Yêu cầu
- Đã cài
blackhole-agt, xem Cài đặt. - Windows: quyền Administrator cho bước cài service. Linux: quyền root và systemd hoặc OpenRC cho bước cài service.
- Kiến trúc x86_64.
- Không cần backend nào cho ví dụ này: pipeline ghi sự kiện ra file ngay trên máy.
Trong hướng dẫn này, $AgentDir (Windows) và $AGENT_DIR (Linux) là thư mục chứa executable. Hãy đổi biến này cho đúng với máy bạn:
- Cài bằng MSI:
C:\Program Files\blackhole-agt\bin - Cài bằng bộ cài đặt:
%USERPROFILE%\.cargo\bin(Windows) hoặc$HOME/.cargo/bin(Linux) - Cài thủ công: thư mục bạn đã copy binary vào
Bước 1: Tạo file cấu hình
Ví dụ dưới đây dùng source file đọc file log và sink file ghi ra ./debug-events/. Không cần Kafka, MQTT hay gRPC nên bạn kiểm tra được đầu ra ngay trên máy.
Windows
$AgentDir = "C:\Program Files\blackhole-agt\bin" # đổi thành thư mục chứa blackhole-agt.exe
$Config = Join-Path $AgentDir "blackhole-agt.yml"
# Tạo sẵn log mẫu để collector có dữ liệu ngay khi khởi động
New-Item -ItemType Directory -Path "$AgentDir\sample-logs" -Force | Out-Null
Set-Content -Path "$AgentDir\sample-logs\test.log" -Value "test event 1"
@"
sources:
sample_logs:
type: file
includes:
- ./sample-logs/*.log
tail: false
sinks:
local_debug:
type: file
inputs: ["*"]
path: ./debug-events/
max_size_mb: 10
max_files: 5
"@ | Set-Content -Path $Config -Encoding utf8Linux
AGENT_DIR="$HOME/.cargo/bin" # đổi thành thư mục chứa binary
CONFIG="$AGENT_DIR/blackhole-agt.yml"
# Tạo sẵn log mẫu để collector có dữ liệu ngay khi khởi động
mkdir -p "$AGENT_DIR/sample-logs"
echo "test event 1" > "$AGENT_DIR/sample-logs/test.log"
cat > "$CONFIG" <<'EOF'
sources:
sample_logs:
type: file
includes:
- ./sample-logs/*.log
tail: false
sinks:
local_debug:
type: file
inputs: ["*"]
path: ./debug-events/
max_size_mb: 10
max_files: 5
EOFXác minh
# Windows
Get-Content $Config# Linux
cat "$CONFIG"Kết quả mong đợi: nội dung YAML vừa ghi, với type: file ở cả sources và sinks.
Bước 2: Chạy thử ở foreground
Windows
cd $AgentDir
.\blackhole-agt.exe --config $Config --verbose startLinux
cd "$AGENT_DIR"
./blackhole-agt --config "$CONFIG" --verbose startAgent khởi động và đọc file cấu hình ngay. Nếu file không tồn tại ở đường dẫn truyền cho --config, tiến trình dừng với lỗi Failed to read file for hashing: <tên file>.
Dừng thử bằng Ctrl+C.
Xác minh
Mở một terminal khác, chạy:
# Windows
cd $AgentDir
Get-ChildItem .\debug-events
Get-Content .\debug-events\* -TotalCount 5# Linux
cd "$AGENT_DIR"
ls debug-events/
head -n 5 debug-events/*Kết quả mong đợi: thư mục debug-events/ được tạo và có file chứa test event 1 bạn vừa ghi ở Bước 1.
Bước 3: Xác thực với Registry (tùy chọn)
Bỏ qua bước này nếu bạn chạy Agent hoàn toàn local. Nếu dùng Registry, thứ tự bắt buộc là: tạo cấu hình có registry: → auth → cài service.
Thêm registry: vào file cấu hình (ít nhất là api_url):
Windows
Add-Content -Path $Config -Value @"
registry:
api_url: "https://<registry-host>"
"@
.\blackhole-agt.exe --config $Config auth --key "<API key>"Linux
cat >> "$CONFIG" <<'EOF'
registry:
api_url: "https://<registry-host>"
EOF
./blackhole-agt --config "$CONFIG" auth --key "<API key>"Xác minh
Lệnh auth hoàn tất mà không báo lỗi: thiết bị được đăng ký và cấu hình local được đẩy lên Registry.
- Nếu thiếu
registry.api_url, lệnh dừng vớiNo registry configured. - Chạy
configure pushtrước khiauthsẽ dừng vớidevice token not available, you need to authenticate first.
Bước 4: Cài đặt Agent như service
Đây là nguyên nhân phổ biến nhất của tình trạng "service chạy nhưng không thu thập gì": file cấu hình nằm sai chỗ. Hãy đặt blackhole-agt.yml cạnh executable như Bước 1 đã làm.
service install khởi động service ngay lập tức, nên không cần chạy service start thêm.
Windows
cd $AgentDir
.\blackhole-agt.exe service installLinux
cd "$AGENT_DIR"
sudo ./blackhole-agt service installLệnh ghi file unit /etc/systemd/system/blackhole-agt.service, đặt WorkingDirectory là thư mục chứa executable, Restart=on-failure và khởi động cùng hệ thống.
Nếu service đã tồn tại, lệnh dừng với Service already exists. Use --force to overwrite. — chạy lại với service install --force để ghi đè.
Xác minh
# Windows
Get-Service -Name "blackhole-agt"
cd $AgentDir
.\blackhole-agt.exe service status# Linux
systemctl status blackhole-agt
cd "$AGENT_DIR"
sudo ./blackhole-agt service statusKết quả mong đợi: trạng thái service là Running (Windows) hoặc active (running) (Linux).
Xác minh
Windows
cd $AgentDir
# Trạng thái service
Get-Service -Name "blackhole-agt"
# Log của service
Get-Content .\logs\default.log -Tail 20
Get-Content .\logs\default-error.log -Tail 20
# Dữ liệu đã thu thập
Get-Content .\debug-events\* -TotalCount 5Linux
cd "$AGENT_DIR"
# Trạng thái service
systemctl status blackhole-agt
# Log của service
tail -n 20 logs/default.log
tail -n 20 logs/default-error.log
# Dữ liệu đã thu thập
head -n 5 debug-events/*Kết quả mong đợi: service ở trạng thái chạy, logs/default.log có dòng log mới, và file trong debug-events/ chứa test event 1.
