cd /usr/local
wget \
https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.17.7-linux-x86_64.tar.gz \
https://artifacts.elastic.co/downloads/kibana/kibana-7.17.7-linux-x86_64.tar.gz \
https://artifacts.elastic.co/downloads/logstash/logstash-7.17.7-linux-x86_64.tar.gz
https://github.com/medcl/elasticsearch-analysis-ik/releases/download/v7.17.7/elasticsearch-analysis-ik-7.17.7.zip
vim /etc/profile
export ES_JAVA_HOME=$JAVA_HOME
export LS_JAVA_HOME=$JAVA_HOME
source /etc/profile
tar -zxvf elasticsearch-7.17.7-linux-x86_64.tar.gz
useradd elk
chown elk:elk -R elasticsearch-7.17.7
echo "elk hard nofile 65536" >> /etc/security/limits.conf
echo "elk soft nofile 65536" >> /etc/security/limits.conf
echo "vm.max_map_count=655360" >> /etc/sysctl.conf
sysctl -p
vim /usr/local/elasticsearch-7.17.7/config/elasticsearch.yml
cluster.name: test-log
node.name: node-1
network.host: 0.0.0.0
http.port: 9200
discovery.seed_hosts: ["0.0.0.0"]
cluster.initial_master_nodes: ["node-1"]
su elk
cd elasticsearch-7.17.7/
bin/elasticsearch
需在云服务器安全组开放相应端口
输入服务器公网ip:9200
nohup bin/elasticsearch >> /dev/null &
cd /usr/local
tar -zxvf kibana-7.17.7-linux-x86_64.tar.gz
chown elk:elk -R kibana-7.17.7-linux-x86_64/
vim /usr/local/kibana-7.17.7-linux-x86_64/config/kibana.yml
server.host: "0.0.0.0"
elasticsearch.hosts: ["http://服务器公网ip:9200"]
i18n.locale: "zh-CN"
cd kibana-7.17.7-linux-x86_64/
su elk
bin/kibana
nohup bin/kibana >> /dev/null &
cd /usr/local
tar -zxvf logstash-7.17.7-linux-x86_64.tar.gz
chown elk:elk -R logstash-7.17.7/
vim /usr/local/logstash-7.17.7/config/logstash.yml
node.name: test-log
path.config: /usr/local/logstash-7.17.7/config/conf/*.conf
vim /usr/local/logstash-7.17.7/config/conf/test-log.conf
input {
tcp {
mode => "server"
port => 4560
}
}
filter {}
output {
elasticsearch {
action => "index"
hosts => ["服务器公网ip:9200"]
index => "test-log"
}
}
cd logstash-7.17.7/
su elk
bin/logstash
nohup bin/logstash >> /dev/null &
需在云服务器安全组开放相应端口4560