ELK7.x安装及基本配置
软件安装
# 安装公钥
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
# apt
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update && sudo apt-get install logstash
# YUM
sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
cat > /etc/yum.repos.d/logstash.repo << EOF
[logstash-7.x]
name=Elastic repository for 7.x packages
baseurl=https://artifacts.elastic.co/packages/7.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
EOF
yum install logstash elasticsearch kibana
Elasticsearch配置
Elasticsearch单节点配置
Elasticsearch集群配置
配置Elasticsearch内存
给Elasticsearch配置密码
检查节点情况
删除历史日志
Logstash配置
示例配置
kibana配置
kibana通过“开发工具”--“控制台”执行ES索引管理操作

部分错误处理
Elasticsearch启动时报错"max virtual memory areas vm.max_map_count [65530] is too low, increase to at least [262144]"
最后更新于
