使用 RPM 包安装和配置 Elasticsearch、Kibana 和 Logstash
以下是使用 RPM 包安装和配置 Elasticsearch、Kibana 和 Logstash 的详细步骤,并设置开机自启。
步骤 1:修改系统参数
编辑系统参数并使其生效:
vim /etc/sysctl.conf
添加以下行:
vm.max_map_count=655360
使配置生效:
sysctl -p
关闭防火墙和 SELinux
关闭防火墙:
systemctl stop firewalld
systemctl disable firewalld
关闭 SELinux:
sed -i 's/SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config
grep SELINUX=disabled /etc/selinux/config
setenforce 0
步骤 2:安装 Elasticsearch
- 添加 Elasticsearch 公钥:
rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
- 创建 yum 源:
cat <<EOF | sudo tee /etc/yum.repos.d/elasticsearch.repo
[elasticsearch-8.x]
name=Elasticsearch repository for 8.x packages
baseurl=https://artifacts.elastic.co/packages/8.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF
- 安装 Elasticsearch:
yum install elasticsearch
步骤 3:配置 Elasticsearch
编辑 Elasticsearch 配置文件 /etc/elasticsearch/elasticsearch.yml
:
vi /etc/elasticsearch/elasticsearch.yml
添加以下内容:
cluster.name: my-application
node.name: node-1
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 0.0.0.0
http.port: 9200
步骤 4:启动 Elasticsearch 并设置开机自启
启动并设置 Elasticsearch 开机自启:
systemctl daemon-reload
systemctl enable elasticsearch
systemctl start elasticsearch
步骤 5:修改 Elasticsearch 密码
修改 elastic
用户密码:
/usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic -i
步骤 6:安装 Kibana
- 添加 Kibana 公钥:
rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
- 创建 yum 源:
cat <<EOF | sudo tee /etc/yum.repos.d/kibana.repo
[kibana-8.x]
name=Kibana repository for 8.x packages
baseurl=https://artifacts.elastic.co/packages/8.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF
- 安装 Kibana:
yum install kibana
步骤 7:配置 Kibana
编辑 Kibana 配置文件 /etc/kibana/kibana.yml
:
vi /etc/kibana/kibana.yml
添加以下内容:
server.port: 5601
server.host: "0.0.0.0"
server.publicBaseUrl: "http://192.168.9.181:5601"
i18n.locale: "zh-CN"
步骤 8:启动 Kibana 并设置开机自启
启动并设置 Kibana 开机自启:
systemctl daemon-reload
systemctl enable kibana
systemctl start kibana
步骤 9:安装 Logstash
- 添加 Logstash 公钥:
rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
- 创建 yum 源:
cat <<EOF | sudo tee /etc/yum.repos.d/logstash.repo
[logstash-8.x]
name=Logstash repository for 8.x packages
baseurl=https://artifacts.elastic.co/packages/8.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF
- 安装 Logstash:
yum install logstash
步骤 10:配置 Logstash
编辑 Logstash 配置文件 /etc/logstash/logstash.yml
:
vi /etc/logstash/logstash.yml
添加以下内容:
path.data: /var/lib/logstash
path.logs: /var/log/logstash
创建 Logstash 管道配置文件 /etc/logstash/conf.d/logstash.conf
:
vi /etc/logstash/conf.d/logstash.conf
添加以下内容:
input {
beats {
port => 5044
}
}
filter {
# Add any filters here
}
output {
elasticsearch {
hosts => ["http://localhost:9200"]
index => "logstash-%{+YYYY.MM.dd}"
}
}
步骤 11:启动 Logstash 并设置开机自启
启动并设置 Logstash 开机自启:
systemctl daemon-reload
systemctl enable logstash
systemctl start logstash
以上步骤涵盖了使用 RPM 包安装 Elasticsearch、Kibana 和 Logstash。