(ELK) ELK 企业实战 ES+head+kibana+logstash部署(最大集群)
    		       		warning:
    		            这篇文章距离上次修改已过435天,其中的内容可能已经有所变动。
    		        
        		                
                在部署一个最大规模的ELK集群时,以下是一个简化的指导步骤和配置示例:
安装Elasticsearch集群:
确保Java已安装,并设置合适的用户。
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update && sudo apt-get install elasticsearch配置elasticsearch.yml,启用集群发现和选举机制,并设置节点名称。
cluster.name: "my-elk-cluster"
node.name: "node-1"
network.host: 0.0.0.0
discovery.seed_hosts: ["node-1_ip", "node-2_ip", "node-3_ip"]
cluster.initial_master_nodes: ["node-1", "node-2", "node-3"]- 安装Elasticsearch Head插件:
 
sudo /usr/share/elasticsearch/bin/elasticsearch-plugin install mobz/elasticsearch-head- 安装Kibana:
 
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update && sudo apt-get install kibana配置kibana.yml,设置Elasticsearch的地址和Kibana的服务端口。
server.port: 5601
server.host: "0.0.0.0"
elasticsearch.hosts: ["http://localhost:9200"]- 安装Logstash:
 
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update && sudo apt-get install logstash配置Logstash以收集日志,并将其发送到Elasticsearch。
input {
  file {
    path => "/var/log/syslog"
  }
}
 
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "syslog-%{+YYYY.MM.dd}"
  }
}启动Elasticsearch、Kibana和Logstash服务,并确保它们在系统启动时自动启动。
sudo systemctl start elasticsearch
sudo systemctl enable elasticsearch
 
sudo systemctl start kibana
sudo systemctl enable kibana
 
sudo systemctl start logstash
sudo systemctl enable logstash访问Kibana (http://<kibana_host>:5601),使用Elasticsearch Head插件 (http://<es_host>:9100) 来监控和管理集群。
注意:这个例子是一个简化的指导,实际部署时需要考虑更多的配置细节,如网络安全、持久化存储、资源分配、监控等。
评论已关闭