You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux下Elasticsearch Curator找不到curator.yml及配置问题求助

解决Elasticsearch Curator配置文件问题及实现日志索引删除

1. 先搞清楚Curator版本问题

你遇到的--config参数报错,大概率是因为通过apt安装的Curator版本偏旧(比如4.x系列),和官方文档里针对5.x+版本的说明不匹配。先查下你的Curator版本:

curator --version

再看看该版本的命令帮助,确认正确的配置方式:

curator --help

如果是4.x版本:它压根不支持--config参数,要么直接用命令行参数指定ES连接信息,要么用默认路径/etc/curator/curator.yml的配置文件(不存在就自己建)。
如果是5.x+版本:那可能是你命令格式错了,正确格式应该是curator --config 配置文件路径 动作文件路径。

2. 创建对应版本的配置文件

针对5.x+版本

新建curator.yml,内容根据你的ES环境调整:

client:
  hosts:
    - 127.0.0.1  # 你的ES节点地址,多个的话继续加
  port: 9200     # ES端口
  use_ssl: false # 开HTTPS就改成true
  timeout: 30    # 连接超时时间
  http_auth:     # ES有认证的话填 "用户名:密码"

logging:
  loglevel: INFO
  logfile: /var/log/curator.log  # 可选,指定日志文件路径
  logformat: default

针对4.x版本

新建/etc/curator/curator.yml(系统默认读取路径),内容示例:

client:
  hosts:
    - 127.0.0.1
  port: 9200
  use_ssl: False
  timeout: 30
  http_auth:

logging:
  loglevel: INFO
  logformat: default

3. 配置索引删除逻辑(分版本)

5.x+版本:需要单独的动作文件

新建delete_old_logs.yml,定义删除规则:

actions:
  1:
    action: delete_indices
    description: "删除7天前的日志索引(匹配logstash-前缀)"
    options:
      ignore_empty_list: True  # 没匹配到索引也不报错
      disable_action: False    # 启用该操作
    filters:
    - filtertype: pattern
      kind: prefix
      value: logstash-  # 改成你日志索引的前缀
    - filtertype: age
      source: name      # 根据索引名称里的时间判断
      direction: older
      timestring: '%Y.%m.%d'  # 索引名里的时间格式,比如logstash-2024.05.20
      unit: days
      unit_count: 7     # 删除7天前的索引

4.x版本:直接用命令行参数

不用单独动作文件,直接通过命令指定删除规则。

4. 执行删除操作

5.x+版本

先测试(不实际删除,只看匹配的索引):

curator --config ./curator.yml --dry-run delete_old_logs.yml

确认没问题后正式执行:

curator --config ./curator.yml delete_old_logs.yml

4.x版本

先测试:

curator delete_indices --host 127.0.0.1 --port 9200 --prefix logstash- --older-than 7 --time-unit days --timestring '%Y.%m.%d' --dry-run

正式删除:

curator delete_indices --host 127.0.0.1 --port 9200 --prefix logstash- --older-than 7 --time-unit days --timestring '%Y.%m.%d'

5. 小提示

  • 始终用--dry-run先测试,避免误删重要索引
  • 如果ES开了认证或HTTPS,记得在配置里加上对应参数
  • 确保Curator运行用户有访问ES和读写配置/日志文件的权限

内容的提问来源于stack exchange,提问作者D. Misal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:53:01