使用用户认证SSL连接Elasticsearch时Telegraf日志报401求助
Telegraf 1.25.0 Elasticsearch输入插件401认证错误调试方案
问题现象
Telegraf配置Elasticsearch输入插件后,持续输出以下错误:
[inputs.elasticsearch] Error in plugin: elasticsearch: API responded with status-code 401, expected 200
当前插件配置
# Read stats from one or more Elasticsearch servers or clusters [[inputs.elasticsearch]] ## specify a list of one or more Elasticsearch servers # you can add username and password to your url to use basic authentication: # servers = ["http://user:pass@localhost:9200"] servers = ["https://elastic.server:9200"] ## Timeout for HTTP requests to the elastic search server(s) http_timeout = "5s" ## When local is true (the default), the node will read only its own stats. ## Set local to false when you want to read the node stats from all nodes ## of the cluster. local = false ## Set cluster_health to true when you want to also obtain cluster health stats cluster_health = true ## Adjust cluster_health_level when you want to also obtain detailed health stats ## The options are ## - indices (default) ## - cluster # cluster_health_level = "indices" ## Set cluster_stats to true when you want to also obtain cluster stats from the ## Master node. cluster_stats = true ## node_stats is a list of sub-stats that you want to have gathered. Valid options ## are "indices", "os", "process", "jvm", "thread_pool", "fs", "transport", "http", ## "breaker". Per default, all stats are gathered. # node_stats = ["jvm", "http"] ## Optional TLS Config tls_ca = "/etc/telegraf/ca.crt" tls_cert = "/etc/telegraf/clientcert.crt" tls_key = "/etc/telegraf/clientcert.key" ## Use TLS but skip chain & host verification # insecure_skip_verify = false username = "telegraf_user" password = "telegraf_user_password"
已验证操作
已尝试将用户名密码嵌入servers配置的URL中,且通过以下curl命令可正常访问Elasticsearch:
curl --cacert /etc/telegraf/ca.crt --cert /etc/telegraf/clientcert.crt --key /etc/telegraf/clientcert.key https://telegraf_user:telefraf_user_password@elkdevn1.dev.oati.local:9200/_nodes/_local/name
返回正常响应:
{"_nodes":{"total":1,"successful":1,"failed":0},"cluster_name":"elkcluster","nodes":{"nodeitentifier":{"name":"elastic.server","transport_address":"10.100.2.128:9300","host":"10.100.2.128","ip":"10.100.2.128","version":"7.16.2","build_flavor":"default","build_type":"rpm","build_hash":"2b937c44140b6559905130a8650c64dbd0879cfb","roles":["data","ingest","master"],"attributes":{"xpack.installed":"true","transform.node":"false"}}}}
调试方法:查看Telegraf具体请求
1. 开启Telegraf Debug日志
修改Telegraf配置文件,添加或修改日志级别:
[agent] log_level = "debug"
或者启动Telegraf时加上--debug参数:
telegraf --config /etc/telegraf/telegraf.conf --debug
Debug日志会输出Telegraf发起的所有HTTP请求细节,包括请求URL、请求头(如Authorization字段)、响应状态等,直接定位认证问题。
2. 抓包分析请求
使用tcpdump捕获Telegraf与Elasticsearch之间的流量:
tcpdump -i any port 9200 -w telegraf_es_traffic.pcap
生成的pcap文件可使用Wireshark打开,过滤HTTP请求,查看Telegraf是否正确发送了认证信息(Basic Auth头或客户端证书)。
3. 查看Elasticsearch访问日志
修改Elasticsearch的config/log4j2.properties配置,开启详细访问日志:
logger.http_access.name = org.elasticsearch.http.HttpServerTransport logger.http_access.level = debug logger.http_access.appenderRef.console.ref = console logger.http_access.appenderRef.file.ref = rolling-file
重启Elasticsearch后,可在日志中看到Telegraf请求的完整细节,包括认证方式、用户信息等,判断是否是认证流程异常。
额外提示
注意到你提供的curl命令中密码拼写为telefraf_user_password,而Telegraf配置中是telegraf_user_password,请确认配置文件中的密码是否与实际使用的一致,避免拼写错误导致认证失败。
内容的提问来源于stack exchange,提问作者jceddy
相关产品推荐
相关产品推荐

