You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kibana无法连接Elasticsearch:ECONNREFUSED 192.168.253.6:9200求助

Kibana启动后自动崩溃问题排查求助

Kibana无法正常运行:启动后执行systemctl status kibana会短暂显示running,随后再次查询则显示failed,已排查数小时陷入僵局。

以下为关键配置文件及日志信息:

kibana.yml

server.port: 5601

server.host: "0.0.0.0"

elasticsearch.hosts: ["https://0.0.0.0:9200"]

logging:
  appenders:
    file:
      type: file
      fileName: /var/log/kibana/kibana.log
      layout:
        type: json
  root:
    appenders:
      - default
      - file

pid.file: /run/kibana/kibana.pid

xpack.encryptedSavedObjects.encryptionKey: mykey
xpack.reporting.encryptionKey: mykey
xpack.security.encryptionKey: mykey

elasticsearch.hosts: ['https://192.168.253.6:9200']
elasticsearch.serviceAccountToken: mytoken
elasticsearch.ssl.certificateAuthorities: [/var/lib/kibana/ca_1680987510447.crt]
xpack.fleet.outputs: [{id: fleet-default-output, name: default, is_default: true, is_default_monitoring: true, type: elasticsearch, hosts: ['https://192.168.253.6:9200'], ca_trusted_fingerprint: ec46451962624a>

server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/kibana-server.crt
server.ssl.key: /etc/kibana/kibana-server.key
server.publicBaseUrl: "https://192.168.253.6:5601"

elasticsearch.yml

path.data: /var/lib/elasticsearch

path.logs: /var/log/elasticsearch

network.host: 0.0.0.0

xpack.security.enabled: true

xpack.security.enrollment.enabled: true

xpack.security.http.ssl:
  enabled: true
  keystore.path: certs/http.p12

xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
# Create a new cluster with the current node only
# Additional nodes can still join the cluster later
#cluster.initial_master_nodes: ["kali-purple.localdomain"]

http.host: 0.0.0.0

discovery.type: single-node

metricbeat.yml

metricbeat.config.modules:
  path: ${path.config}/modules.d/*.yml

  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1
  index.codec: best_compression

setup.kibana:
  host: "https://192.168.253.6"
  setup.kibana.ssl.enabled: true
  ssl.certificate_authorities: ["/etc/kibana/kibana-server_ca.crt"]
  setup.kibana.ssl.certificate: "/etc/kibana/kibana-server.crt"
  setup.kibana.ssl.key: "/etc/kibana/kibana-server.key"

  output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["https://192.168.253.6"]
  username: "elastic"
  password: "mypass"
  ssl.ca_trusted_fingerprint: myfingerprint

  processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

/etc/hosts

127.0.0.1       localhost
192.168.253.6   kali-purple.localdomain kali-purple

# The following lines are desirable for IPv6 capable hosts
::1     localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

kibana.log末尾片段

"X-Pack Monitoring Cluster Alerts will not be available: connect ECONNREFUSED 192.168.253.6:9200"
"Kibana is now unavailable (was critical)"
"Starting monitoring stats collection"
"Kibana is now available (was unavailable)"
"Fleet Usage: {\"agents_enabled\":true,\"agents\":{\"total_enrolled\":1,\"healthy\..."
"Stopping all plugins."
"Monitoring stats collection is stopped",
"Unable to retrieve version information from Elasticsearch nodes. connect ECONNREFUSED 192.168.253.6:9200"
"error writing bulk events: \"connect ECONNREFUSED 192.168.253.6:9200"

排查思路与解决建议

  • 优先验证Elasticsearch连通性:日志反复出现connect ECONNREFUSED,先确认ES状态:
    • 执行systemctl status elasticsearch查看ES是否正常运行
    • 在Kibana服务器上执行curl -k https://192.168.253.6:9200测试端口连通性(-k临时忽略证书验证)
  • 修复kibana.yml配置错误:
    • 删除重复的elasticsearch.hosts: ["https://0.0.0.0:9200"]行,保留指向192.168.253.6的配置
    • 补全xpack.fleet.outputs字段,当前末尾ec46451962624a>未闭合,需补全完整指纹并添加}}闭合结构
  • 检查证书与权限:
    • 确认/var/lib/kibana/ca_1680987510447.crt文件存在,且Kibana用户拥有可读权限
    • 对比ES HTTP证书的SHA256指纹与Kibana配置中的ca_trusted_fingerprint是否一致,可通过openssl x509 -fingerprint -sha256 -in /path/to/elasticsearch/http.crt获取正确值
  • 修复目录权限:
    • 确认/run/kibana/和/var/log/kibana/目录的所有者为kibana用户,执行chown -R kibana:kibana /run/kibana /var/log/kibana修复
  • 查看完整崩溃日志:
    • 执行journalctl -u kibana -f实时监控Kibana服务日志,获取崩溃时的完整错误信息
    • 检查ES日志/var/log/elasticsearch/elasticsearch.log,确认是否有拒绝连接的相关记录

内容的提问来源于stack exchange,提问作者Aehri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 18:32:21