

¾È³çÇϼ¼¿ä. ÁÖ½Äȸ»ç ¼¹ö¸ó ÀÔ´Ï´Ù.
¿À´ÃÀº RSYSLOG ¼¹ö¸¦ ±¸ÃàÇÏ°í µµÄ¿ ÄÁÅ×À̳ʷΠ±¸¼ºÇÑ
ELK¸¦ ÀÌ¿ëÇÏ¿© RSYSLOG µ¥ÀÌÅ͸¦ ½Ã°¢ÈÇÏ´Â ¹æ¹ýÀ» ¾Ë¾Æº¸°Ú½À´Ï´Ù.
±¸¼º ȯ°æ
ÇöÀç ´Ù¸¥ ¼¹ö·ÎºÎÅÍ RSYSLOG µ¥ÀÌÅ͸¦ ¹Þ°í ÀÖ½À´Ï´Ù.
docker compose¸¦ »ç¿ëÇÏ¿© ELK Stack ±¸¼º ÇÕ´Ï´Ù.
rsyslog¸¦ ÅëÇØ Àü¼ÛµÈ ·Î±×¸¦ Logstash°¡ ¼ö½ÅÇϰí,
¼ö½ÅÇÑ ·Î±×¸¦ Elasticsearch¿¡ ÀúÀåÇÑ ÈÄ Kibana¿¡¼ ½Ã°¢È ÇÕ´Ï´Ù.
DockerÀÇ ³»¿ëÀ» ÀÛ¼ºÇÑ °Ô½Ã±ÛÀº ¾Æ·¡ ¸µÅ©¸¦ ÅëÇØ È®ÀÎ °¡´ÉÇÕ´Ï´Ù.
https://servermon.tistory.com/255
[Linux] µµÄ¿ Docker °³³ä ¹× ±¸¼º ¹æ¹ý
¾È³çÇϼ¼¿ä. ÁÖ½Äȸ»ç ¼¹ö¸ó ÀÔ´Ï´Ù. ¿À´ÃÀº Docker ¿¡ ´ëÇØ ¾Ë¾Æ º¸µµ·Ï ÇϰڽÀ´Ï´Ù. Docker¶õ ¾ÖÇø®ÄÉÀ̼ÇÀ» ½Å¼ÓÇÏ°Ô ±¸Ãà, Å×½ºÆ® ¹× ¹èÆ÷ÇÒ ¼ö ÀÖ´Â ¼ÒÇÁÆ®¿þ¾î Ç÷§ÆûÀÔ´Ï´Ù. Docker´Â ¼ÒÇÁÆ®
servermon.tistory.com
RsyslogÀÇ ³»¿ëÀ» ÀÛ¼ºÇÑ °Ô½Ã±ÛÀº ¾Æ·¡ ¸µÅ©¸¦ ÅëÇØ È®ÀÎ °¡´ÉÇÕ´Ï´Ù.
https://servermon.tistory.com/535
[Linux] ¿ø°Ý ½Ã½ºÅÛ ·Î±× Rsyslog ±¸¼º
¾È³çÇϼ¼¿ä. ÁÖ½Äȸ»ç ¼¹ö¸ó ÀÔ´Ï´Ù. ±Ý¹ø Æ÷½ºÆÃÀº Rsyslog¸¦ »ç¿ëÇÑ ¿ø°Ý ·Î±ë ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀÌÇØ¿Í ±¸ÃàÀ» ÁøÇà Çϵµ·Ï ÇϰڽÀ´Ï´Ù. ·Î±×¶õ? ·Î±×´Â ¸ðµç ¼ÒÇÁÆ®¿þ¾î ¹× ¿î¿µÃ¼Á¦¿¡ Áß¿äÇÑ
servermon.tistory.com
ELK Stack ¶õ?
ELK StackÀº ·Î±× µ¥ÀÌÅ͸¦ ¼öÁý, ÀúÀå, ºÐ¼®, ½Ã°¢ÈÇϱâ À§ÇÑ µµ±¸
Elasticsearch
ºÐ»ê °Ë»ö ¹× ºÐ¼® ¿£ÁøÀ¸·Î, ·Î±× µ¥ÀÌÅ͸¦ ÀúÀåÇÏ°í °Ë»öÇÕ´Ï´Ù.
Logstash
µ¥ÀÌÅÍ Ã³¸® ÆÄÀÌÇÁ¶óÀÎÀ¸·Î, ´Ù¾çÇÑ ¼Ò½º¿¡¼ µ¥ÀÌÅ͸¦ ¼öÁýÇϰí
º¯È¯ÇÏ¿© Elasticsearch¿¡ Àü¼ÛÇÕ´Ï´Ù.
Kibana
Elasticsearch¿¡ ÀúÀåµÈ µ¥ÀÌÅ͸¦ ½Ã°¢ÈÇϰí
Ž»öÇÒ ¼ö ÀÖ´Â À¥ ÀÎÅÍÆäÀ̽ºÀÔ´Ï´Ù.
Docker, Rsyslog ¼³Ä¡ ¹× ½ÇÇà
dnf -y config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo
dnf -y install docker-ce docker-ce-cli containerd.io
dnf -y install rsyslog
dnf -y install docker-compose-plugin
git clone https://github.com/deviantony/docker-elk.git
systemctl start docker
systemctl enable docker
systemctl start rsyslog
systemctl enable rsyslog
¹æÈº® ¼³Á¤
firewall-cmd --permanent --zone=public --add-port=514/tcp
firewall-cmd --permanent --zone=public --add-port=514/udp
firewall-cmd --permanent --zone=public --add-port=9200/tcp
firewall-cmd --permanent --zone=public --add-port=5601/tcp
firewall-cmd --permanent --zone=public --add-port=5044/tcp
firewall-cmd --reload
firewall-cmd --list-ports
rsyslog ÆÄÀÏ ¼³Á¤
vim /etc/rsyslog.conf
*.* @@127.0.0.1:5044
systemctl restart rsyslog

ELK ¼³Á¤
logstash ¼³Á¤
vim /opt/docker-elk/logstash/pipeline/logstash.conf
input {
tcp {
port => 5044
type => "rsyslog"
}
}
filter { }
output {
elasticsearch {
hosts => ["elasticsearch:9200"]
index => "rsyslog-%{+YYYY.MM.dd}"
}
}

Docker compose ½ÇÇà
docker-compose up -d
-d : ¹é±×¶ó¿îµå¿¡¼ ½ÇÇà
-t : ÄÁÅ×ÀÌ³Ê Å¸ÀӾƿô½Ã°£ ¼³Á¤
--no-deps : ¸µÅ©µÈ ¼ºñ½º´Â ½ÇÇàÇÏÁö ¾ÊÀ½
--no-build : À̹ÌÁö¸¦ ºôµåÇÏÁö ¾ÊÀ½
up : ÄÁÅ×À̳ʸ¦ »ý¼º ¹× ½ÇÇà
ps : ÄÁÅ×ÀÌ³Ê ¸ñ·Ï È®ÀÎ
logs : ÄÁÅ×ÀÌ³Ê ·Î±× Ãâ·Â
start : ÄÁÅ×À̳ʸ¦ ½ÇÇà
stop : ÄÁÅ×À̳ʸ¦ ÁßÁö
restart : ÄÁÅ×À̳ʸ¦ Àç½ÃÀÛ
kill : ½ÇÇàÁßÀÎ ÄÁÅ×À̳ʸ¦ °Á¦ Á¾·á
rm : ÄÁÅ×ÀÌ³Ê »èÁ¦

elasticsearch Ŭ·¯½ºÅÍ ½ÇÇà È®ÀÎ
À¥ ºê¶ó¿ìÀú -> http://localhost:9200 Á¢¼Ó

kibana ·Î±× µ¥ÀÌÅÍ ½Ã°¢È ¼³Á¤
kibana Á¢¼Ó
À¥ ºê¶ó¿ìÀú -> http://localhost:5601

index patterns µî·Ï
(µ¥ÀÌÅÍ ½Ã°¢È¸¦ À§ÇÑ ·Î±× µ¥ÀÌÅÍ ÆÐÅÏ µî·Ï)
Stack Management -> Data views -> Create data view
index pattern À» ¼öÁýÁßÀÎ ·Î±× ÆÄÀÏ¸í¿¡ ¸ÂÃç ÆÐÅÏ ¼³Á¤

·Î±× µ¥ÀÌÅÍ È®ÀÎ ¹× Field ±¸¼º
Discover¿¡ µé¾î°¡¸é ¼öÁýÇÑ ·Î±× ¸ñ·Ï È®ÀÎ °¡´ÉÇÕ´Ï´Ù.
Discover -> Data view¸¦ »ý¼ºÇÑ rsyslog·Î º¯°æ
field °ªÀÇ ·Î±× µ¥ÀÌÅÍ È®ÀÎ

µ¥ÀÌÅÍ ½Ã°¢È
Visualize Library¿¡¼ Field¸¦ Ãß°¡ÇÏ¿© ±×·¡ÇÁ¿Í Â÷Æ®¸¦ »ý¼ºÇÏ¿©
·Î±× µ¥ÀÌÅ͸¦ ½Ã°¢ÈÇÒ ¼ö ÀÖ½À´Ï´Ù.

Visualize Library¿¡¼ »ý¼ºÇÑ ±×·¡ÇÁ,Â÷Æ®´Â Dashboards¿¡¼ È®ÀÎ °¡´ÉÇÕ´Ï´Ù.
°¨»çÇÕ´Ï´Ù.

1U¼¹ö / 2U¼¹ö / AI¼¹ö / alyac / APC / APC UPS / backup / carepack / centos / chakramax / cuda / DAS / DB / DB¼¹ö / defog / DEFOG·¢ / dell5820 / dell5820t / dell7920 / dellpoweredge / dellr240 / dellr340 / dellr350 / dellr450 / dellr540 / dellr630 / dellr640 / dellr740 / dellr750 / dellserver / dellt40 / dellt440 / dellt5820 / dell¼¹ö / DELL¼¹öCPU / DELL¼¹öRAIDÄÁÆ®·Ñ·¯ / DELL¼¹öSASÇϵåµð½ºÅ© / DELL¼¹ö°¡°Ýºñ±³ / DELL¼¹ö°¡°Ýºñ±³°ßÀû / DELL¼¹ö°ßÀû / DELL¼¹ö±¸¸Å / DELL¼¹öµð½ºÅ©±³Ã¼ / DELL¼¹ö¸Þ¸ð¸® / dell¼¹ö¼¹ö¸ó / DELL¼¹öÆß¿þ¾î / DELL¼¹öÇϵåµð½ºÅ©±¸¸Å / dell¿É¼Ç / dell¿öÅ©½ºÅ×ÀÌ¼Ç / dl20 / dl20gen10 / dl20gen11 / dl360 / dl360gen10 / dl360gen11 / dl380 / dl380g10 / dl380gen10 / dl380gen11 / ECC¸Þ¸ð¸® / EDFOG·¢°¡°Ý / embedded / est security / ESTSOFT / FIRMWARE / GPU / gpu¼¹ö / gpuŸ¿öÇü¼¹ö / greenlake / HA¼Ö·ç¼Ç / HP GPU / hp hdd / hpdl20 / HPDL20Gen10 / hpdl360 / hpdl360gen10 / hpdl380 / hpdl380g10 / HPDL380Gen10 / HPE / HPE GPU / hpe hdd / hpe rok / HPE Service Pack for Proliant / HPE SPP / hpe ssa / hpedl20 / hpedl20gen10 / hpedl360gen10 / hpe¼¹ö / HPE¼¹öCPU / HPE¼¹öRAIDÄÁÆ®·Ñ·¯ / HPE¼¹öSASÇϵåµð½ºÅ© / HPE¼¹ö°¡°Ýºñ±³ / HPE¼¹ö°¡°Ýºñ±³°ßÀû / HPE¼¹ö°ßÀû / HPE¼¹ö±¸¸Å / HPE¼¹öµå¶óÀ̹ö¼³Ä¡ / HPE¼¹öµð½ºÅ©±³Ã¼ / HPE¼¹ö¸Þ¸ð¸® / HPE¼¹öºñ¿ë / hpe¼¹ö¼ÒÀ½ / HPE¼¹öÆß¿þ¾î / HPE¼¹öÇϵåµð½ºÅ©±¸¸Å / hpe¿É¼Ç / hpeÁ¤Ç° / hpgen10 / hpml30 / hpserver / hpz2 / hpz4 / hpz4g4 / hpz6g4 / hpz8g4 / hp¸¶ÀÌÅ©·Î¼¹ö / hp¼¹ö / hp¼¹öcto / hp¼¹öpc / HP¼¹ö¸Þ¸ð¸® / hp¼¹ö¼ÒÀ½ / hp¼¹öÄÄÇ»ÅÍ / HP¼¹öÆÄ¿ö / HP¼¹öÆß¿þ¾î / HP¼¹öÇϵåµð½ºÅ© / hp¿É¼Ç / hp¿öÅ©½ºÅ×ÀÌ¼Ç / hpÁ¤Ç° / hpÇÁ·Î¶óÀÌ¾ðÆ® / HYPER BACKUP / ibm¼¹ö / ilo / Intelligent Provisioning / internetdisk / KVM / KVM ±â¼úÁö¿øºñ(ºñ¿ë) / KVM ¼³Ä¡ºñ / L2½ºÀ§Ä¡ / L3½ºÀ§Ä¡ / LENONO¼¹öSASÇϵåµð½ºÅ© / lenovop620 / lenovor650 / LENOVO¼¹ö / LENOVO¼¹öCPU / LENOVO¼¹öRAIDÄÁÆ®·Ñ·¯ / LENOVO¼¹ö°¡°Ýºñ±³ / LENOVO¼¹ö°¡°Ýºñ±³°ßÀû / LENOVO¼¹ö°ßÀû / LENOVO¼¹ö±¸¸Å / LENOVO¼¹öµð½ºÅ©±³Ã¼ / LENOVO¼¹ö¸Þ¸ð¸® / LENOVO¼¹öÇϵåµð½ºÅ©±¸¸Å / LENOVOÆß¿þ¾î¾÷µ¥ÀÌÆ® / Linux / ML30 / ml30gen10 / ml30gen11 / ML350GEN10 / ml350gen11 / ML360 / MS CSP / MSSQL / MSSQL ±â¼úÁö¿øºñ(ºñ¿ë) / MSSQL ¼³Ä¡ºñ / MYSQL / MySQL ±â¼úÁö¿øºñ(ºñ¿ë) / MySQL ¼³Ä¡ºñ / NAS / NVIDIA / Office 365 / oneview / orange / OS¼³Ä¡ / PA-410 / PA-440 / paloalto / poweredger740 / poweredger750 / precision5820 / QUADRO / r240 / r250 / r340 / r360 / r440 / r550 / r650 / r660 / r740 / r750xs / r760 / r760xs / RAID / redhat / RHEL¼³Ä¡ / RMS·¢ / rocky / s100i / securedisk / server / serverpc / smart storage administrator / SPP / sql server / sr250 / sr650 / SYNOLOGY / SYNOLOGY³ª½º / t150 / t360 / UPS / UPS±â¼úÁö¿ø / UPS³³Ç° / UPS¼³Ä¡ / V3 / veeam / vroc / windows server / Windows¼¹ö¼³Ä¡ / XEON¼¹ö / z8g4 / °¡»ó¼¹ö / °¡¼ººñ¼¹ö / ±â¼úÁö¿øºñ(ºñ¿ë) / ³ª½º±â¼úÁö¿ø / ³ª½º¼³Ä¡Áö¿ø / ³×Æ®¿öÅ©½ºÀ§Ä¡ / ³×Æ®¿öÅ©Àåºñ / ´õºíÅ×ÀÌÅ© / µ¥ÀÌÅͺ£À̽º / µ¨5820 / µ¨¼¹ö / µ¨¼¹öºñ¿ë / µ¨¼¹öÆß¿þ¾î¾÷µ¥ÀÌÆ® / µ¨¿É¼Ç / µ¨¿öÅ©½ºÅ×ÀÌ¼Ç / µ¨ÄÄÇ»ÅÍ¿öÅ©½ºÅ×ÀÌ¼Ç / µðÆ÷±× / µðÆ÷±×·¢ / µðÆ÷±×·¢°¡°Ý / µö·¯´× / µö·¯´×pc / µö·¯´×¼¹ö / ·¢ / ·¢(RACK) ±â¼úÁö¿øºñ(ºñ¿ë) / ·¢(RACK) ¼³Ä¡ºñ / ·¢³³Ç°¼³Ä¡ / ·¢¼³Ä¡ / ·¹³ë¹öp620 / ·¹³ë¹ö¼¹ö / ·¹³ë¹ö¿öÅ©½ºÅ×ÀÌ¼Ç / ·¹³ëº¸¼¹ö / ·¹³ëº¸¼¹öÆß¿þ¾î / ·¹µåÇò¼³Ä¡ / ·¹À̵å / ·¹À̵屸¼º / ·Ï۸®´ª½º / ¸®´ª½º / ¸®´ª½º ±â¼úÁö¿øºñ(ºñ¿ë) / ¸®´ª½º ¼³Ä¡ºñ / ¸®´ª½º¼¹ö / ¸®´ª½º¼¹ö¼³Ä¡ / ¸®´ª½º¼¹öÆ®·¯ºí½´ÆÃ / ¸®´ª½ºÆ®·¯ºí½´ÆÃ / ¹®¼º¸¾È / ¹®¼Áß¾ÓÈ / ¹Ì´Ï¼¹ö / ¹Ì´Ï¼¹ö·¢ / ¹Ì´Ï¼¹ö·º / ¹Ìµð¾î¼¹ö / ¹æÈº® / ¹æÈº® ±â¼úÁö¿øºñ(ºñ¿ë) / ¹æÈº® ¼³Ä¡ºñ / ¹æÈº®¿£Áö´Ï¾î / ¹é¾÷ / ¹é¾÷ ±â¼úÁö¿øºñ(ºñ¿ë) / ¹é¾÷ ¼¹ö / ¹é¾÷¼ºñ½º / ¹é¾÷¼Ö·ç¼Ç / º¸¾È¼Ö·ç¼Ç / º¸¾È¼Ö·ç¼Ç±¸¸Å / º¸¾È¼Ö·ç¼Ç¼³Ä¡ / º¸¾ÈÅø / ºö¹é¾÷ / »þÅ©¶ó¸Æ½º / ¼¹ö / ¼¹ö ±â¼úÁö¿øºñ(ºñ¿ë) / ¼ ¹ö ·¢¸¶¿îÆ®ºñ¿ë / ¼¹ö ¼³Ä¡ºñ / ¼¹ö Àå¾ÖÁ¶Ä¡ºñ¿ë / ¼¹öCPU / ¼¹öMEMORY / ¼¹öOS¼³Ä¡ / ¼¹öpc / ¼¹ö°¡°Ý / ¼¹ö°¡¼Ó±â / ¼¹ö°ßÀû / ¼¹ö±³Ã¼ / ¼¹ö±¸¸Å / ¼¹ö±¸ÀÔ / ¼¹ö±¸Ãà / ¼¹ö±â¼úÁö¿ø / ¼¹ö³³Ç° / ¼¹öµð½ºÅ©Àå¾Öó¸® / ¼¹ö·¢ / ¼¹ö·º / ¼¹ö·º¸¶¿îÆ® / ¼¹ö¸Þ¸ð¸® / ¼¹ö ¸ó / ¼¹ö¸ó±â¼úÁö¿ø / ¼¹ö¹é¾÷ / ¼¹öº¸¾È / ¼¹öºÎǰ / ¼¹ö¿£Áö´Ï¾î / ¼¹ö¿É¼Ç / ¼¹ö¿ëGPU / ¼¹ö¿ëPC / ¼¹ö¿ë±×·¡ÇÈÄ«µå / ¼¹ö¿ë¸Þ¸ð¸® / ¼¹ö / ÄÄÇ»ÅÍ / ¼¹ö¿ëÇϵåµð½ºÅ© / ¼¹öÀç°í / ¼¹öÄÄ / ¼¹öÄÄÇ»ÅÍ / ¼¹öÆ®·¯ºí½´ÆÃ / ¼¹öÆÇ¸Å / ¼¹öÇϵå / ¼¹öÈ£½ºÆÃ / ½ºÀ§Ä¡ / ½ºÀ§Ä¡ ±â¼úÁö¿øºñ(ºñ¿ë) / ½ºÀ§Ä¡ ¼³Ä¡ºñ / ½ºÅ丮Áö / ½ºÅ丮Áö ±â¼úÁö¿øºñ(ºñ¿ë) / ½ºÅ丮Áö ·¢¸¶¿îÆ®ºñ¿ë / ½ºÅ丮Áö ¼³Ä¡ºñ / ½ºÅ丮Áö Àå¾ÖÁ¶Ä¡ºñ¿ë / ½ºÅ丮Áö³³Ç°¼³Ä¡ / ½ºÅ丮Áö¼¹ö / ½Ã³î·ÎÁöDS918 / ½Ã³î·ÎÁöHyperBackup / ½Ã³î·ÎÁö³ª½º / ½Ã³î·ÎÁö³ª½º¹é¾÷ / ½Ã³î·ÎÁöÇÏÀÌÆÛ¹é¾÷ / ½ÃÅ¥¾îµð½ºÅ© / ¾È·¦ / ¾Ë¾à / ¾Û¼¹ö / ¿ÀÇǽº 365 / ¿ìºÐÅõ¼³Ä¡ / ¿öÅ©½ºÅ×ÀÌ¼Ç / ¿öÅ©½ºÅ×À̼Çpc / ¿öÅ©½ºÅ×À̼ÇÄÄÇ»ÅÍ / À©µµ¿ì¼¹ö / À©µµ¿ì¼¹ö2016 / À©µµ¿ì¼¹ö2019 / À©µµ¿ì¼¹ö2022 / À©µµ¿ì¼¹ö¼³Ä¡ / À©µµ¿ì¼¹öÄÄÇ»ÅÍ / À©µµ¿ì¼¹öÆ®·¯ºí½´ÆÃ / À©µµ¿ìÁî ±â¼úÁö¿øºñ(ºñ¿ë) / À©µµ¿ìÁî ¼³Ä¡ºñ / À̽ºÆ®¼ÒÇÁÆ® / À̽ºÆ® ½ÃÅ¥¸®Æ¼ / ÀÌÁßȼַç¼Ç / ÀÌÁßȼַç¼Ç±¸¸Å / ÀÌÁßȼַç¼Ç¼³Ä¡ / ÀÎÅͳݵð½ºÅ© / ÀÓº£µðµå / Àú°¡¼¹ö / Àú·ÅÇѼ¹ö / Á¤Ç°¼¹ö / Á¤Ç°¼¹ö¿É¼Ç / Á¦¿Â¼¹ö / Á¨¼¹ö / Áß°í¼¹ö / Áß°í¿öÅ©½ºÅ×ÀÌ¼Ç / Ä«º¸³ªÀÌÆ® / Ä«½ºÆÛ½ºÅ° / ÄÄÇ»Åͼ¹ö / ÄɾîÆÑ / Ÿ¿ö¼¹ö / Ÿ¿öÇü¼¹ö / ÆÈ·Î¾ËÅä / Æäµµ¶ó¼³Ä¡ / ÇÁ·Î¶óÀ̾ðÆ®