# Increase buffer when logs surge rapidly:
harvester_buffer_size: 128k
# Queue spool size should be at least twice expected burst size.
queue.spool.max_size_kb: 20480 # ~20 MB spool file per harvester.
⚠️ 痛点:过小导致溢出;老实说,过大则占用过多内存。怎么说呢,.
调整 Elasticsearch worker threads:
# In elasticsearch.yml per node:
threadpool.bulk.size:<%= number_of_cpu %>*4 # default is one per node
# In Filebeat output config:
output.elasticsearch.bulk_max_size_bytes : "16mb" # larger bulk reduces round trips.
output.elasticsearch.bulk_actions : "5000" # batch size.
⚠️ 痛点:worker 少时会出现 ack 延迟;过多时会耗尽节点线程,.
开启 TLS/SSL 加密,并使用压缩:
# Enable gzip compression to reduce bandwidth usage.
output.elasticsearch.compress:true
# Enable TLS if network crosses untrusted zones.
tls.enabled:true
tls.verification_mode:"full"
⚠️ 痛点:TLS 加密会增加 CPU 开销;压缩需验证兼容性,.
启用 Elastic Stack 的 Monitoring 模块:
# In filebeat.yml:
setup.monitor.enabled:true # requires connection to Elasticsearch.
# Kibana -> Stack Monitoring -> Beats section shows live throughput and latency.
# Also consider Metricbeat's System module for host-level metrics.
# Increase buffer when logs surge rapidly:
harvester_buffer_size: 128k
# Queue spool size should be at least twice expected burst size.
queue.spool.max_size_kb: 20480 # ~20 MB spool file per harvester.
⚠️ 痛点:过小导致溢出;老实说,过大则占用过多内存。怎么说呢,.
调整 Elasticsearch worker threads:
# In elasticsearch.yml per node:
threadpool.bulk.size:<%= number_of_cpu %>*4 # default is one per node
# In Filebeat output config:
output.elasticsearch.bulk_max_size_bytes : "16mb" # larger bulk reduces round trips.
output.elasticsearch.bulk_actions : "5000" # batch size.
⚠️ 痛点:worker 少时会出现 ack 延迟;过多时会耗尽节点线程,.
开启 TLS/SSL 加密,并使用压缩:
# Enable gzip compression to reduce bandwidth usage.
output.elasticsearch.compress:true
# Enable TLS if network crosses untrusted zones.
tls.enabled:true
tls.verification_mode:"full"
⚠️ 痛点:TLS 加密会增加 CPU 开销;压缩需验证兼容性,.
启用 Elastic Stack 的 Monitoring 模块:
# In filebeat.yml:
setup.monitor.enabled:true # requires connection to Elasticsearch.
# Kibana -> Stack Monitoring -> Beats section shows live throughput and latency.
# Also consider Metricbeat's System module for host-level metrics.