You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用用户认证SSL连接Elasticsearch时Telegraf日志报401求助

Telegraf 1.25.0 Elasticsearch输入插件401认证错误调试方案

问题现象

Telegraf配置Elasticsearch输入插件后,持续输出以下错误:

[inputs.elasticsearch] Error in plugin: elasticsearch: API responded with status-code 401, expected 200

当前插件配置

# Read stats from one or more Elasticsearch servers or clusters
[[inputs.elasticsearch]]
  ## specify a list of one or more Elasticsearch servers
  # you can add username and password to your url to use basic authentication:
  # servers = ["http://user:pass@localhost:9200"]
  servers = ["https://elastic.server:9200"]

  ## Timeout for HTTP requests to the elastic search server(s)
  http_timeout = "5s"

  ## When local is true (the default), the node will read only its own stats.
  ## Set local to false when you want to read the node stats from all nodes
  ## of the cluster.
  local = false

  ## Set cluster_health to true when you want to also obtain cluster health stats
  cluster_health = true

  ## Adjust cluster_health_level when you want to also obtain detailed health stats
  ## The options are
  ##  - indices (default)
  ##  - cluster
  # cluster_health_level = "indices"

  ## Set cluster_stats to true when you want to also obtain cluster stats from the
  ## Master node.
  cluster_stats = true

  ## node_stats is a list of sub-stats that you want to have gathered. Valid options
  ## are "indices", "os", "process", "jvm", "thread_pool", "fs", "transport", "http",
  ## "breaker". Per default, all stats are gathered.
  # node_stats = ["jvm", "http"]

  ## Optional TLS Config
  tls_ca = "/etc/telegraf/ca.crt"
  tls_cert = "/etc/telegraf/clientcert.crt"
  tls_key = "/etc/telegraf/clientcert.key"
  ## Use TLS but skip chain & host verification
  # insecure_skip_verify = false

  username = "telegraf_user"
  password = "telegraf_user_password"

已验证操作

已尝试将用户名密码嵌入servers配置的URL中,且通过以下curl命令可正常访问Elasticsearch:

curl --cacert /etc/telegraf/ca.crt --cert /etc/telegraf/clientcert.crt --key /etc/telegraf/clientcert.key https://telegraf_user:telefraf_user_password@elkdevn1.dev.oati.local:9200/_nodes/_local/name

返回正常响应:

{"_nodes":{"total":1,"successful":1,"failed":0},"cluster_name":"elkcluster","nodes":{"nodeitentifier":{"name":"elastic.server","transport_address":"10.100.2.128:9300","host":"10.100.2.128","ip":"10.100.2.128","version":"7.16.2","build_flavor":"default","build_type":"rpm","build_hash":"2b937c44140b6559905130a8650c64dbd0879cfb","roles":["data","ingest","master"],"attributes":{"xpack.installed":"true","transform.node":"false"}}}}

调试方法:查看Telegraf具体请求

1. 开启Telegraf Debug日志

修改Telegraf配置文件,添加或修改日志级别:

[agent]
  log_level = "debug"

或者启动Telegraf时加上--debug参数:

telegraf --config /etc/telegraf/telegraf.conf --debug

Debug日志会输出Telegraf发起的所有HTTP请求细节,包括请求URL、请求头(如Authorization字段)、响应状态等,直接定位认证问题。

2. 抓包分析请求

使用tcpdump捕获Telegraf与Elasticsearch之间的流量:

tcpdump -i any port 9200 -w telegraf_es_traffic.pcap

生成的pcap文件可使用Wireshark打开,过滤HTTP请求,查看Telegraf是否正确发送了认证信息(Basic Auth头或客户端证书)。

3. 查看Elasticsearch访问日志

修改Elasticsearch的config/log4j2.properties配置,开启详细访问日志:

logger.http_access.name = org.elasticsearch.http.HttpServerTransport
logger.http_access.level = debug
logger.http_access.appenderRef.console.ref = console
logger.http_access.appenderRef.file.ref = rolling-file

重启Elasticsearch后,可在日志中看到Telegraf请求的完整细节,包括认证方式、用户信息等,判断是否是认证流程异常。

额外提示

注意到你提供的curl命令中密码拼写为telefraf_user_password,而Telegraf配置中是telegraf_user_password,请确认配置文件中的密码是否与实际使用的一致,避免拼写错误导致认证失败。

内容的提问来源于stack exchange,提问作者jceddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 05:24:56