You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需Wazuh Agent,用Filebeat向Wazuh-Indexer传数据遇连接错误求排查

Filebeat连接Wazuh-Indexer超时问题排查

问题描述

尝试直接使用Filebeat向Wazuh-Indexer发送日志数据时,出现连接超时错误。

Filebeat配置

filebeat.inputs:
- input_type: log
  paths:
  - /home/siem/first4.log
  enable: true
output.elasticsearch:
  hosts: ["192.168.0.123:9200"]
  protocol: https
  index: "test"
  username: admin
  password: admin
  ssl.certificate_authorities:
    - /etc/filebeat/certs/root-ca.pem
  ssl.certificate: "/etc/filebeat/certs/filebeat-1.pem"
  ssl.key: "/etc/filebeat/certs/filebeat-1-key.pem"
setup.template.json.enabled: false
setup.ilm.overwrite: true
setup.ilm.enabled: false
setup.template.name: false
setup.template.pattern: false

#setup.template.json.path: '/etc/filebeat/wazuh-template.json'
#setup.template.json.name: 'wazuh'

#filebeat.modules:
#  - module: wazuh
#    alerts:
#      enabled: true
#    archives:
#      enabled: false

错误信息

2023-01-30T09:29:18.634Z        ERROR   [publisher_pipeline_output]     pipeline/output.go:154  Failed to connect to backoff(elasticsearch(https://192.168.0.123:9200)): Get "https://192.168.0.123:9200": context deadline exceeded (Client.Timeout exceeded while awaiting headers)
2023-01-30T09:29:18.635Z        INFO    [publisher_pipeline_output]     pipeline/output.go:145  Attempting to reconnect to backoff(elasticsearch(https://192.168.0.123:9200)) with 1 reconnect attempt(s)
2023-01-30T09:29:18.635Z        INFO    [publisher]     pipeline/retry.go:219   retryer: send unwait signal to consumer
2023-01-30T09:29:18.635Z        INFO    [publisher]     pipeline/retry.go:223     done
2023-01-30T09:29:46.177Z        INFO    [monitoring]    log/log.go:145  Non-zero metrics in the last 30s      

排查与解决步骤

  • 验证网络连通性
    在Filebeat所在主机执行以下命令,测试能否正常访问Wazuh-Indexer:

    curl -vk https://192.168.0.123:9200 -u admin:admin
    

    若请求失败,优先排查:

    • Wazuh-Indexer主机的防火墙是否开放9200端口
    • 两台主机之间的路由是否正常
    • Wazuh-Indexer服务是否处于运行状态
  • 检查SSL证书配置
    确认证书文件的路径、权限与有效性:

    ls -l /etc/filebeat/certs/
    

    确保:

    • 证书路径配置正确,Filebeat进程拥有读取证书文件的权限(建议权限设为640,所属组为Filebeat运行用户)
    • root-ca.pem与Wazuh-Indexer使用的CA证书一致
    • filebeat-1.pem和filebeat-1-key.pem未过期,且已在Wazuh-Indexer侧完成认证配置
  • 核对Wazuh-Indexer监听配置
    查看Wazuh-Indexer的elasticsearch.yml配置文件,确认其监听地址允许外部访问:

    network.host: 0.0.0.0
    http.port: 9200
    xpack.security.enabled: true
    

    同时验证Indexer服务状态:

    systemctl status wazuh-indexer
    
  • 修正Filebeat配置细节

    • 旧版input_type参数已废弃,替换为type: log:
      filebeat.inputs:
      - type: log
        paths:
        - /home/siem/first4.log
        enabled: true
      
    • setup.template.name和setup.template.pattern参数应为字符串类型,布尔值配置无效,建议直接删除或注释这两项
  • 调整超时参数
    若网络环境存在延迟,可在output.elasticsearch中增加超时配置:

    output.elasticsearch:
      # 其他原有配置...
      timeout: 30s
    

内容的提问来源于stack exchange,提问作者iq tech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 23:03:07