Skip to content

Instalasi ELK Stack

Rahmat Agung Wibowo edited this page Mar 11, 2019 · 1 revision

ELK Stack dipasang disisi server pengumpul. ELK Stack terdiri dari 3 komponen, yaitu: Elasticsearch : menyimpan log Logstash : menerima log dari Filebeat dan memproses log. Kibana : Visualisasi log.

Penambahan repository

sudo apt-get install default-jre
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/6.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-6.x.list
sudo apt-get update

Instalasi Elasticsearch

sudo apt-get install elasticsearch
sudo nano /etc/elasticsearch/elasticsearch.yml
	network.host: "alamat_server_pengumpul"
	http.port:9200
sudo systemctl restart elasticsearch
sudo systemctl daemon-reload
sudo systemctl enable elasticsearch

Instalasi Kibana

sudo apt install kibana
sudo nano/etc/kibana/kibana.yml
	server.port: 5601
	server.host: 10.33.109.76
	elasticsearch.url: "http://alamatip_elasticsearch:9200"
sudo systemctl daemon-reload
sudo systemctl enable kibana
sudo systemctl start kibana

Instalasi Logstash

sudo apt install logstash

Lalu, membuat file konfigurasi di direktori /etc/logstash/conf.d/.

sudo nano /etc/logstash/conf.d/beats-conf.conf