Azure Elasticsearch服务能否作为Grafana数据源?9200端口如何开放?
问题描述
我正在Grafana中配置Elasticsearch数据源,按照官方文档操作。我的Elasticsearch是Azure上的Elastic Observability(Elasticsearch)原生ISV服务,配置数据源时使用Azure提供的URL加9200端口,但无法建立连接。
我用以下命令测试9200端口是否开放:
test-NetConnection xxx.es.westeurope.azure.elastic-cloud.com -Port 9200 WARNING: TCP connect to (20.xxx.xxx.29 : 9200) failed ComputerName : xxxx.es.westeurope.azure.elastic-cloud.com RemoteAddress : 20.xxx.xxx.29 RemotePort : 9200 InterfaceAlias : Ethernet 4 SourceAddress : 10.xx.xxx.59 PingSucceeded : True PingReplyDetails (RTT) : 20 ms TcpTestSucceeded : False
测试结果显示9200端口未开放。我查资料得知要修改Elasticsearch的network.host=0.0.0.0配置来开放端口,但在Azure Elasticsearch门户中设置该配置时,系统提示:
Save configuration settings? Your changes cannot be applied Elasticsearch - 'network.host': is not allowed Elasticsearch - 'network.host': is not allowed Elasticsearch - 'network.host': is not allowed Elasticsearch - 'network.host': is not allowed Elasticsearch - 'network.host': is not allowed Elasticsearch - 'network.host': is not allowed Elasticsearch - 'network.host': is not allowed Set network.host to 0.0.0.0 No significant Kibana configuration changes No significant APM configuration changes No significant Integrations Server configuration changes No significant Enterprise Search configuration changes
即使我是Elasticsearch服务管理员,也无法修改该配置。因此我有两个问题:
- Azure Elasticsearch服务是否可以作为Grafana的数据源?
- 如果可以,如何开放其9200端口以配置为Grafana数据源?
解答
Azure Elastic Observability(Elasticsearch)原生ISV服务可以作为Grafana的数据源,官方支持该集成场景。
关于端口配置的问题:
- Azure托管的Elastic Cloud服务默认不对外暴露9200端口,这是托管服务的安全设计,且
network.host属于平台受保护配置,用户无权修改。 - 正确的配置方式是使用HTTPS的9243端口(Elasticsearch的安全通信端口):
- 在Grafana的Elasticsearch数据源配置页,将URL改为Azure提供的服务地址加
:9243(示例:https://xxx.es.westeurope.azure.elastic-cloud.com:9243)。 - 启用TLS/SSL选项,确保连接使用加密通信。
- 认证方式选择用户名/密码,使用Azure Elastic服务中创建的具备访问权限的账号(如elastic管理员账号或自定义角色账号)。
- 在Grafana的Elasticsearch数据源配置页,将URL改为Azure提供的服务地址加
- 额外注意:需确保Grafana所在网络能访问Azure Elastic服务的9243端口:
- 若Grafana部署在Azure内网,可通过VNet对等连接或私有端点建立安全访问;
- 若为公网环境,需在Azure Elastic服务的防火墙规则中添加Grafana的公网IP白名单。
- Azure托管的Elastic Cloud服务默认不对外暴露9200端口,这是托管服务的安全设计,且
内容的提问来源于stack exchange,提问作者Moral
相关产品推荐
相关产品推荐

