该插件作用为实现使用基本的sql语句进行日志信息的查询
elasticsearch-sql该插件可以通过基本的sql语句进行日志信息的查询提取
下载elasticsearch-sql该插件,对应的下载地址为https://github.com/NLPchina/elasticsearch-sql
将下载的安装包解压,将解压的文件目录中的文件移动到到elasticsearch的如下所示目录中
[root@master-node1 sql]# pwd
/usr/share/elasticsearch/plugins/sql
[root@master-node1 sql]# ls
druid.jar elasticsearch-sql-6.0.0.0.jar guava.jar parent-join-client-6.0.0.jar plugin-descriptor.properties reindex-client-6.0.0.jar
以上操作完成后重启elasticsearch服务
在浏览器中输入相关信息进行验证,如:
http://172.31.125.105:9200/_sql?sql=select * from messages-2018.12.29
如果现实如下信息表示成功
{"took":78,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":4633,"max_score":1.0,"hits":[{"_index":"messages-2018.12.29","_type":"doc","_id":"NNRP92cBiiLaSzqvmDKM","_score":1.0,"_source":{"@timestamp":"2018-12-29T00:14:07.563Z","offset":2958361,"@version":"1","beat":{"name":"data-node2.localdomain","hostname":"data-node2.localdomain","version":"6.0.0"},"host":"data-node2.localdomain","source":"/var/log/messages","message":"Dec 29 08:14:01 data-node2 systemd: Starting User Slice of
node.js和npm安装
下载node.js安装包
下载地址 https://nodejs.org/en/download/
解压文件
[root@master-node1 node]# tar -xJf node-v10.15.0-linux-x64.tar.xz
将解压的文件移动到相应的目录
mv node-v10.15.0-linux-x64 /opt/
建立文件链接使npm和node命令道系统命令
ln –s /opt/ node-v10.15.0-linux-x64/bin/node /usr/local/bin/node
ln –s /opt/ node-v10.15.0-linux-x64/bin/npm /usr/local/bin/npm
部署成功以后验证是否安装成功
[root@master-node1 node]# node -v
v10.15.0
[root@master-node1 node]# npm -v
6.4.1