The problem is as follows:
1.FileBeat journal "Dial TCP 127.0.0.1:5544:connectex:no connection could be made because the target machine actively refused It
Resolution process:
A: Modify the Filebeat folder in the Filebeat.yml file, the direct output of the results to Elasticsearch, the test elasticsearch can view the data, to exclude filebeat problems
B: Console Enter the following, start the Logstash program to see if it can start successfully, the test Logstash cannot start, prompting the input control beats problems
C: The console continues to enter the plugin list, to see if there is a logstash-input-beats plugin in the list of plug-ins, the test logstash-1.5.4 does not have this plugin, you can download the plugin to install or download a later version. Here you use a later version of logstash-2.2.1 to reinstall the problem after the boot issue is resolved.
2.Elasticsearch received data in Chinese garbled problem solving
A:FILEBEAT.YML Add the following encoding format
b:logstash.conf Add the following encoding format
3.kibana No data received
Open the Kinaba service, right-click Properties-Login-Login status to add this account as a login account.
4. The problem solution for multi-line logs does not match
Using the multiline plugin for matching
Add a multiline matching rule in the Filebeat.yml configuration file that matches the pattern to whether it is the next row of data, where each line starts with "2017-12-07 13:00:26,795" format
5. The project name solution cannot be judged for different project analysis under the same host
Modify the Filebeat.yml file here, add additional information through fields, set the information as a top-level directory with the Fields_under_root:true property, and override the Fields property name
The results are as follows:
6. Added Fileds in Elasticsearch, unable to get the problem under terms when drawing Kibana
Sync issues, refresh Kibana settings settings to resolve
Summary of LOG4NET+FILEBEAT+ELK log Analysis system under Windows system