You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ELK与Filebeat跨服务器日志传输异常:无法接收客户端日志

Hey there, let's troubleshoot why your Filebeat isn't sending logs to your ELK stack. You've already ruled out basic connectivity issues (ping, SSH, 5044 port listening), so let's dive into the specific checks that usually fix this kind of problem:

1. Finish & Validate Your Filebeat Configuration

It looks like your config snippet was cut off, so let's make sure the key parts are set correctly:

  • First, ensure your log prospector is enabled (you had a comment about changing to true):
    filebeat.prospectors:
    - type: log
      enabled: true  # Don't forget this line!
      paths:
        - /path/to/your/client/logs/*.log  # Replace with actual log file paths
    
  • Confirm the output is pointing to your ELK server's 5044 port (since that's what Logstash is listening on):
    output.logstash:
      hosts: ["<YOUR_ELK_SERVER_IP>:5044"]
      # Temporarily disable SSL for testing if you haven't configured it yet
      ssl.enabled: false
    

Check for syntax errors in your config with:

sudo filebeat test config
2. Check Filebeat Service Health & Logs

On your Wind River client, make sure Filebeat is running properly:

sudo systemctl status filebeat

If it's not running, start and enable it:

sudo systemctl start filebeat
sudo systemctl enable filebeat

Then tail the Filebeat logs to spot errors (like permission issues, missing log files, or connection failures):

sudo journalctl -u filebeat -f

Common gotcha: Filebeat's default user might not have read access to your target log files. If you see permission errors, adjust file permissions or run Filebeat as a user with access.

3. Verify Firewall Rules for 5044 TCP Traffic

Even though ping/SSH works, double-check that firewalls aren't blocking TCP traffic on port 5044:

  • On your Ubuntu ELK server, check UFW rules:
    sudo ufw status
    
    If 5044 isn't allowed, add it:
    sudo ufw allow 5044/tcp
    
  • On your Wind River client, check iptables for outbound restrictions:
    sudo iptables -L -n
    
    Ensure there's no rule blocking outbound traffic to your ELK server's 5044 port.
4. Test Direct Connection to ELK's 5044 Port

From your Wind River client, use telnet or nc to confirm you can actually reach the 5044 port:

# Using telnet
telnet <YOUR_ELK_SERVER_IP> 5044

# Or netcat
nc -zv <YOUR_ELK_SERVER_IP> 5044

If this fails, there's still a network barrier (like a hidden router rule or security group) you need to fix. If it succeeds, the issue is likely in Filebeat/Logstash configuration.

5. Validate Logstash Input Configuration

On your ELK server, make sure Logstash's beats input is correctly set up (typically in /etc/logstash/conf.d/02-beats-input.conf):

input {
  beats {
    port => 5044
    ssl => false  # Match this with your Filebeat SSL setting
  }
}

Restart Logstash and check its logs for errors:

sudo systemctl restart logstash
sudo journalctl -u logstash -f
6. Check Version Compatibility

Ensure your Filebeat version is compatible with your ELK stack (Logstash/Elasticsearch). Cross-major versions (e.g., Filebeat 7.x with ELK 6.x) often cause connectivity or parsing issues.

内容的提问来源于stack exchange,提问作者Vamshi Krishna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:28:55