You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu Server上ElasticSearch与Filebeat部署配置问题求助

解决ElasticSearch与Filebeat连接配置问题

1. 先处理curl的证书验证错误

你遇到的curl failed to verify the legitimacy of the server...错误,是因为新版ElasticSearch默认启用了HTTPS安全传输,用http协议访问会触发证书验证失败。直接用以下命令测试连通性:

curl -k "https://192.168.1.68:9200"

执行后输入elastic用户的密码,就能看到ES的响应信息。-k参数用于临时忽略自签名证书的验证,适合新手实验环境。

2. elasticsearch.yml的host配置

你之前设置的network.host: 0.0.0.0完全正确,这个配置让ES监听虚拟机所有网卡的请求,无需修改为其他值。另外补充一个关键配置,避免ES再次意外停止:
在elasticsearch.yml中添加或确保存在:

discovery.type: single-node

单节点ES必须添加该配置,否则会因找不到集群节点自动退出,这大概率是你之前ES意外停止的核心原因之一。

3. filebeat.yml的output.elasticsearch配置

直接填写ES所在虚拟机的实际IP192.168.1.68即可,不能填0.0.0.0(这是监听地址,不是连接目标地址),也不能填网段(192.168.1.0这类是网段标识,不是具体服务地址)。
同时因为ES启用了安全机制,需补充HTTPS相关配置,完整的output段示例:

output.elasticsearch:
  hosts: ["https://192.168.1.68:9200"]
  username: "elastic"
  password: "你生成的elastic密码"
  ssl.verification_mode: "none"  # 实验环境先关闭证书验证,后续再配置可信证书

4. 执行Filebeat setup的注意事项

执行命令时加上sudo,确保拥有足够权限读取配置文件和写入数据:

sudo /usr/share/filebeat/bin/filebeat setup -c /etc/filebeat/filebeat.yml --path.data /var/lib/filebeat --path.home /usr/share/filebeat

内容的提问来源于stack exchange,提问作者Nolan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 11:50:11