Linux下Elasticsearch Curator找不到curator.yml及配置问题求助
解决Elasticsearch Curator配置文件问题及实现日志索引删除
1. 先搞清楚Curator版本问题
你遇到的--config参数报错,大概率是因为通过apt安装的Curator版本偏旧(比如4.x系列),和官方文档里针对5.x+版本的说明不匹配。先查下你的Curator版本:
curator --version
再看看该版本的命令帮助,确认正确的配置方式:
curator --help
如果是4.x版本:它压根不支持--config参数,要么直接用命令行参数指定ES连接信息,要么用默认路径/etc/curator/curator.yml的配置文件(不存在就自己建)。
如果是5.x+版本:那可能是你命令格式错了,正确格式应该是curator --config 配置文件路径 动作文件路径。
2. 创建对应版本的配置文件
针对5.x+版本
新建curator.yml,内容根据你的ES环境调整:
client: hosts: - 127.0.0.1 # 你的ES节点地址,多个的话继续加 port: 9200 # ES端口 use_ssl: false # 开HTTPS就改成true timeout: 30 # 连接超时时间 http_auth: # ES有认证的话填 "用户名:密码" logging: loglevel: INFO logfile: /var/log/curator.log # 可选,指定日志文件路径 logformat: default
针对4.x版本
新建/etc/curator/curator.yml(系统默认读取路径),内容示例:
client: hosts: - 127.0.0.1 port: 9200 use_ssl: False timeout: 30 http_auth: logging: loglevel: INFO logformat: default
3. 配置索引删除逻辑(分版本)
5.x+版本:需要单独的动作文件
新建delete_old_logs.yml,定义删除规则:
actions: 1: action: delete_indices description: "删除7天前的日志索引(匹配logstash-前缀)" options: ignore_empty_list: True # 没匹配到索引也不报错 disable_action: False # 启用该操作 filters: - filtertype: pattern kind: prefix value: logstash- # 改成你日志索引的前缀 - filtertype: age source: name # 根据索引名称里的时间判断 direction: older timestring: '%Y.%m.%d' # 索引名里的时间格式,比如logstash-2024.05.20 unit: days unit_count: 7 # 删除7天前的索引
4.x版本:直接用命令行参数
不用单独动作文件,直接通过命令指定删除规则。
4. 执行删除操作
5.x+版本
先测试(不实际删除,只看匹配的索引):
curator --config ./curator.yml --dry-run delete_old_logs.yml
确认没问题后正式执行:
curator --config ./curator.yml delete_old_logs.yml
4.x版本
先测试:
curator delete_indices --host 127.0.0.1 --port 9200 --prefix logstash- --older-than 7 --time-unit days --timestring '%Y.%m.%d' --dry-run
正式删除:
curator delete_indices --host 127.0.0.1 --port 9200 --prefix logstash- --older-than 7 --time-unit days --timestring '%Y.%m.%d'
5. 小提示
- 始终用
--dry-run先测试,避免误删重要索引 - 如果ES开了认证或HTTPS,记得在配置里加上对应参数
- 确保Curator运行用户有访问ES和读写配置/日志文件的权限
内容的提问来源于stack exchange,提问作者D. Misal
相关产品推荐
相关产品推荐

