ELK与Filebeat跨服务器日志传输异常:无法接收客户端日志
Hey there, let's troubleshoot why your Filebeat isn't sending logs to your ELK stack. You've already ruled out basic connectivity issues (ping, SSH, 5044 port listening), so let's dive into the specific checks that usually fix this kind of problem:
It looks like your config snippet was cut off, so let's make sure the key parts are set correctly:
- First, ensure your log prospector is enabled (you had a comment about changing to
true):filebeat.prospectors: - type: log enabled: true # Don't forget this line! paths: - /path/to/your/client/logs/*.log # Replace with actual log file paths - Confirm the output is pointing to your ELK server's 5044 port (since that's what Logstash is listening on):
output.logstash: hosts: ["<YOUR_ELK_SERVER_IP>:5044"] # Temporarily disable SSL for testing if you haven't configured it yet ssl.enabled: false
Check for syntax errors in your config with:
sudo filebeat test config
On your Wind River client, make sure Filebeat is running properly:
sudo systemctl status filebeat
If it's not running, start and enable it:
sudo systemctl start filebeat sudo systemctl enable filebeat
Then tail the Filebeat logs to spot errors (like permission issues, missing log files, or connection failures):
sudo journalctl -u filebeat -f
Common gotcha: Filebeat's default user might not have read access to your target log files. If you see permission errors, adjust file permissions or run Filebeat as a user with access.
Even though ping/SSH works, double-check that firewalls aren't blocking TCP traffic on port 5044:
- On your Ubuntu ELK server, check UFW rules:
If 5044 isn't allowed, add it:sudo ufw statussudo ufw allow 5044/tcp - On your Wind River client, check iptables for outbound restrictions:
Ensure there's no rule blocking outbound traffic to your ELK server's 5044 port.sudo iptables -L -n
From your Wind River client, use telnet or nc to confirm you can actually reach the 5044 port:
# Using telnet telnet <YOUR_ELK_SERVER_IP> 5044 # Or netcat nc -zv <YOUR_ELK_SERVER_IP> 5044
If this fails, there's still a network barrier (like a hidden router rule or security group) you need to fix. If it succeeds, the issue is likely in Filebeat/Logstash configuration.
On your ELK server, make sure Logstash's beats input is correctly set up (typically in /etc/logstash/conf.d/02-beats-input.conf):
input { beats { port => 5044 ssl => false # Match this with your Filebeat SSL setting } }
Restart Logstash and check its logs for errors:
sudo systemctl restart logstash sudo journalctl -u logstash -f
Ensure your Filebeat version is compatible with your ELK stack (Logstash/Elasticsearch). Cross-major versions (e.g., Filebeat 7.x with ELK 6.x) often cause connectivity or parsing issues.
内容的提问来源于stack exchange,提问作者Vamshi Krishna

