Fluentd
Search…
0.12
Powered By GitBook
Recipe Syslog To Elasticsearch
Looking to get data out of syslog into elasticsearch? You can do that with fluentd in 10 minutes!
Here is how:
1
$ gem install fluentd
2
$ gem install fluent-plugin-elasticsearch
3
$ touch fluentd.conf
Copied!
fluentd.conf should look like this (just copy and paste this into fluentd.conf):
1
<source>
2
@type syslog
3
port 5140
4
bind 0.0.0.0
5
tag system.local
6
</source>
7
8
<match **>
9
@type elasticsearch
10
logstash_format true
11
host <hostname> #(optional; default="localhost")
12
port <port> #(optional; default=9200)
13
index_name <index name> #(optional; default=fluentd)
14
type_name <type name> #(optional; default=fluentd)
15
</match>
Copied!
After that, you can start fluentd and everything should work:
1
$ fluentd -c fluentd.conf
Copied!
Of course, this is just a quick example. If you are thinking of running fluentd in production, consider using td-agent, the enterprise version of Fluentd packaged and maintained by Treasure Data, Inc..
If this article is incorrect or outdated, or omits critical information, please let us know. Fluentd is a open source project under Cloud Native Computing Foundation (CNCF). All components are available under the Apache 2 License.
Last modified 2yr ago
Copy link