在AWS EC2上设置ElasticSearch初始密码时集群健康检测失败
解决Elasticsearch重置密码报错"Failed to determine the health of the cluster"
1. 先确认Elasticsearch服务状态
执行以下命令检查服务是否正常运行:
sudo systemctl status elasticsearch
如果服务未启动,先启动并等待集群稳定:
sudo systemctl start elasticsearch sleep 60
2. 修正重置密码命令参数
你的配置中启用了HTTP SSL加密,默认命令无法通过HTTPS连接集群,需要补充SSL相关参数:
推荐方式(单节点环境)
指定本地HTTPS地址和CA证书路径执行命令:
cd /usr/share/elasticsearch/bin ./elasticsearch-reset-password -u elasticsearch --url https://localhost:9200 --cacert /etc/elasticsearch/certs/http_ca.crt
按照提示输入新密码即可完成重置。
备选方式(通过传输端口连接)
如果本地HTTPS连接有问题,可通过集群内部传输端口连接,需要用到传输证书:
cd /usr/share/elasticsearch/bin ./elasticsearch-reset-password -u elasticsearch --transport --cacert /etc/elasticsearch/certs/transport.p12 --keystore /etc/elasticsearch/certs/transport.p12
注意:执行时需要输入keystore密码,自动生成的安全配置中,该密码可在ES日志文件/var/log/elasticsearch/elasticsearch.log中查找初始密码记录。
3. 清理配置文件冲突项
你的配置文件中同时存在network.host: ["0.0.0.0"]和http.host: 0.0.0.0,两者功能重叠,建议注释掉network.host配置,只保留http.host: 0.0.0.0,然后重启服务:
sudo systemctl restart elasticsearch
4. 验证密码有效性
重置完成后,用以下命令测试连接:
curl --cacert /etc/elasticsearch/certs/http_ca.crt -u elasticsearch:你的新密码 https://localhost:9200
返回集群信息即说明密码设置成功。
内容的提问来源于stack exchange,提问作者NULL
相关产品推荐
相关产品推荐

