?¹¤ÒµÂ·ÓÉÆ÷ÈÕÖ¾ÅŲéÔõô¿´£¿
Ò»¡¢¹¤ÒµÂ·ÓÉÆ÷ÈÕÖ¾ÓÐÄÄЩ·ÖÀࣿ
²É¼¯ÈÕÖ¾
²É¼¯ÈÕÖ¾Êǹ¤ÒµÂ·ÓÉÆ÷¼Ç¼É豸Êý¾Ý²É¼¯¹ý³ÌµÄÖØÒªÎļþ¡£ËüÏêϸ¼Ç¼ÁËÿ´ÎÊý¾Ý²É¼¯µÄʱ¼ä¡¢É豸ID¡¢Êý¾ÝÀàÐÍ¡¢Êý¾ÝÁ¿ÒÔ¼°²É¼¯×´Ì¬µÈÐÅÏ¢¡£µ±Êý¾ÝÖÊÁ¿³öÏÖÎÊÌ⣬ÈçÊý¾Ý¶ªÊ§¡¢´íÎó»òÑÓ³Ùʱ£¬²É¼¯ÈÕÖ¾³ÉΪÅŲéÎÊÌâµÄÊ×ÒªÒÀ¾Ý¡£
רҵ¼¼ÇÉ£º
ÈÕÖ¾µÈ¼¶µ÷Õû£ºÔÚÍø¹ØµÄÅäÖýçÃæÖУ¬½«²É¼¯ÈÕÖ¾µÈ¼¶ÉèÖÃΪ¡°µ÷ÊÔ¡±Ä£Ê½£¬¿ÉÒÔ»ñÈ¡×îÏêϸµÄÈÕÖ¾ÐÅÏ¢¡£ÕâÓÐÖúÓÚ²¶×½Êý¾Ý²É¼¯¹ý³ÌÖеÄÿһ¸öϸ½Ú£¬´Ó¶ø¾«×¼¶¨Î»ÎÊÌâËùÔÚ¡£
ÈÕÖ¾·ÖÎö£ºÀûÓÃרҵµÄÈÕÖ¾·ÖÎö¹¤¾ß£¨ÈçLogstash¡¢SplunkµÈ£©¶Ô²É¼¯ÈÕÖ¾½øÐнâÎöºÍ¹ýÂË£¬¿ìËÙɸѡ³öÒì³£Êý¾Ý»ò´íÎóʼþ¡£
ÈÕÖ¾¹éµµ£º¶¨ÆÚ½«²É¼¯ÈÕÖ¾¹éµµ±£´æ£¬ÒÔ±ãºóÐø·ÖÎöºÍ¶Ô±È£¬ÎªÊý¾ÝÖÊÁ¿µÄ³ÖÐøÓÅ»¯ÌṩÒÀ¾Ý¡£
ÔÆ½ÓÈëÈÕÖ¾
ÔÆ½ÓÈëÈÕÖ¾¼Ç¼Á˹¤ÒµÂ·ÓÉÆ÷ÓëÔÆÆ½Ì¨Ö®¼äµÄͨÐŹý³Ì£¬°üÀ¨ÇëÇó¡¢ÏìÓ¦¡¢×´Ì¬ÂëºÍ´íÎóÐÅÏ¢¡£µ±ÔÆÆ½Ì¨Êý¾ÝÒì³£»òͨÐÅͨµÀ¹ÊÕÏʱ£¬ÔƽÓÈëÈÕÖ¾³ÉΪÅŲéÎÊÌâµÄ¹Ø¼ü¡£
רҵ¼¼ÇÉ£º
ÈÕÖ¾²¶»ñ£ºÔÚÍø¹ØÅäÖÃÖÐÆôÓÃÔÆ½ÓÈëÈÕÖ¾µÄ¡°µ÷ÊÔ¡±Ä£Ê½£¬È·±£Ã¿´ÎͨÐŶ¼±»Ïêϸ¼Ç¼¡£
ͨÐÅÐÒé·ÖÎö£º¸ù¾ÝʹÓõÄͨÐÅÐÒ飨ÈçMQTT¡¢HTTPµÈ£©£¬ÀûÓÃÐÒé·ÖÎö¹¤¾ß£¨ÈçWireshark£©¶ÔÔÆ½ÓÈëÈÕÖ¾½øÐнâÎö£¬²é¿´ÇëÇóºÍÏìÓ¦µÄ¾ßÌåÄÚÈÝ£¬ÒÔ¼°ÊÇ·ñ´æÔÚÐÒé´íÎó¡£
´íÎóÂë¶ÔÕÕ£º¸ù¾ÝÔÆÆ½Ì¨ÌṩµÄ´íÎóÂë¶ÔÕÕ±í£¬¿ìËÙ¶¨Î»ÔƽÓÈëÈÕÖ¾ÖеĴíÎóÔÒò£¬²¢²ÉÈ¡ÏàÓ¦µÄ½â¾ö´ëÊ©¡£
ϵͳÈÕÖ¾
ϵͳÈÕÖ¾¼Ç¼Á˹¤ÒµÂ·ÓÉÆ÷µÄϵͳÆô¶¯¡¢½ø³Ì¹ÜÀí¡¢ÍøÂç״̬¡¢Òì³£±¨´íµÈ¹Ø¼üÐÅÏ¢¡£µ±ÏµÍ³³öÏÖÒì³£»òÍøÂç²»Îȶ¨Ê±£¬ÏµÍ³ÈÕÖ¾³ÉΪÅŲéÎÊÌâµÄ±¦¹ó×ÊÔ´¡£
רҵ¼¼ÇÉ£º
ʵʱ¼à¿Ø£ºÀûÓÃϵͳÈÕÖ¾µÄʵʱ¼à¿Ø¹¦ÄÜ£¬¼°Ê±·¢ÏÖ²¢´¦ÀíϵͳÒì³£¡£
ÈÕÖ¾¹ýÂË£º¸ù¾ÝϵͳÈÕÖ¾µÄ¹Ø¼ü´Ê»òʱ¼ä·¶Î§½øÐйýÂË£¬¿ìËÙ¶¨Î»ÎÊÌâ·¢ÉúµÄ¾ßÌåʱ¼äºÍÉÏÏÂÎÄ¡£
ÈÕÖ¾µ¼³ö£º½«ÏµÍ³ÈÕÖ¾µ¼³öΪÎı¾»òCSV¸ñʽ£¬±ãÓÚºóÐø·ÖÎöºÍ±¨¸æ×«Ð´¡£
¶þ¡¢ÈÕÖ¾Êä³öÓëµ¼³ö
²É¼¯ÈÕÖ¾µÄÊä³öÓëµ¼³ö
Ô¶³Ì·ÃÎÊ£ºÍ¨¹ýSSH»òÔ¶³Ì×ÀÃæÐÒ飨RDP£©Á¬½Óµ½¹¤ÒµÂ·ÓÉÆ÷£¬Ö±½ÓÔÚÃüÁîÐнçÃæ»ò¹ÜÀí½çÃæÖв鿴ºÍµ¼³ö²É¼¯ÈÕÖ¾¡£
ÈÕÖ¾¹ÜÀí¹¤¾ß£ºÊ¹ÓÃÈÕÖ¾¹ÜÀí¹¤¾ß£¨ÈçGraylog¡¢ELK StackµÈ£©¶Ô²É¼¯ÈÕÖ¾½øÐм¯ÖйÜÀíºÍµ¼³ö¡£ÕâЩ¹¤¾ßÖ§³Ö¶àÖÖÈÕÖ¾¸ñʽºÍÐÒ飬Äܹ»×Ô¶¯ÊÕ¼¯¡¢½âÎöºÍ´æ´¢ÈÕÖ¾Êý¾Ý¡£
ÔÆ½ÓÈëÈÕÖ¾µÄÊä³öÓëµ¼³ö
ÔÆÆ½Ì¨½Ó¿Ú£º²¿·ÖÔÆÆ½Ì¨ÌṩÁËÈÕÖ¾²éѯºÍµ¼³ö½Ó¿Ú£¬¿ÉÒÔͨ¹ýAPIµ÷ÓûñÈ¡ÔÆ½ÓÈëÈÕÖ¾¡£
ÈÕÖ¾´úÀí£ºÔÚÍø¹ØÉϲ¿ÊðÈÕÖ¾´úÀí£¨ÈçFluentd¡¢rsyslogµÈ£©£¬½«ÔƽÓÈëÈÕ־ת·¢µ½Ö¸¶¨µÄÈÕÖ¾·þÎñÆ÷»ò´æ´¢½éÖÊÖС£
ϵͳÈÕÖ¾µÄÊä³öÓëµ¼³ö
ϵͳÃüÁʹÓÃϵͳ×Ô´øµÄÈÕÖ¾²é¿´ÃüÁÈçtail¡¢grep¡¢awkµÈ£©²é¿´ºÍɸѡϵͳÈÕÖ¾¡£
ÈÕÖ¾Îļþ£ºÍ¨¹ýSSHµÈÔ¶³Ì·ÃÎÊ·½Ê½£¬Ö±½Ó·ÃÎʹ¤ÒµÂ·ÓÉÆ÷ÉϵÄϵͳÈÕÖ¾Îļþ£¨Èç/var/log/syslog¡¢/var/log/messagesµÈ£©£¬²¢½øÐи´ÖÆ»òµ¼³ö²Ù×÷¡£