td-agent对接Elasticsearch报错:客户端与服务器版本不兼容
问题分析与解决方案
核心问题
当前安装的fluent-plugin-elasticsearch 5.2.4依赖的Elasticsearch Ruby客户端版本为8.4.0,而你的Elasticsearch服务器版本与该客户端版本不兼容(大概率是ES 7.x或更低版本)。
版本兼容矩阵
| Elasticsearch服务器版本 | 推荐fluent-plugin-elasticsearch版本 | 依赖的Ruby客户端版本 |
|---|---|---|
| 8.x | 5.x(如5.2.4) | 8.x |
| 7.x | 4.x(如4.4.3) | 7.x |
| 6.x | 3.x(如3.14.0) | 6.x |
解决步骤
1. 确认Elasticsearch服务器版本
执行命令查询你的ES版本:
curl http://35.171.30.19:9200/
返回结果中version.number字段即为ES服务器版本。
2. 卸载不兼容的插件版本
使用td-agent自带的gem工具卸载当前插件:
sudo /opt/td-agent/bin/fluent-gem uninstall fluent-plugin-elasticsearch
3. 安装匹配的插件版本
根据你的ES版本选择对应命令:
- ES 7.x:
sudo /opt/td-agent/bin/fluent-gem install fluent-plugin-elasticsearch -v 4.4.3 - ES 6.x:
sudo /opt/td-agent/bin/fluent-gem install fluent-plugin-elasticsearch -v 3.14.0 - ES 8.x:若确认ES是8.x仍报错,可临时在
<match>块添加verify_version false配置(不推荐长期使用,建议排查ES服务器API权限)。
4. 验证安装结果
sudo /opt/td-agent/bin/fluent-gem list fluent-plugin-elasticsearch
确认输出的版本与你安装的一致。
5. 重启td-agent服务
sudo systemctl restart td-agent
额外配置注意事项
- 若你的ES版本为7.x及以上,索引名称
index_name test需保持小写,ES默认禁止大写索引名。 - 若ES开启了SSL加密,需在
<match>块中补充配置:ssl_verify false # 无需证书验证时使用,或指定ca_file路径 scheme https
内容的提问来源于stack exchange,提问作者S Andrew
相关产品推荐
相关产品推荐

