You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否在不重装Graylog及MongoDB的前提下重建损坏的Graylog OpenSearch实例?

重建Graylog OpenSearch索引(保留Graylog及MongoDB)

可以完全通过以下步骤重建OpenSearch索引,无需删除或重装Graylog与MongoDB:

操作步骤

  1. 停止Graylog服务
    避免操作过程中Graylog持续写入数据,执行:

    sudo systemctl stop graylog-server
    
  2. 清理损坏的OpenSearch索引

    • 先列出所有Graylog关联的索引,确认目标:
      curl -X GET 'http://<你的OpenSearch主机地址>:9200/_cat/indices?v'
      
      找到所有以graylog_开头的索引,以及graylog_deflector(偏转器索引)
    • 删除这些损坏的索引:
      curl -X DELETE 'http://<你的OpenSearch主机地址>:9200/graylog_*,graylog_deflector'
      
  3. 重置MongoDB中的Graylog索引元数据
    MongoDB存储了Graylog的索引集配置,需要清空旧数据:

    • 进入MongoDB的Graylog数据库:
      mongo graylog
      
    • 删除索引集配置:
      db.index_sets.remove({})
      
    • 删除偏转器状态记录:
      db.deflectors.remove({})
      
    • 退出MongoDB shell:exit
  4. 确保OpenSearch版本兼容
    确认当前使用的OpenSearch版本与你的Graylog版本匹配(参考Graylog官方版本兼容说明),如果之前是因为版本不兼容导致损坏,先将OpenSearch调整到兼容版本,再重启服务:

    sudo systemctl restart opensearch
    
  5. 重启Graylog服务

    sudo systemctl start graylog-server
    
  6. 重新创建Graylog索引集
    登录Graylog Web后台,进入System > Indices:

    • 点击Create index set,设置索引前缀(如graylog_)、分片数、副本数等参数(可使用默认配置)
    • 将新建的索引集设为默认索引集,确保后续日志能正常写入新索引

重要注意事项

  • 操作前务必备份MongoDB的Graylog数据库,防止误操作:
    mongodump --db graylog --out /path/to/your/backup/directory
    
  • 重建索引后,之前存储在OpenSearch中的日志数据会完全丢失,仅保留MongoDB中的Graylog配置数据(如用户、流规则、仪表盘等)

内容的提问来源于stack exchange,提问作者automator

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 15:40:01