# 07_Elastic Stack 从入门到实践(七)---1

发布于:2025-05-16 ⋅ 阅读:(12) ⋅ 点赞:(0)

07_Elastic Stack 从入门到实践(七)—1

一、Filebeat入门之读取 Nginx 日志文件

1、首先启动 Elasticsearch 集群 和 Nginx 服务,打开GoogleChrome 浏览器,点击 elasticsearch-head 插件,连接Elasticsearch 集群 服务器。

# 查看网卡名
$  ip addr

# 修改网卡配置,改为静态IP
vim /etc/sysconfig/network-scripts/ifcfg-enp0s3

[root@manager1 ~]# vim /etc/sysconfig/network-scripts/ifcfg-enp0s3
TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
# BOOTPROTO=dhcp
BOOTPROTO=static
IPADDR=192.168.67.199
NETMASK=255.255.255.0
GATEWAY=192.168.67.1
DNS1=8.8.8.8
DNS2=114.114.114.114
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=enp0s3
UUID=43f2469a-7ff2-418f-ac9a-3bc5a3f14d46
DEVICE=enp0s3
ONBOOT=yes

# 保存并退出编辑  :wq

# 修改 elasticsearch 集群配置
vim /dzs168/es-cluster/elasticsearch-6.5.4/config/elasticsearch.yml 

#node1主节点
cluster.name: es-dzs168-cluster
node.name: node01
node.master: true
node.data: true
network.host: 0.0.0.0
http.port: 9200
discovery.zen.ping.unicast.hosts: ["192.168.67.199","192.168.67.71","192.168.67.207"]
discovery.zen.minimum_master_nodes: 2
http.cors.enabled: true
http.cors.allow-origin: "*"


# node02 的配置
cluster.name: es-dzs168-cluster
node.name: node02
node.master: true
node.data: true
network.host: 0.0.0.0
http.port: 9200
discovery.zen.ping.unicast.hosts: ["192.168.67.199","192.168.67.71","192.168.67.207"]
discovery.zen.minimum_master_nodes: 2
http.cors.enabled: true
http.cors.allow-origin: "*"

# node03从节点
cluster.name: es-dzs168-cluster
node.name: node03
node.master: true
node.data: true
network.host: 0.0.0.0
http.port: 9200
discovery.zen.ping.unicast.hosts: ["192.168.67.199","192.168.67.71","192.168.67.207"]
discovery.zen.minimum_master_nodes: 2
http.cors.enabled: true
http.cors.allow-origin: “*”



# (192.168.67.199虚拟机上)关闭防火墙,切换到 elsearch用户,启动elasticsearch

$ systemctl stop firewalld
$ su elsearch
$ /dzs168/es-cluster/elasticsearch-6.5.4/bin/elasticsearch

# 查看80端口占用情况,如果占用,杀死进程ID
[root@manager1 ~]# netstat -tulpn | grep :80
tcp6  0      0 :::80    :::*      LISTEN      964/httpd           
[root@manager1 ~]# kill 964

# 启动nginx服务
$  /usr/local/nginx/nginx/sbin/nginx

# 可通过浏览器访问nginx页面(默认80端口):http://192.168.67.199/

# (192.168.67.71虚拟机上)关闭防火墙,切换到 elsearc

网站公告

今日签到

点亮在社区的每一天
去签到