elasticsearch7.10.2 安装实战
elasticsearch 安装 安全配置
Es7.10.2安装:
1.下载es:
https://www.elastic.co/cn/downloads/past-releases/elasticsearch-7-10-2
useradd es_user
passwd es_user //123456
chgrp -R es_user /home/apps/elasticsearch-7.10.2
chown -R es_user /home/apps/elasticsearch-7.10.2
chmod 777 /home/apps/elasticsearch-7.10.2
2.修改配置
vim /etc/security/limits.conf
添加以下内容:
- soft nofile 65536
- hard nofile 65536
修改虚拟内存空间
vim /etc/sysctl.conf
vm.max_map_count=262144 //添加的内容
sysctl -p
cd elasticsearch-7.10.2/
cd config
vim jvm.options
-Xms512m
-Xmx512m
vim elasticsearch.yml
cluster.name: elk
node.name: esnode-0
path.data: /home/apps/elasticsearch-7.10.2/data
path.logs: /home/apps/elasticsearch-7.10.2/logs
network.host: 0.0.0.0
http.port: 9200
discovery.seed_hosts: [“192.168.234.131”,“192.168.234.132”,“192.168.234.133”]
cluster.initial_master_nodes: esnode-0
xpack.security.enabled: false
xpack.security.enrollment.enabled: false
ingest.geoip.downloader.enabled: false
3.创建数据目录
mkdir -p /home/apps/elasticsearch-7.10.2/data
chmod 777 data
chown es_user data
chgrp es_user data
4.启动
su - es_user
/home/apps/elasticsearch-7.10.2/bin/elasticsearch -d
注意:每个节点都执行启动命令
5.开启安全后需要
5.1.在ES的根目录生成CA证书
bin/elasticsearch-certutil ca
中间需要设置密码,直接回车可以不设置(慎重考虑)。
5.2.使用第一步生成的证书,产生p12密钥
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12
copy 2生成的 elastic-certificates.p12 到各个节点
5.3.config/elasticsearch.yml加入
xpack.security.enabled: true
xpack.license.self_generated.type: basic
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12
5.4.设置账户密码
./elasticsearch-setup-passwords interactive
设置的都是123456
更多推荐
所有评论(0)