我正在尝试按照本指南http://docs.fluentd.org/articles/free-alternative-to-splunk-by-fluentd了解如何设置流利,弹性搜索和kibana。我在Ubuntu 14.04上进行设置。当我尝试启动td-agent时,它会立即崩溃。 以下是关于崩溃的日志部分:
2015-10-01 21:47:21 +0000 [info]: listening fluent socket on 0.0.0.0:24224
2015-10-01 21:47:21 +0000 [info]: listening dRuby uri="druby://127.0.0.1:24230" object="Engine"
2015-10-01 21:47:21 +0000 [info]: listening fluent socket on 0.0.0.0:24224
2015-10-01 21:47:21 +0000 [error]: unexpected error error_class=Errno::EADDRINUSE error=#<Errno::EADDRINUSE: Address already in use - bind(2) for "0.0.0.0" port 24224>
答案 0 :(得分:1)
我发现了我的问题。在指南中,它表示要修改td-agent.conf,如下所示:
<source>
type syslog
port 42185
tag syslog
</source>
<source>
type forward
</source>
<match syslog.**>
type elasticsearch
logstash_format true
flush_interval 10s # for testing
</match>
但<source>type forward</source>
部分已在配置文件中