You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Filebeat.yml将WSO2AM日志发送至Elasticsearch

Filebeat对接WSO2AM与Elasticsearch配置方法

完整配置示例

将以下内容替换到你的filebeat.yml中,再按需修改对应参数即可:

# 输入配置:采集WSO2AM日志
filebeat.inputs:
- type: filestream
  enabled: true
  paths:
    - /opt/wso2am-4.2.0/repository/logs/wso2carbon.log
    - /opt/wso2am-4.2.0/repository/logs/api-manager.log
    - /opt/wso2am-4.2.0/repository/logs/audit.log
  # 自定义字段标记日志来源,方便ES侧筛选
  fields:
    log_source: wso2am
  # 多行日志合并配置,适配WSO2AM异常堆栈的换行场景
  multiline.type: pattern
  multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}|^TID:'
  multiline.negate: true
  multiline.match: after

# 可选:日志预处理,删除冗余字段减少存储占用
processors:
  - drop_fields:
      fields: ["agent", "ecs", "input", "log.offset"]
      ignore_missing: true

# Elasticsearch输出配置
output.elasticsearch:
  hosts: ["http://你的ES服务地址:9200"]
  # 若ES开启身份认证,取消注释并填写对应账号密码
  # username: "elastic"
  # password: "你的ES访问密码"
  # 自定义索引规则,按天切分方便管理
  index: "filebeat-wso2am-%{+yyyy.MM.dd}"

# 索引模板与生命周期配置
setup.ilm.enabled: false
setup.template.enabled: true
setup.template.pattern: "filebeat-wso2am-*"
setup.template.name: "filebeat-wso2am"

关键配置修改说明

  • paths:替换为你实际部署的WSO2AM日志目录,默认日志目录为<WSO2AM安装路径>/repository/logs/,可按需添加需要采集的日志文件路径
  • hosts:替换为你的Elasticsearch服务实际访问地址与端口
  • 若使用7.0以下版本的Filebeat,将type: filestream修改为type: log即可,其余配置兼容

配置生效与验证

  • 执行filebeat test config校验配置语法是否合法,返回Config OK即为正常
  • 执行filebeat test output校验与Elasticsearch的连通性,返回Connection to host ... succeeded即为正常
  • 校验通过后重启Filebeat服务即可生效,稍等片刻即可在Elasticsearch的filebeat-wso2am-*索引下查询到WSO2AM产生的日志

内容的提问来源于stack exchange,提问作者mohammad amin rahimi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 22:36:04