ELK 6.4.3 OSS版本安装配置

OSS版本是遵守Apache 2.0 licensed的,属于开源项目。

Elasticsearch OSS 倒排索引服务

Elasticsearch OSS 6.4.3 下载地址:
https://www.elastic.co/downloads/past-releases/elasticsearch-oss-6-4-3

解压修改配置文件:

# 数据文件目录
path.data: /data/disk/data/elasticsearch
# 日志文件目录
path.logs: /data/disk/log/elasticsearch
# 关闭内存锁定,不关的话,centos6下报错。
bootstrap.memory_lock: false
# 关闭系统调用过滤器,不关的话,centos6下报错。
bootstrap.system_call_filter: false
# 网络地址
network.host: 0.0.0.0
# 端口号
http.port: 9200

切换到非rootsu ekl
运行bin/elasticsearch
查看结果:

curl http://localhost:9200/

elasticsearch analysis ik 分词插件

elasticsearch-analysis-ik 下载地址:
https://github.com/medcl/elasticsearch-analysis-ik/releases

安装:

新建ik目录,并解压到ik目录

mkdir your-es-root/plugins/ik
unzip  elasticsearch-analysis-ik-6.4.3.zip -d your-es-root/plugins/ik

新建索引:

curl -XPUT http://localhost:9200/index

新建映射

curl -XPOST http://localhost:9200/index/doc/_mapping -H 'Content-Type:application/json' -d'
{
        "properties": {
            "content": {
                "type": "text",
                "analyzer": "ik_max_word",
                "search_analyzer": "ik_max_word"
            }
        }

}'

Kibana OSS 可视化开发工具

Kibana OSS 6.4.3 下载地址:
https://www.elastic.co/downloads/past-releases/kibana-oss-6-4-3

设置elasticsearch.url到es:
运行bin/kibana
就可以在http://localhost:5601看到界面了。

Logstash OSS 同步mysql到ES

Logstash OSS 6.4.3 下载地址:
https://www.elastic.co/downloads/past-releases/logstash-oss-6-4-3

配置一个文件

input {
    jdbc {
      jdbc_driver_library => "mysql-connector-java-5.1.33-bin.jar"
      jdbc_driver_class => "com.mysql.jdbc.Driver"
      jdbc_user => "user"
      jdbc_password=> "password"
      jdbc_connection_string => "jdbc:mysql://192.168.0.100:3306/db"
      jdbc_validate_connection => "true"
      schedule => "* * * * *"
      use_column_value => true
      tracking_column => "id"
      last_run_metadata_path => "/data/.logstash_shandian_last_run"
      statement => "SELECT a.id, a.title, a.keywords, d.content FROM table_article a JOIN table_data d ON a.id=d.id WHERE a.id > :sql_last_value AND a.status=100 ORDER BY id ASC"
      jdbc_paging_enabled =>true
      jdbc_page_size => 10000
    }
}
filter {
    date {
      match => ["addline", "yyyy-MM-dd HH:mm:ss,SSS", "UNIX"]
      target => "@timestamp"
      locale => "cn"
    }
}
output {
    elasticsearch {
      hosts => ["http://192.168.0.200:9200"]
      index => "suoyin"
      document_id => "%{id}"
    }    
    stdout {
        codec => line {
            format => "suoyin: %{id} %{title}"
        }
    }
}

运行

bin/logstash -f logstash.conf

你可能感兴趣的:(elasticsearch)