Kibana无法连接Elasticsearch:ECONNREFUSED 192.168.253.6:9200求助
Kibana启动后自动崩溃问题排查求助
Kibana无法正常运行:启动后执行systemctl status kibana会短暂显示running,随后再次查询则显示failed,已排查数小时陷入僵局。
以下为关键配置文件及日志信息:
kibana.yml
server.port: 5601 server.host: "0.0.0.0" elasticsearch.hosts: ["https://0.0.0.0:9200"] logging: appenders: file: type: file fileName: /var/log/kibana/kibana.log layout: type: json root: appenders: - default - file pid.file: /run/kibana/kibana.pid xpack.encryptedSavedObjects.encryptionKey: mykey xpack.reporting.encryptionKey: mykey xpack.security.encryptionKey: mykey elasticsearch.hosts: ['https://192.168.253.6:9200'] elasticsearch.serviceAccountToken: mytoken elasticsearch.ssl.certificateAuthorities: [/var/lib/kibana/ca_1680987510447.crt] xpack.fleet.outputs: [{id: fleet-default-output, name: default, is_default: true, is_default_monitoring: true, type: elasticsearch, hosts: ['https://192.168.253.6:9200'], ca_trusted_fingerprint: ec46451962624a> server.ssl.enabled: true server.ssl.certificate: /etc/kibana/kibana-server.crt server.ssl.key: /etc/kibana/kibana-server.key server.publicBaseUrl: "https://192.168.253.6:5601"
elasticsearch.yml
path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: 0.0.0.0 xpack.security.enabled: true xpack.security.enrollment.enabled: true xpack.security.http.ssl: enabled: true keystore.path: certs/http.p12 xpack.security.transport.ssl: enabled: true verification_mode: certificate keystore.path: certs/transport.p12 truststore.path: certs/transport.p12 # Create a new cluster with the current node only # Additional nodes can still join the cluster later #cluster.initial_master_nodes: ["kali-purple.localdomain"] http.host: 0.0.0.0 discovery.type: single-node
metricbeat.yml
metricbeat.config.modules: path: ${path.config}/modules.d/*.yml reload.enabled: false setup.template.settings: index.number_of_shards: 1 index.codec: best_compression setup.kibana: host: "https://192.168.253.6" setup.kibana.ssl.enabled: true ssl.certificate_authorities: ["/etc/kibana/kibana-server_ca.crt"] setup.kibana.ssl.certificate: "/etc/kibana/kibana-server.crt" setup.kibana.ssl.key: "/etc/kibana/kibana-server.key" output.elasticsearch: # Array of hosts to connect to. hosts: ["https://192.168.253.6"] username: "elastic" password: "mypass" ssl.ca_trusted_fingerprint: myfingerprint processors: - add_host_metadata: ~ - add_cloud_metadata: ~ - add_docker_metadata: ~ - add_kubernetes_metadata: ~
/etc/hosts
127.0.0.1 localhost 192.168.253.6 kali-purple.localdomain kali-purple # The following lines are desirable for IPv6 capable hosts ::1 localhost ip6-localhost ip6-loopback ff02::1 ip6-allnodes ff02::2 ip6-allrouters
kibana.log末尾片段
"X-Pack Monitoring Cluster Alerts will not be available: connect ECONNREFUSED 192.168.253.6:9200" "Kibana is now unavailable (was critical)" "Starting monitoring stats collection" "Kibana is now available (was unavailable)" "Fleet Usage: {\"agents_enabled\":true,\"agents\":{\"total_enrolled\":1,\"healthy\..." "Stopping all plugins." "Monitoring stats collection is stopped", "Unable to retrieve version information from Elasticsearch nodes. connect ECONNREFUSED 192.168.253.6:9200" "error writing bulk events: \"connect ECONNREFUSED 192.168.253.6:9200"
排查思路与解决建议
- 优先验证Elasticsearch连通性:日志反复出现
connect ECONNREFUSED,先确认ES状态:- 执行
systemctl status elasticsearch查看ES是否正常运行 - 在Kibana服务器上执行
curl -k https://192.168.253.6:9200测试端口连通性(-k临时忽略证书验证)
- 执行
- 修复kibana.yml配置错误:
- 删除重复的
elasticsearch.hosts: ["https://0.0.0.0:9200"]行,保留指向192.168.253.6的配置 - 补全
xpack.fleet.outputs字段,当前末尾ec46451962624a>未闭合,需补全完整指纹并添加}}闭合结构
- 删除重复的
- 检查证书与权限:
- 确认
/var/lib/kibana/ca_1680987510447.crt文件存在,且Kibana用户拥有可读权限 - 对比ES HTTP证书的SHA256指纹与Kibana配置中的
ca_trusted_fingerprint是否一致,可通过openssl x509 -fingerprint -sha256 -in /path/to/elasticsearch/http.crt获取正确值
- 确认
- 修复目录权限:
- 确认
/run/kibana/和/var/log/kibana/目录的所有者为kibana用户,执行chown -R kibana:kibana /run/kibana /var/log/kibana修复
- 确认
- 查看完整崩溃日志:
- 执行
journalctl -u kibana -f实时监控Kibana服务日志,获取崩溃时的完整错误信息 - 检查ES日志
/var/log/elasticsearch/elasticsearch.log,确认是否有拒绝连接的相关记录
- 执行
内容的提问来源于stack exchange,提问作者Aehri
相关产品推荐
相关产品推荐

