logstash收集springboot日志 maven依赖 <dependency> <groupId>net.logstash.logback</groupId> <artifactId>logstash-logback-encoder</artifactId> <version>5.1</version> </dependency> springboot 配置文件 logging: config: classpath:logback.xml logback.xml <?xml version="1.0" encoding="UTF-8"?> <configuration> <include resource="org/springframework/boot/logging/logback/base.xml" /> <!--======================================= 本地变量 ======================================== --> <!--在没有定义${LOG_HOME}系统变量的时候,可以设置此本地变量。提交测试、上线时,要将其注释掉,使用系统变量。 --> <property value="logs/spring.log" /> <!-- 应用名称:和统一配置中的项目代码保持一致(小写) --> <property value="log" /> <!--日志文件保留天数 --> <property value="30" /> <!--定义日志文件的存储地址 勿在 LogBack 的配置中使用相对路径 --> <!--应用日志文件保存路径 --> <property value="${APP_NAME}/%d{yyyy-MM-dd}" /> <!--=========================== 按照每天生成日志文件:默认配置=================================== --> <!-- 控制台输出 --> <appender> <encoder> <!--格式化输出:%d表示日期,%thread表示线程名,%-5level:级别从左显示5个字符宽度%msg:日志消息,%n是换行符 --> <pattern>%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] %-5level %logger{50} - %msg%n</pattern> </encoder> </appender> <!-- 按照每天生成日志文件:主项目日志 --> <appender> <rollingPolicy> <!--日志文件输出的文件名 --> <FileNamePattern>${LOG_APP_HOME}/base.%d{yyyy-MM-dd}.log </FileNamePattern> <!--日志文件保留天数 --> <MaxHistory>${LOG_MAX_HISTORY}</MaxHistory> </rollingPolicy> <encoder> <!--格式化输出:%d表示日期,%thread表示线程名,%-5level:级别从左显示5个字符宽度%msg:日志消息,%n是换行符 --> <pattern>%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] %-5level %logger{500} - %msg%n</pattern> </encoder> </appender> <!--=============================== 日志输出: 默认主业务日志 ====================================== --> <logger> <level value="WARN" /> </logger> <logger> <level value="WARN" /> </logger> <logger> <level value="WARN" /> </logger> <logger> <level value="WARN" /> </logger> <logger> <level value="DEBUG" /> </logger> <logger> <level value="DEBUG" /> </logger> <logger> <level value="DEBUG" /> </logger> <logger> <level value="DEBUG,INFO" /> </logger> <!-- 这里是你的业务的包名 --> <logger> <level value="DEBUG" /> </logger> <!-- logstash ip和暴露的端口,我目前理解就是通过这个地址把日志发送过去 --> <appender> <!-- 和logstash 的input 配置的端口保持一致 --> <destination>localhost:4567</destination> <encoder charset="UTF-8" /> </appender> <root level="warn,info,debug"> <appender-ref ref="APP" /> <appender-ref ref="STDOUT" /> <appender-ref ref="LOGSTASH" /> <appender-ref ref="CONSOLE" /> </root> </configuration> logstash
springboot-log.conf
# 文档 # https://www.elastic.co/guide/en/logstash/5.6/input-plugins.html # https://www.elastic.co/guide/en/logstash/6.1/input-plugins.html input{ tcp { mode => "server" host => "0.0.0.0" port => 4567 codec => json_lines } } output{ # 为了模拟测试就先不放es了,在控制台输出测试看看 #elasticsearch{ # hosts=>["127.0.0.1:9200"] # index => "springboot-elk-%{+YYYY.MM.dd}" #} stdout{ codec => rubydebug } } 测试接口 import java.time.LocalDateTime; import java.time.format.DateTimeFormatter; import javax.servlet.http.HttpServletRequest; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; import org.springframework.web.context.request.RequestContextHolder; import org.springframework.web.context.request.ServletRequestAttributes; @RestController public class ApiTests { protected final static Logger log = LoggerFactory.getLogger(ApiTests.class); @GetMapping("/api/log") public Object log() { ServletRequestAttributes requestAttributes = (ServletRequestAttributes)RequestContextHolder.getRequestAttributes(); HttpServletRequest request = requestAttributes.getRequest(); String ip = request.getRemoteAddr(); String uri = request.getRequestURI(); String logStr = String.format("IP=[%s] send request URI = [%s]", ip, uri); log.debug("[debug] "+logStr); log.info("[info] "+logStr); log.warn("[warn] "+logStr); log.error("[error] "+logStr); return "ok : "+ LocalDateTime.now().format(DateTimeFormatter.ofPattern("yyyy-MM-dd HH:mm:ss")); } } 测试效果先运行logstash
# linux: bin/logstash -f config/springboot-log.conf # windows: bin\logstash.bat -f config/springboot-log.conf在运行springboot项目,然后调用测试接口::8080/api/log