如何用Filebeat实现Elastic ELK Stack 8.5与Spring Boot应用集成?
本地搭建Elasticsearch+Kibana+Logstash日志Pipeline并接入Spring Boot日志(Filebeat推送)
以下针对单Spring Boot应用场景,给出清晰的实操步骤:
1. 环境准备
- 下载同版本的Elasticsearch、Kibana、Logstash、Filebeat(推荐8.x系列,避免兼容性问题)
- 本地机器建议配置:4核8G以上内存,防止资源不足导致服务启动失败
2. 启动Elasticsearch
- 解压后进入
bin目录,执行启动命令:- Linux/macOS:
./elasticsearch - Windows:
elasticsearch.bat
- Linux/macOS:
- 首次启动会生成超级用户密码和Kibana的enrollment token,务必保存好这些信息
- 验证启动:访问
http://localhost:9200,输入用户名elastic和对应密码,能返回JSON响应即正常
3. 启动Kibana
- 解压后进入
bin目录,执行启动命令:- Linux/macOS:
./kibana - Windows:
kibana.bat
- Linux/macOS:
- 首次启动按照提示输入之前生成的enrollment token,完成配置
- 验证启动:访问
http://localhost:5601,能进入Kibana管理界面即成功
4. 配置并启动Logstash
- 在Logstash目录下新建
config/spring-boot-log-pipeline.conf,写入以下配置(根据实际密码修改):input { beats { port => 5044 } } filter { if [fields][source] == "spring-boot" { # 匹配默认Spring Boot日志格式,自定义日志格式需调整此规则 grok { match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:loglevel} %{NUMBER:pid} --- \[%{DATA:thread}\] %{DATA:class} : %{GREEDYDATA:message}" } } date { match => [ "timestamp", "yyyy-MM-dd HH:mm:ss.SSS" ] target => "@timestamp" } } } output { elasticsearch { hosts => ["http://localhost:9200"] user => "elastic" password => "你的Elasticsearch超级用户密码" index => "spring-boot-logs-%{+YYYY.MM.dd}" } } - 启动Logstash:
- Linux/macOS:
./logstash -f config/spring-boot-log-pipeline.conf - Windows:
logstash.bat -f config/spring-boot-log-pipeline.conf
- Linux/macOS:
- 验证:启动后无报错信息即配置有效
5. 配置并启动Filebeat
- 打开Filebeat目录下的
filebeat.yml,修改核心配置项:filebeat.inputs: - type: filestream enabled: true paths: - /你的Spring Boot应用日志路径/*.log # 替换为实际日志路径,Windows用类似C:/app/logs/*.log格式 fields: source: spring-boot output.logstash: hosts: ["localhost:5044"] - 启动Filebeat:
- Linux/macOS:
./filebeat -e -c filebeat.yml - Windows:
filebeat.bat -e -c filebeat.yml
- Linux/macOS:
6. 验证全链路
- 启动你的Spring Boot应用,触发一些日志生成
- 进入Kibana,依次打开
Management->Index Management,确认生成了spring-boot-logs-YYYY.MM.dd格式的索引 - 创建索引模式:
Management->Index Patterns,创建匹配spring-boot-logs-*的模式,之后就能在Discover模块中查看、检索Spring Boot日志
注意事项
- 所有组件必须使用相同大版本,否则可能出现兼容性问题
- Elasticsearch内存可通过
config/jvm.options调整,默认1G,建议根据机器内存改为2G - 如果自定义了Spring Boot日志格式,需要同步修改Logstash的grok匹配规则
内容的提问来源于stack exchange,提问作者Leons
相关产品推荐
相关产品推荐

