÂ¼Ò³Ãæ
¸ü¸ÄÐí¿ÉÖ¤Êé;
³õʼÕË»§ÃÜÂëÊÇ admin ºÍ changeme
ÉèÖýÓÊÕÊý¾ÝµÄ¶Ë¿Ú£º
µã»÷Ò³ÃæÓÒÉϽǵÄÉèÖÃÀïÃæµÄ¡±×ª·¢ºÍ½ÓÊÕ¡±¡£Ñ¡Ôñ ¡°ÅäÖýÓÊÕ¡±Äǵ㡰ÐÂÔö¡±¡£ÊäÈëÄãÒª½ÓÊÕÊý¾ÝµÄ¶Ë¿ÚÈç12345
µ½ÕâÀï·þÎñÆ÷¾Í»ù±¾×¼±¸ºÃÁË¡£
´´½¨Ë÷Òý£º
µã»÷Ò³ÃæÓÒÉϽǵÄÉèÖÃÀïÃæµÄ ¡°Ë÷Òý¡± ¡£Ñ¡Ôñ ¡°ÐÂÔöË÷Òý¡±¡£
¿Í»§¶ËµÄ°²×°
rpm -ivh ¨Cprefix=/home/splunk splunk_package_name.rpm
./splunk start ¨Caccept-license
Ð޸Ŀͻ§¶ËµÄÃÜÂ룺./splunk edit user admin -password ¡®ÐÂÃÜÂ롯
-role admin -auth admin:changeme
ÉèÖÿͻ§¶ËµÄÊä³ö£¨·¢Ë͵ķþÎñÆ÷ºÍ¶Ë¿Ú£©£º./splunk add forward-server server_ip:12345
²é¿´ÄãµÄÊä³öÉèÖãº./splunk list forward-server
×¢²á¿Í»§¶Ëµ½·þÎñÆ÷£º./splunk set deploy-poll server_ip:8089
ÄãÐèÒª½«Õâ¸ö¿Í»§¶Ë×¢²áµ½·þÎñÆ÷¡£ÄãÔÚwebÒ³ÃæÉϾͿÉÒÔ¿´µ½ÓÐÄÄЩ¿Í»§¶Ë¡£¶øÇÒ¿ÉÒÔÔÚÒ³ÃæÉÏÅäÖÃ¼à¿Ø·þÎñÆ÷
¼à¿ØÒ»¸öĿ¼£º
./splunk add monitor /your_dir_path
./splunk add monitor /var/log/\*.log
./splunk add monitor /your_dir_path -index indexname
-sourcetype sourcetypename
ɾ³ý
./splunk remove monitor /data/weblog/oem.v2.zhiziyun.com
ÏÔʾÓÐÄÄЩ±»¼à¿Ø:./splunk list monitor
ÖØÆô¿Í»§¶Ë
ÒÔÉϿͻ§¶ËµÄÊäÈëºÍÊä³öÅäÖö¼¿ÉÒÔͨ¹ýÐÞ¸ÄËûµÄÅäÖÃÎļþÀ´ÉúЧ¡£(ÔõôÅäÖÿ´¹Ù·½Îĵµ)
¼à¿ØÄÄЩĿ¼Äã¿ÉÒÔÐ޸ģº$SPLUNK_HOME/etc/system/local/input.conf
¸ñʽÈçÏ£º
[monitor://ÈÕÖ¾µØÖ·£¨ÕâÀï¿ÉÒÔʹÓÃÕýÔòÀ´¹ýÂËÊý¾Ý£©]
index=indexName
sourcetype=sourceName
[monitor://ÁíÒ»¸ö]
index=indexName
sourcetype=sourceName
[monitor:///xxx/xxx/log/xxx/xxx.log]
index=xxxxxxxx
sourcetype=xxxxxx |
ת·¢Êý¾Ýµ½ÄÄÄã¿ÉÒÔÐ޸ģº$SPLUNK_HOME/etc/system/local/output.conf
¼à¿Ø¿Í»§¶ËµÄĿ¼
Ñ¡ÔñÒ³ÃæÓÒÉÏ½Ç ¡®ÉèÖᯠÀïÃæµÄ¡°Êý¾ÝÊäÈ롱
µãн¨£ºÑ¡ÔñÄã¼à¿ØµÄ·þÎñÆ÷Áбí -> ÊäÈëÄãµÄÎļþ¼Ð·¾¶(¿ÉÒÔÓÃÕýÔò¹ýÂËÎļþ) -> Ñ¡ÔñË÷ÒýºÍÊý¾ÝÀàÐÍ
µ½´ËÄãµÄ¿Í»§¶Ë¾ÍÅäÖÃÍê³ÉÁË¡£Äã¿ÉÒÔÔÚwebµÄËÑË÷½çÃæ¿´µ½ÄãË÷ÒýµÄĿ¼ÀïÃæµÄÈÕÖ¾ÎļþÁË¡£
Èç¹ûÄãÒª¼à¿Ø¶à¸ö¿Í»§¶Ë¡£ÄãÖ»Ðè°´ÕÕÒÔÉϿͻ§¶ËµÄÅäÖþÍÐÐÁË¡£µ±È»Splunk²»Ö¹Ö»ÓÐÕâôµã¹¦ÄÜ¡£Äã¿ÉÒԲ鿴¹Ù·½µÄÎĵµËµÃ÷¡£
Óʼþ¸æ¾¯
ÉèÖ÷¢ÓʼþµÄ·þÎñÆ÷£ºÉèÖÃ->·þÎñÆ÷ÉèÖÃ->µç×ÓÓʼþÉèÖÃ
SplunkµÄÒ»´óÌØµã¾ÍÊÇ¿ÉÒÔ¸ù¾ÝÄãµÄÉèÖÃ¼à¿ØÄãµÄÈÕÖ¾£¬Èç¹ûÂú×ãÄãµÄÉèÖñ¨¾¯Ìõ¼þ£¬Ëü¾Í¿ÉÒÔ·¢Óʼþµ½ÌصãµÄÓÊÏä
ɾ³ýË÷Òý
SplunkËÆºõÊÇ Ã»ÓÐË÷Òý¹ýÆÚ×Ô¶¯É¾³ý»úÖÆµÄ£¨ÖÁÉÙÎÒû¿´µ½£©
¹Ù·½¸øµÄɾ³ýË÷ÒýµÄ·½Ê½ÓÐÁ½¸ö
È«²¿Çå¿ÕÒ»¸öË÷ÒýÊý¾Ý£ºÍ£µôserverÈ»ºóÔËÐÐÃüÁî./splunk
clean eventdata -index
²¿·Ö»òÕßÈ«²¿Çå¿Õ£ºÔØwebÉÏ´´½¨Ò»¸öеÄÓû§user¡£¸³Óècan_delete½ÇÉ«¡£È»ºóÓÃÕâ¸öÓû§µÇ¼£¬ÔÚËÑË÷Ò³ÃæÊäÈëÄã
µÄ²éѯÌõ¼þÈ磺index=¡±test¡± | delete ÄÇËû»á°ÑÄã²é³öÀ´µÄ¶¼É¾µô
¿ØÖÆindexµÄ´óС¡£¿ÉÒÔÔÚ´´½¨indexµÄʱºòÖªµÀ´óС·¶Î§£¬³¬¹ýÕâ¸ö´óСË÷ÒýÊý¾Ý¾Í»á±»Çå¿Õ
ÆóÒµ°æ×ªÃâ·Ñ°æ£¨free£©¡£Èç¹û²»ÂòµÄ»°£¨Æäʵfree°æ¶Ô¿´ÈÕÖ¾À´ËµÍêÈ«¹»ÓÃÁË£¬Ò»ÌìÔõô˵Ҳ²»»áÓÐ500MµÄÈÕÖ¾£¬ÀýÍâ¾ÍËãÁË£¬ÍøÉÏÓÐÆÆ½âµÄ½Å±¾£©£¬½¨Òé¸Õ×°ºÃµÄʱºò¾Í°ÑÖ¤ÊéתΪfree¡£ÒòΪһ¿ªÊ¼µÄʱºòĬÈÏÊÇÆóÒµ
trit°æ£¬µ±Ä㽨ÓÃÕâ¸ö°æ±¾½¨indexÖ®ºó£¬µÈ¹ýÆÚÁËÏëÔÙתfree¿ÉÄÜ»á³öÏÖindex²»¿ÉÓã¬Ð½¨Ò²²»ÐУ¬Õâ¸öʱºòÄã¿ÉÄÜÐèÒªÖØÐ°²×°£¬ËùÒÔ½¨ÒéÊǸÕ×°ºÃsplunk¾Í°ÑÕæÖ¤ÊéתΪfree°æÈ»ºóÖØÆô¼´¿É¡£
ÔÚÊÚȨÀïÃæ¸ü¸ÄÖ¤Êé×é¼´¿É¡£
²é¿´Ê¹ÓÃÇé¿ö
|