实验前夕
systemctl stop firewalld.service //关闭防火墙
systemctl status firewalld.service //查看防火墙状态
setenforce 0 // 关闭安全系统
一,安装部署 1.环境部署 node1 ; 192.168.189.14 Elasticsearch/Kibana node2 ; 192.168.189.15 Elasticsearch apache; 192.168.189.16 httpd / Logstash 客户机 win10 3.更改主机名 hostnamectl set-hostname +主机名 4.配置elasticsearch 环境 node1 nede2 配置
echo '192.168.189.14 node1' >> /etc/hosts
echo '192.168.189.15 node2' >> /etc/hosts
cat /etc/hosts
data:image/s3,"s3://crabby-images/12fa9/12fa9b9981cc528a0c3d8b614a808ce9a9aba31a" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/06f19/06f19f716baf79928df97513dd71380c80904b70" alt="在这里插入图片描述" 5.安装elasticsearch软件 node1 node2
cd /opt
rpm -ivh elasticsearch-5.5.0.rpm
data:image/s3,"s3://crabby-images/64ddc/64ddc692015cab5f4ac6442bd4e8218d49f04ecc" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/b14b6/b14b67bb5e0d73034fef70f0ce24fe7bd73f3d38" alt="在这里插入图片描述" 二,加载系统服务 systemctl daemon-reload systemctl enable elasticsearch.service
1.更改elasticsearch参数配置
cp /etc/elasticsearch/elasticsearch.yml /etc/elasticsearch/elasticsearch.yml.bak
2.vim /etc/elasticsearch/elasticsearch.yml
cluster.name: my-elk-cluster
node.name: node1
path.data: /data/elk_data
path.logs: /var/log/elasticsearch
bootstrap.memory_lock: false
network.host: 0.0.0.0
http.port: 9200
discovery.zen.ping.unicast.hosts: ["node1", "node2"]
data:image/s3,"s3://crabby-images/3636f/3636fc43ba0071c1adeca03a811470042a0d96c8" alt="在这里插入图片描述"
data:image/s3,"s3://crabby-images/4e675/4e675e72a76bff56a1f20b617bd6ca9258c68cba" alt="在这里插入图片描述" 3.检验配置
grep -v "^#" /etc/elasticsearch/elasticsearch.yml
data:image/s3,"s3://crabby-images/b7be5/b7be57195a3d2a59e336e4893a78cb1425a65f43" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/0836b/0836b3107416d8666cea1a6423a429ae3696d4ed" alt="在这里插入图片描述" 4.创建数据存放路径并授权
mkdir -p /data/elk_data
chown elasticsearch:elasticsearch /data/elk_data/
5.启动一下
systemctl start elasticsearch
6.查看一下
netstat -antp | grep 9200
data:image/s3,"s3://crabby-images/9dfe4/9dfe4529db1c464a081c4d9deddb24bb467221c8" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/ca8b8/ca8b86a22413dbf3ce492b47eb7076981eef7758" alt="在这里插入图片描述" 7.查看节点信息
http://192.168.189.14:9200
http://192.168.189.15:9200
data:image/s3,"s3://crabby-images/9f012/9f0122f937626521f40dca1461e66ae653d5dd80" alt="在这里插入图片描述" 8.检验集群健康状态
http://192.168.189.14:9200/_cluster/health?pretty
http://192.168.189.15:9200/_cluster/health?pretty
data:image/s3,"s3://crabby-images/3839c/3839c0cd472f5058f3434d278ed74f2a86592a8e" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/19515/1951577338c75bfa0e7921b8672f5b12015a2631" alt="在这里插入图片描述" 9.查看集群状态
http://192.168.189.14:9200/_cluster/state?pretty
http://192.168.189.15:9200/_cluster/state?pretty
data:image/s3,"s3://crabby-images/416dd/416dd568595bd7a6d849673c084986deb1bb2bf9" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/eb89c/eb89ce8b422b2ca7730d00f9f23afc91f74a3c30" alt="在这里插入图片描述" 三,安装elasticsearch-head插件
node1 node 2 1.编译安装node组件依赖包
yum -y install gcc gcc-c++ make
cd /opt
tar xzvf node-v8.2.1.tar.gz
cd node-v8.2.1/
./configure && make && make install
data:image/s3,"s3://crabby-images/ab86e/ab86eb747c2809c33aa6199bf5441d8c4038b692" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/204bd/204bd16042b85725f6801f470bbb1d7ff370e2fb" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/6431a/6431a6c821a5e9c59139c32b131168e0b3efa4c3" alt="在这里插入图片描述"
2.安装安装phantomjs 前端框架 node1 node2
cd /opt
tar jxvf phantomjs-2.1.1-linux-x86_64.tar.bz2 -C /usr/local/src/
cd /usr/local/src/phantomjs-2.1.1-linux-x86_64/bin
cp phantomjs /usr/local/bin
data:image/s3,"s3://crabby-images/d62d9/d62d9dc79666bf1c1995beb1a9e20e4ed380490e" alt="在这里插入图片描述" 3.安装elasticsearch-head 数据可视化工具 node1 node2
cd /opt
tar zxvf elasticsearch-head.tar.gz -C /usr/local/src/
cd /usr/local/src/elasticsearch-head/
npm install
data:image/s3,"s3://crabby-images/c0125/c0125f501dd649e7cb025f83b7d999b6b7a8d6b6" alt="在这里插入图片描述" 4.修改主机配置文件 node1 node2
vim /etc/elasticsearch/elasticsearch.yml
http.cors.enabled: true
http.cors.allow-origin: "*"
systemctl restart elasticsearch.service
data:image/s3,"s3://crabby-images/ecbcf/ecbcf1e18e6e9549d558b90c836e295fa045f3ef" alt="在这里插入图片描述"
data:image/s3,"s3://crabby-images/70203/70203b4e176e446628758e5b7f983b4632ca1923" alt="在这里插入图片描述" 5.启动elasticsearch-head node1 node2
在 elasticsearch-head 目录下启动服务
cd /usr/local/src/elasticsearch-head/
npm run start &
netstat -natp |grep 9100
data:image/s3,"s3://crabby-images/36c21/36c21bb229d5090fc18c914ef2aa4cc37da5901b" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/2733f/2733f0473f8745942bf6dc01c7dbd318c9463250" alt="在这里插入图片描述" 6.使用elasticsearch-head插件查看集群状态
http://192.168.189.14:9100
在Elasticsearch 后面的栏目中输入
http://192.168.189.15:9200
http://192.168.189.15:9100
在Elasticsearch 后面的栏目中输入
http://192.168.189.14:9200
data:image/s3,"s3://crabby-images/01db0/01db0dfb4cca9374eaef4941311158d03e2bd217" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/14444/1444417b6dc4803902e935fb8c152b9aa69e552c" alt="在这里插入图片描述" 7.创建索引 node1
创建索引为index-demo,类型为test
curl -XPUT 'localhost:9200/index-demo/test/1?pretty&pret
data:image/s3,"s3://crabby-images/25cdd/25cdd6f521753cbbbfefd7e2d38f365ad26456d2" alt="在这里插入图片描述" 查看数据浏览–会发现在node1上创建的索引为index-demo,类型为test, 相关的信息 data:image/s3,"s3://crabby-images/6545a/6545a7e63c2eb6a458295e2903a618434594fa6f" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/ff9b9/ff9b9acf4e85d57ef23a79b1180a331d11a8cc2a" alt="在这里插入图片描述" 8…安装logstash 收集日志输出到elasticsearch中 安装Apahce服务(httpd) apache
yum -y install httpd
systemctl start httpd
9.安装logstash apache
cd /opt
rpm -ivh logstash-5.5.1.rpm
systemctl start logstash.service
systemctl enable logstash.service
ln -s /usr/share/logstash/bin/logstash /usr/local/bin/
data:image/s3,"s3://crabby-images/0e4dc/0e4dc2ba54d83dc5663a30a863624fbc39703a80" alt="在这里插入图片描述"
10.测试logstash命令 apache
logstash -e 'input { stdin{ } } output { stdout { } }'
使用rubydebug显示详细输出,codec为一种编解码器
logstash -e 'input { stdin{} } output { stdout{ codec=>rubydebug} }'
使用logstash将信息写入elasticsearch中,并查看
logstash -e 'input { stdin{} } output { elasticsearch { hosts=> ["192.168.35.40:9200"] } }'
data:image/s3,"s3://crabby-images/74971/74971501f8123f6b816783ddf469e19d23c19373" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/fafff/fafffbf922641bb311e7374248c52b75cf9d3327" alt="在这里插入图片描述" 11.使用平台收集日志
chmod o+r /var/log/messages
vim /etc/logstash/conf.d/system.conf
input {
file{
path => "/var/log/messages"
type => "system"
start_position => "beginning"
}
}
output {
elasticsearch {
hosts => ["192.168.189.14:9200"]
index => "system-%{+YYYY.MM.dd}"
}
}
systemctl restart logstash.service
data:image/s3,"s3://crabby-images/b8478/b847890d558de68e12716aad60ecb3078bb3d00f" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/d53d3/d53d399687e4e12cdfb34cacb0adb340a54935e7" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/7e93a/7e93afdced3a890525f9e0743f9ef8be3de71cf1" alt="在这里插入图片描述" 四,安装kibana node1
上传kibana-5.5.1-x86_64.rpm到/usr/local/src目录
cd /usr/local/src
rpm -ivh kibana-5.5.1-x86_64.rpm
cd /etc/kibana/
cp kibana.yml kibana.yml.bak
vim kibana.yml
2 server.port: 5601
7 server.host: "0.0.0.0“ ##kibana侦听的地址
21 elasticsearch.url: "http://192.168.189.14:9200" ##和elasticsearch建立联系
30 kibana.index: ".kibana"
systemctl start kibana.service
访问5601端口:http://192.168.189.14:5601/
data:image/s3,"s3://crabby-images/4db52/4db52af488cf2dbf9e685fbfe1f3ec3b5fbf1461" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/e8101/e8101653eb1aa89824bed1f1a1b3918c09724b1d" alt="在这里插入图片描述" 2.对接apache的日志(访问的、错误)
apache
cd /etc/logstash/conf.d/
vim apache_log.conf
input {
file{
path => "/etc/httpd/logs/access_log"
type => "access"
start_position => "beginning"
}
file{
path => "/etc/httpd/logs/error_log"
type => "error"
start_position => "beginning"
}
}
output {
if [type] == "access" {
elasticsearch {
hosts => ["192.168.189.14:9200"]
index => "apache_access-%{+YYYY.MM.dd}"
}
}
if [type] == "error" {
elasticsearch {
hosts => ["192.168.189.14:9200"]
index => "apache_error-%{+YYYY.MM.dd}"
}
}
}
data:image/s3,"s3://crabby-images/1c497/1c497f0ee0fa37a6bbefcc5709efa8d7236653a0" alt="在这里插入图片描述" 进入kibana进入创建Apache索引appche_acess和apache_error 首页Management–Index Patterns–Create Index Pattern–选择inde name or pattern 验证索引 data:image/s3,"s3://crabby-images/adb09/adb09ffcb7be86ffc2d4bd6c9d662b373eb4cb1f" alt="在这里插入图片描述"
|