***elk安装需要2g内存***
1、logstash下载:https://www.elastic.co/cn/downloads/past-releases/
2、解压到:/usr/local/
3、进入/usr/local/logstash-6.3.1/config/
4、在/usr/local/logstash-6.3.1/config目录下新增一个文件
logstash01.conf
5、启动(Logstash启动有点慢): ./bin/logstash -f ./config/logstash01.conf
后台启动:nohup ./bin/logstash -f ./config/logstash02 &
如下图,收集到json日志说明启动成功: