ELK集群-安全监控平台

1、集群环境

主机名 IP
elk1 10.0.0.51
elk2 10.0.0.52
elk3 10.0.0.53

2、配置host解析

# 所有机器操作
cat >>/etc/hosts<<'END'
10.0.0.51 elk1
10.0.0.52 elk2
10.0.0.53 elk3
END

2、安装java环境

# 所有机器操作
rpm -ivh jdk-8u191-linux-x64.rpm 

cat  >>/etc/profile<<'EOF'
JAVA_HOME=/usr/java/jdk1.8.0_191-amd64
CLASSPATH=%JAVA_HOME%/lib:%JAVA_HOME%/jre/lib
PATH=$PATH:$JAVA_HOME/bin:$JAVA_HOME/jre/bin
export PATH CLASSPATH JAVA_HOME
EOF

source /etc/profile
java -version

3、Zookeeper集群环境部署

# elk1操作
tar zxvf zookeeper-3.4.9.tar.gz -C /opt/

cd /opt/zookeeper-3.4.9/conf/
mv zoo_sample.cfg zoo.cfg

cat >zoo.cfg<<'END'
tickTime=2000
initLimit=10
syncLimit=5
dataDir=/opt/zookeeper-3.4.9/data
clientPort=2181
server.1=elk1:2888:3888
server.2=elk2:2888:3888
server.3=elk3:2888:3888
END

mkdir -p /opt/zookeeper-3.4.9/data/
echo 1 >/opt/zookeeper-3.4.9/data/myid
cat /opt/zookeeper-3.4.9/data/myid

/opt/zookeeper-3.4.9/bin/zkServer.sh start
/opt/zookeeper-3.4.9/bin/zkServer.sh status

4、elasticsearch集群环境部署

# elk1操作
yum install -y java-1.8.0-openjdk.x86_64
rpm -ivh elasticsearch-6.6.0.rpm

cat >/etc/elasticsearch/elasticsearch.yml</etc/elasticsearch/elasticsearch.yml</etc/elasticsearch/elasticsearch.yml<

你可能感兴趣的:(ELK集群-安全监控平台)