ELK常见问题

1:kibana无法外网访问
设置server.host = "0.0.0.0"
2:kibana7.x首次无法启动
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'unsafe-eval' 'nonce-SK5LdJc4MkeDocgq'". Either the 'unsafe-inline' keyword, a hash ('sha256-SHHSeLc0bp6xt4BoVVyUy+3IbVqp3ujLaR+s+kSP5UI='), or a nonce ('nonce-...') is required to enable inline execution.
设置logging.verbose: true
重启后文件解决
2:elasticsearch7.x启动报错
修改了network.host为0.0.0.0怎么都启动不起来,到/var/log/elasticsearch/查看错误日志如下

the default discovery settings are unsuitable for production use; at least one of [discovery.seed_hosts, discovery.seed_providers, cluster.initial_master_nodes] must be configured

解决步骤如下:(以ubuntu16.04为例)

vi /etc/security/limits.conf
添加:
* soft nofile 65534
* hard nofile 65534
root soft nofile 65534
root hard nofile 65534
重启电脑
vi  /etc/sysctl.conf
vm.max_map_count=262144
保存退出,sysctl  -p  
修改elasticsearch.yml
cluster.initial_master_nodes: ["node-1"]
 curl -H "Content-Type: application/json" -XPUT localhost:9200/_settings -d '{ "index" : { "refresh_interval" : -1, "number_of_replicas" : 0 } }'

3:删除filebeat对文件的记录
/var/lib/filebeat/registry
删除这个里面的东西重启即可

相关讨论:https://discuss.elastic.co/t/problems-with-access-to-elasticsearch-form-outside-machine/172450

4:logstash进程杀不掉
initctl stop logstash

标签: none

添加新评论