注:所有软件我都安装在/opt下面了 大家可以自行调整!
Mkdir –p /opt/tmp/data
Mkdir –p /opt/tmp/log
Mkdir –p /opt/backup
Useradd elk
Groupadd elks
Usermod -a –G elks elk
Usermod -a –G root elk
Cd /opt/
Tar –zxvf /opt/backup/jdk-8u131-linux-x64.tar.gz
Mv jdk-8u131-linux-x64 jdk
Sudo vi /etc/profile
export JAVA_HOME=/opt/jdk
export PATH=$PATH:$JAVA_HOME/bin
export
CLASSPATH=.:$JAVA_HOME/lib/dt.jar:$JAVA_HOME/lib/tools.jar
export JAVA_HOME JAVA_BIN PATH CLASSPATH
ulimit -SHn 65537
Source /etc/profile
Java -version
Cd /opt/
Tar –zxvf /opt/backup/ logstash-5.4.1.tar.gzElasticsearch
Mv logstash-5.4.1* logstash
Cd /opt/logstash/config/
vi logstash.conf
#start
input {
file {
path =>["/opt/tmp/Logstash.log"]
add_field => {"appName" => "elk"}
type =>"elk"
}
beats {
port => 5044
}
}
filter{
grok {
match => {"message" => "msg" }
}
}
output {
elasticsearch { hosts => ["192.168.152.128:9200"] }
stdout { codec => rubydebug }
}
#end
Cd /opt/
Tar –zxvf /opt/backup/ kibana-5.4.1-linux-x86_64.tar.gz
Mv kibana-5.4.1* kibana
Cd /opt/kibana/config/
Vi kibana.yml
server.host: "192.168.152.128"
elasticsearch.url: http://192.168.152.128:9200
#账户密码需要自己看自己的默认是下边的
elasticsearch.username: "elastic"
elasticsearch.password: "changeme"
#end
Cd /opt/
Tar –zxvf /opt/backup/ elasticsearch-5.4.1.tar.gz
Mv elasticsearch-5.4.1* elastic
Cd /opt/elastic
vi elasticsearch.yml
path.data: /opt/tmp/data
path.logs: /opt/tmp/log
network.host: 192.168.152.128
http.port: 9200
为防止Elastic启动报错
http.cors.allow-origin: "/.*/"
http.cors.enabled: true
bootstrap.memory_lock: false
bootstrap.system_call_filter: false
编辑ELK配置文件
vi jvm.options
#把下边两个改为以下参数
#看自己的内存修改
-Xms512m
-Xmx512m
Chown –R elk.elks /opt/
#或者Chown –R elkselk /opt/
Su elk
Cd /opt/elastic/bin/
./elasticsearch
Cd /opt/kibana/bin/
./kibana -e -c filebeat.yml
Cd /opt/logstash/bin
./logstash –f logstash.conf
#如果没问题的话就可以访问
#http://IP:9200
#http://IP:5601
#首次登陆的时候,需要先配置索引,默认使用的索引是logstash-*,并且是基于时#间的。建议把基于时间的选项取消,然后点击创建。
#完成索引配置后,切换到Discover页面就可以开始进行日志数据的检索
#可惜不可能没问题!!!
JDK一定要去官网下载!!!JDK官网
报错:
ERROR: bootstrap checks failed
system call filters failed to install; check the logs and fix your configuration or disable system call filters at your own risk
bootstrap.memory_lock: false
bootstrap.system_call_filter: false
[WARN ][o.e.b.JNANatives ] unable to install syscall filter:
Java.lang.UnsupportedOperationException: seccomp unavailable: requires kernel 3.5+ with CONFIG_SECCOMPandCONFIG_SECCOMP_FILTERcompiledinatorg.elasticsearch.bootstrap.Seccomp.linuxImpl(Seccomp.java:349) ~[elasticsearch-5.0.0.jar:5.0.0] at org.elasticsearch.bootstrap.Seccomp.init(Seccomp.java:630) ~[elasticsearch-5.0.0.jar:5.0.0]
ERROR: bootstrap checks failed max file descriptors [4096] for elasticsearch process likely too low, increase to at least [65536]、
vi /etc/security/limits.conf
#加入内容:
* soft nofile 65536
* hard nofile 131072
* soft nproc 2048
* hard nproc 4096
# * 代表用户
#保存 ulimit –a 不生效的话 退出然后重新登陆
max number of threads [1024] for user [es] likely too low, increase to at least [2048]
vi /etc/security/limits.d/90-nproc.conf
#找到如下内容:
* soft nproc 1024
#修改为
* soft nproc 2048
max virtual memory areas vm.max_map_count [65530] likely too low, increase to at least [262144]
vi /etc/sysctl.conf
#添加下面配置:
vm.max_map_count=655360
#执行命令:
sysctl -p
然后重新启动elasticsearch,即可启动成功。
5.X版本没有plugins脚本
所以可以用
./elasticsearch-plugin install x-pack
旧版本:
plugins install xxx
新版本安装
#官网放出来的信版本可以只用通过下载rpm包直接进行安装
rpm - ivh xxx.rpm