参考文档:
通过《ELK实时日志分析平台环境部署--完整记录》、《2017.7.18 linux下ELK环境搭建》了解了ELK的部署与应用,同时按照博客上步骤一步步实现,但是遇到了如下问题:
报如下错误
[2017-08-30T13:41:13,631][INFO ][o.e.n.Node ] [ELK-node1] starting ...
[2017-08-30T13:41:14,093][INFO ][o.e.t.TransportService ] [ELK-node1] publish_address {192.168.252.121:9300}, bound_addresses {[::]:9300}
[2017-08-30T13:41:14,121][INFO ][o.e.b.BootstrapChecks ] [ELK-node1] bound or publishing to a non-loopback or non-link-local address, enforcing bootstrap checks
[2017-08-30T13:41:14,127][ERROR][o.e.b.Bootstrap ] [ELK-node1] node validation exception
[2] bootstrap checks failed
[1]: max file descriptors [4096] for elasticsearch process is too low, increase to at least [65536]
[2]: max virtual memory areas vm.max_map_count [65530] is too low, increase to at least [262144]
[2017-08-30T13:41:14,142][INFO ][o.e.n.Node ] [ELK-node1] stopping ...
[2017-08-30T13:41:14,186][INFO ][o.e.n.Node ] [ELK-node1] stopped
[2017-08-30T13:41:14,186][INFO ][o.e.n.Node ] [ELK-node1] closing ...
[2017-08-30T13:41:14,204][INFO ][o.e.n.Node ] [ELK-node1] closed
这时我通过问题查找,看到了《ElasticSearch 安装报错整理》这篇文章,按照上面的方法进行处理,不过还是无法解决问题。
无奈,只能去请教大神Wilson,经过大神指导,终于解决了问题!
具体解决步骤如下:
1. 修改 /etc/sysctl.conf : vm.max_map_count = 655360 保存退出;
执行 sysctl -p;
2.修改: /etc/security/limits.d/90-nproc.conf 增加: ***** soft nproc 4096;
注: ***** 是es执行用户名;
3. 修改: /etc/security/limits.conf 增加两行:
用户名 hard nofile 65536
用户名 soft nofile 65536;
4. elasticsearch.yml 增加: bootstrap.system_call_filter: false;
主要是解决bootstrap 报错提示。
最终,通过curl访问配置过的接口得到了如期的返回内容,成功启动Elasticsearch服务。