Zabbix 3.4.6版本开始支持历史数据存储到Elasticsearch, 早就想测试这个功能,最近有个需求需保存zabbix的历史数据上达十亿条,因此决定测试这功能的实用性,事实证明确实效果挺好。从今以后zabbix也支持大量的历史数据。
以下是测试12亿条数据存储环境:
服务器系统:Ubuntu 16.04
Elasticsearch服务器IP:192.168.1.231
#vi /etc/sysctl.conf
vm.max_map_count=655360
#sysctl -p
#vi /etc/security/limits.conf
elasticsearch soft memlock unlimited
elasticsearch hard memlock unlimited
elasticsearch soft nofile 65536
elasticsearch hard nofile 131072
elasticsearch soft nproc 65536
elasticsearch hard nproc 65536
/etc/elasticsearch/jvm.option
#vi /etc/fstab
#/dev/mapper/cryptswap1 none swap sw 0 0 注释
ELK依赖java,因此需要安装
#add-apt-repository ppa:webupd8team/java
#apt-get update
#apt-get install oracle-java8-installer
#wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.4.2.deb
#dpkg -i elasticsearch-6.4.2.deb
以下配置仅供参考
#vim /etc/elasticsearch/jvm.options
-Xms4g #配置服务器内存的50%
-Xmx4g #配置服务器内存的50%
-XX:+UseConcMarkSweepGC
-XX:CMSInitiatingOccupancyFraction=75
-XX:+UseCMSInitiatingOccupancyOnly
-XX:+AlwaysPreTouch
-server
-Xss1m
-Djava.awt.headless=true
-Dfile.encoding=UTF-8
-Djna.nosys=true
-XX:-OmitStackTraceInFastThrow
-Dio.netty.noUnsafe=true
-Dio.netty.noKeySetOptimization=true
-Dio.netty.recycler.maxCapacityPerThread=0
-Dlog4j.shutdownHookEnabled=false
-Dlog4j2.disable.jmx=true
-XX:+HeapDumpOnOutOfMemoryError
-XX:HeapDumpPath=/var/lib/elasticsearch
以下配置仅供参考
#vim /etc/elasticsearch/elasticsearch.yml
cluster.name: elk-group
node.name: elk-1
node.master: true
node.data: true
node.attr.rack: r1
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 0.0.0.0
http.port: 9200
transport.tcp.port: 9300
http.cors.enabled: true
discovery.zen.ping.unicast.hosts: ["192.168.1.231"]
discovery.zen.minimum_master_nodes: 1
cluster.routing.allocation.same_shard.host: true
discovery.zen.fd.ping_timeout: 60s
discovery.zen.fd.ping_retries: 5
如需Salve Elasticsearch配置如下:
#vim /etc/elasticsearch/elasticsearch.yml
cluster.name: elk-group
node.name: elk-2
node.master: false
node.data: true
node.attr.rack: r1
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 0.0.0.0
http.port: 9200
transport.tcp.port: 9300
http.cors.enabled: true
discovery.zen.ping.unicast.hosts: ["192.168.1.231"]
discovery.zen.minimum_master_nodes: 1
cluster.routing.allocation.same_shard.host: true
discovery.zen.fd.ping_timeout: 60s
discovery.zen.fd.ping_retries: 5
service elasticsearch start
Elasticsearch 支持Zabbix的监控项类型:uint,dbl,str,log,text,对应如下
Zabbix监控项数据类型 |
对应Zabbix表 |
对应Elasticsearch类型 |
Numeric(unsigned) |
history_uint |
uint |
Numeric(float) |
history |
dbl |
Character |
history_str |
str |
Log |
history_log |
log |
Text |
history_text |
text |
#curl -H "Content-Type:application/json" -XPUT http://192.168.1.231:9200/uint -d ' { "settings" : { "index" : { "number_of_replicas" : 1, "number_of_shards" : 5 } }, "mappings" : { "values" : { "properties" : { "itemid" : { "type" : "long" }, "clock" : { "format" : "epoch_second", "type" : "date" }, "value" : { "type" : "long" } } } } } '
#curl -H "Content-Type:application/json" -XPUT http://192.168.1.231:9200/dbl -d ' { "settings" : { "index" : { "number_of_replicas" : 1, "number_of_shards" : 5 } }, "mappings" : { "values" : { "properties" : { "itemid" : { "type" : "long" }, "clock" : { "format" : "epoch_second", "type" : "date" }, "value" : { "type" : "double" } } } } } '
#curl -H "Content-Type:application/json" -XPUT http://192.168.1.231:9200/log -d ' { "settings" : { "index" : { "number_of_replicas" : 1, "number_of_shards" : 5 } }, "mappings" : { "values" : { "properties" : { "itemid" : { "type" : "long" }, "clock" : { "format" : "epoch_second", "type" : "date" }, "value" : { "fields" : { "analyzed" : { "index" : true, "type" : "text", "analyzer" : "standard" } }, "index" : false, "type" : "text" } } } } } '
#curl -H "Content-Type:application/json" -XPUT http://192.168.1.231:9200/text -d ' { "settings" : { "index" : { "number_of_replicas" : 1, "number_of_shards" : 5 } }, "mappings" : { "values" : { "properties" : { "itemid" : { "type" : "long" }, "clock" : { "format" : "epoch_second", "type" : "date" }, "value" : { "fields" : { "analyzed" : { "index" : true, "type" : "text", "analyzer" : "standard" } }, "index" : false, "type" : "text" } } } } } '
#curl -H "Content-Type:application/json" -XPUT http://192.168.1.231:9200/str -d ' { "settings" : { "index" : { "number_of_replicas" : 1, "number_of_shards" : 5 } }, "mappings" : { "values" : { "properties" : { "itemid" : { "type" : "long" }, "clock" : { "format" : "epoch_second", "type" : "date" }, "value" : { "fields" : { "analyzed" : { "index" : true, "type" : "text", "analyzer" : "standard" } }, "index" : false, "type" : "text" } } } } } '
Zabbix安装过程忽略
配置zabbix_server.conf文件
在/etc/zabbix/zabbix_server.conf文件下添加elasticsearch配置,指定数据类型使用elasticsearch。
#vim /etc/zabbix/zabbix_server.conf
HistoryStorageURL=http://192.168.1.231:9200
HistoryStorageTypes=uint,dbl,str,log,text
配置zabbix.conf.php文件
在/etc/zabbix/web/zabbix.conf.php文件下添加elasticsearch配置
#vim /etc/zabbix/zabbix_server.conf
多台elasticsearch集群可按以下格式配置
$HISTORY['url'] = [ 'uint' => 'http://192.168.1.230:9200 ', 'text' => 'http://192.168.1.234:9200 '
'log' => 'http://192.168.1.235:9200 ' ];
$HISTORY['types'] = ['uint', 'text','log'];
service zabbix-server start
在Elasticsearch服务器安装,如独立服务器请另外安装java
#wget https://artifacts.elastic.co/downloads/kibana/kibana-6.4.2-amd64.deb
#dpkg -i kibana-6.4.2-amd64.deb
#vim /etc/kibana/kibana.yml
server.port: 5601
server.host: "0.0.0.0"
elasticsearch.url: "http://192.168.1.231:9200"
service kibana start
web登录
http://192.168.1.231:5601/app/kibana