【问题标题】:Filebeat 6.7.0 not pushing logs to Elasticsearch 6.7.0 after upgradeFilebeat 6.7.0 升级后未将日志推送到 Elasticsearch 6.7.0
【发布时间】:2019-08-19 11:52:21
【问题描述】:

从 6.6.2 升级到 6.7.0 后,Filebeat 停止工作

我的 Filebeat 配置是:

filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/www/current/log/production.log
    - /var/www/current/log/api_v2.production.log
  multiline.pattern: '^[EIWDF]\, '
  multiline.negate: true
  multiline.match: after
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
setup.template.settings:
  index.number_of_shards: 3
setup.kibana:
output.elasticsearch:
  hosts: ["ip:29200"]

但是 /var/log/filebeat/filebeat 显示:

2019-03-28T14:12:11.091Z    ERROR   pipeline/output.go:100  Failed to connect to backoff(elasticsearch(http://ip:9200)): Connection marked as failed because the onConnect callback failed: This Beat requires the default distribution of Elasticsearch. Please upgrade to the default distribution of Elasticsearch from elastic.co, or downgrade to the oss-only distribution of beats
2019-03-28T14:12:11.091Z    INFO    [publish]   pipeline/retry.go:189   retryer: send unwait-signal to consumer
2019-03-28T14:12:11.091Z    INFO    [publish]   pipeline/retry.go:191     done
2019-03-28T14:12:11.091Z    INFO    [publish]   pipeline/retry.go:166   retryer: send wait signal to consumer
2019-03-28T14:12:11.091Z    INFO    [publish]   pipeline/retry.go:168     done
2019-03-28T14:12:11.091Z    INFO    pipeline/output.go:93   Attempting to reconnect to backoff(elasticsearch(http://ip:9200)) with 5 reconnect attempt(s)
2019-03-28T14:12:11.125Z    INFO    elasticsearch/client.go:739 Attempting to connect to Elasticsearch version 6.7.0

但是当我点击curl ip:9200 时它返回:

{
  "name" : "30KRsiU",
  "cluster_name" : "docker-cluster",
  "cluster_uuid" : "xim_BCzFSXWrAO_kMO3TQA",
  "version" : {
    "number" : "6.7.0",
    "build_flavor" : "oss",
    "build_type" : "docker",
    "build_hash" : "8453f77",
    "build_date" : "2019-03-21T15:32:29.844721Z",
    "build_snapshot" : false,
    "lucene_version" : "7.7.0",
    "minimum_wire_compatibility_version" : "5.6.0",
    "minimum_index_compatibility_version" : "5.0.0"
  },
  "tagline" : "You Know, for Search"
}

我如何让它工作?我没主意了。感谢您的帮助。

【问题讨论】:

    标签: elasticsearch elastic-stack filebeat


    【解决方案1】:

    我遇到了同样的问题(心跳),建议的解决方案是降级到 6.6.2

    2019-04-01T09:36:27.474Z 错误实例/beat.go:802 退出:无法连接到任何已配置的 Elasticsearch 主机。错误:[与 Elasticsearch 的错误连接http://localhost:19200:连接标记为失败,因为 onConnect 回调失败:此 Beat 需要 Elasticsearch 的默认分发。请从 elastic.co 升级到 Elasticsearch 的默认发行版,或者降级到 beats 的 oss-only 发行版]

    步骤

    wgethttps://artifacts.elastic.co/downloads/beats/heartbeat/heartbeat-6.6.2-amd64.deb

    dpkg -i heartbeat-6.6.2-amd64.deb

    sudo 服务心跳-弹性重启

    现在日志显示它已成功连接到 ES

    2019-04-01T09:42:38.061Z INFO pipeline/output.go:105 连接到回退(elasticsearch(http://localhost:9200)) 建立

    【讨论】:

      【解决方案2】:

      如果您使用的是 Elasticsearch 的开源“OSS”发行版,那么所有连接的节拍也必须使用相应的“OSS”版本进行部署。使用 docker 镜像时,在镜像名称后面加上-oss 后缀,即可得到正确的镜像。对于来自弹性网站的基于文件的下载,请在版本号之前插入-oss,例如https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-oss-7.0.0-linux-x86_64.tar.gz

      【讨论】:

        猜你喜欢
        • 2018-08-24
        • 2020-08-29
        • 1970-01-01
        • 1970-01-01
        • 2018-05-10
        • 2023-01-16
        • 1970-01-01
        • 1970-01-01
        • 2020-10-02
        相关资源
        最近更新 更多