无需Wazuh Agent,用Filebeat向Wazuh-Indexer传数据遇连接错误求排查
Filebeat连接Wazuh-Indexer超时问题排查
问题描述
尝试直接使用Filebeat向Wazuh-Indexer发送日志数据时,出现连接超时错误。
Filebeat配置
filebeat.inputs: - input_type: log paths: - /home/siem/first4.log enable: true output.elasticsearch: hosts: ["192.168.0.123:9200"] protocol: https index: "test" username: admin password: admin ssl.certificate_authorities: - /etc/filebeat/certs/root-ca.pem ssl.certificate: "/etc/filebeat/certs/filebeat-1.pem" ssl.key: "/etc/filebeat/certs/filebeat-1-key.pem" setup.template.json.enabled: false setup.ilm.overwrite: true setup.ilm.enabled: false setup.template.name: false setup.template.pattern: false #setup.template.json.path: '/etc/filebeat/wazuh-template.json' #setup.template.json.name: 'wazuh' #filebeat.modules: # - module: wazuh # alerts: # enabled: true # archives: # enabled: false
错误信息
2023-01-30T09:29:18.634Z ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://192.168.0.123:9200)): Get "https://192.168.0.123:9200": context deadline exceeded (Client.Timeout exceeded while awaiting headers) 2023-01-30T09:29:18.635Z INFO [publisher_pipeline_output] pipeline/output.go:145 Attempting to reconnect to backoff(elasticsearch(https://192.168.0.123:9200)) with 1 reconnect attempt(s) 2023-01-30T09:29:18.635Z INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer 2023-01-30T09:29:18.635Z INFO [publisher] pipeline/retry.go:223 done 2023-01-30T09:29:46.177Z INFO [monitoring] log/log.go:145 Non-zero metrics in the last 30s
排查与解决步骤
验证网络连通性
在Filebeat所在主机执行以下命令,测试能否正常访问Wazuh-Indexer:curl -vk https://192.168.0.123:9200 -u admin:admin若请求失败,优先排查:
- Wazuh-Indexer主机的防火墙是否开放9200端口
- 两台主机之间的路由是否正常
- Wazuh-Indexer服务是否处于运行状态
检查SSL证书配置
确认证书文件的路径、权限与有效性:ls -l /etc/filebeat/certs/确保:
- 证书路径配置正确,Filebeat进程拥有读取证书文件的权限(建议权限设为640,所属组为Filebeat运行用户)
root-ca.pem与Wazuh-Indexer使用的CA证书一致filebeat-1.pem和filebeat-1-key.pem未过期,且已在Wazuh-Indexer侧完成认证配置
核对Wazuh-Indexer监听配置
查看Wazuh-Indexer的elasticsearch.yml配置文件,确认其监听地址允许外部访问:network.host: 0.0.0.0 http.port: 9200 xpack.security.enabled: true同时验证Indexer服务状态:
systemctl status wazuh-indexer修正Filebeat配置细节
- 旧版
input_type参数已废弃,替换为type: log:filebeat.inputs: - type: log paths: - /home/siem/first4.log enabled: true setup.template.name和setup.template.pattern参数应为字符串类型,布尔值配置无效,建议直接删除或注释这两项
- 旧版
调整超时参数
若网络环境存在延迟,可在output.elasticsearch中增加超时配置:output.elasticsearch: # 其他原有配置... timeout: 30s
内容的提问来源于stack exchange,提问作者iq tech
相关产品推荐
相关产品推荐

