You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Filebeat实现Elastic ELK Stack 8.5与Spring Boot应用集成?

本地搭建Elasticsearch+Kibana+Logstash日志Pipeline并接入Spring Boot日志(Filebeat推送)

以下针对单Spring Boot应用场景,给出清晰的实操步骤:

1. 环境准备

  • 下载同版本的Elasticsearch、Kibana、Logstash、Filebeat(推荐8.x系列,避免兼容性问题)
  • 本地机器建议配置:4核8G以上内存,防止资源不足导致服务启动失败

2. 启动Elasticsearch

  • 解压后进入bin目录,执行启动命令:
    • Linux/macOS:./elasticsearch
    • Windows:elasticsearch.bat
  • 首次启动会生成超级用户密码和Kibana的enrollment token,务必保存好这些信息
  • 验证启动:访问http://localhost:9200,输入用户名elastic和对应密码,能返回JSON响应即正常

3. 启动Kibana

  • 解压后进入bin目录,执行启动命令:
    • Linux/macOS:./kibana
    • Windows:kibana.bat
  • 首次启动按照提示输入之前生成的enrollment token,完成配置
  • 验证启动:访问http://localhost:5601,能进入Kibana管理界面即成功

4. 配置并启动Logstash

  • 在Logstash目录下新建config/spring-boot-log-pipeline.conf,写入以下配置(根据实际密码修改):
    input {
      beats {
        port => 5044
      }
    }
    
    filter {
      if [fields][source] == "spring-boot" {
        # 匹配默认Spring Boot日志格式,自定义日志格式需调整此规则
        grok {
          match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:loglevel} %{NUMBER:pid} --- \[%{DATA:thread}\] %{DATA:class} : %{GREEDYDATA:message}" }
        }
        date {
          match => [ "timestamp", "yyyy-MM-dd HH:mm:ss.SSS" ]
          target => "@timestamp"
        }
      }
    }
    
    output {
      elasticsearch {
        hosts => ["http://localhost:9200"]
        user => "elastic"
        password => "你的Elasticsearch超级用户密码"
        index => "spring-boot-logs-%{+YYYY.MM.dd}"
      }
    }
    
  • 启动Logstash:
    • Linux/macOS:./logstash -f config/spring-boot-log-pipeline.conf
    • Windows:logstash.bat -f config/spring-boot-log-pipeline.conf
  • 验证:启动后无报错信息即配置有效

5. 配置并启动Filebeat

  • 打开Filebeat目录下的filebeat.yml,修改核心配置项:
    filebeat.inputs:
    - type: filestream
      enabled: true
      paths:
        - /你的Spring Boot应用日志路径/*.log  # 替换为实际日志路径,Windows用类似C:/app/logs/*.log格式
      fields:
        source: spring-boot
    
    output.logstash:
      hosts: ["localhost:5044"]
    
  • 启动Filebeat:
    • Linux/macOS:./filebeat -e -c filebeat.yml
    • Windows:filebeat.bat -e -c filebeat.yml

6. 验证全链路

  • 启动你的Spring Boot应用,触发一些日志生成
  • 进入Kibana,依次打开Management -> Index Management,确认生成了spring-boot-logs-YYYY.MM.dd格式的索引
  • 创建索引模式:Management -> Index Patterns,创建匹配spring-boot-logs-*的模式,之后就能在Discover模块中查看、检索Spring Boot日志

注意事项

  • 所有组件必须使用相同大版本,否则可能出现兼容性问题
  • Elasticsearch内存可通过config/jvm.options调整,默认1G,建议根据机器内存改为2G
  • 如果自定义了Spring Boot日志格式,需要同步修改Logstash的grok匹配规则

内容的提问来源于stack exchange,提问作者Leons

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 07:55:28