elasticsearch须要安装java 8 环境,配置JAVA_HOMEjava
查看是否有旧版本的javanode
java -verison
若是没有安装,能够进入官方选择适合本身的版本,下载地址:http://www.oracle.com/technetwork/java/javase/downloads/jdk8-downloads-2133151.htmllinux
下载并解压express
$ cd /usr/local/src $ wget --no-cookies --no-check-certificate --header "Cookie: gpw_e24=http%3A%2F%2Fwww.oracle.com%2F; oraclelicense=accept-securebackup-cookie" http://download.oracle.com/otn-pub/java/jdk/8u171-b11/512cd62ec5174c3487ac17c61aaa89e8/jdk-8u171-linux-x64.tar.gz $ tar zxvf jdk-8u171-linux-x64.tar.gz
配置环境变量bootstrap
# export PATH USER LOGNAME MAIL HOSTNAME HISTSIZE HISTCONTROL 以后加入下面内容 #jdk export JAVA_HOME=/usr/local/src/jdk1.8.0_171 export PATH=$JAVA_HOME/bin:$PATH export CLASSPATH=.:$JAVA_HOME/lib/dt.jar:$JAVA_HOME/lib/tools.jar
使配置生效vim
source /etc/profile
再次验证是否安装成功centos
java -version
java version "1.8.0_171" Java(TM) SE Runtime Environment (build 1.8.0_171-b11) Java HotSpot(TM) 64-Bit Server VM (build 25.171-b11, mixed mode)
查看变量浏览器
[root@VM_35_1_centos ~]# echo $JAVA_HOME /usr/local/src/jdk1.8.0_171
安装教程位置:安全
https://www.elastic.co/guide/en/elasticsearch/reference/5.6/install-elasticsearch.html
这里咱们使用tar包
cd /usr/local/src wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-5.6.9.tar.gz tar zxvf elasticsearch-5.6.9.tar.gz cd elasticsearch-5.6.9/
内存配置
默认的内存配置是2g,我学习用的机子内存较小(实际2g)会挂掉,因此我将内存改为1g(机子实际内存的一半)
vim /etc/elasticsearch/jvm.options
内容
-Xms1g -Xmx1g
启动
./bin/elasticsearch
若是你使用root用户启动,则会出现下面的报错
[2018-05-23T15:00:43,762][WARN ][o.e.b.ElasticsearchUncaughtExceptionHandler] [] uncaught exception in thread [main] org.elasticsearch.bootstrap.StartupException: java.lang.RuntimeException: can not run elasticsearch as root at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:136) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:123) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:70) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:134) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.cli.Command.main(Command.java:90) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:91) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:84) ~[elasticsearch-5.6.9.jar:5.6.9] Caused by: java.lang.RuntimeException: can not run elasticsearch as root at org.elasticsearch.bootstrap.Bootstrap.initializeNatives(Bootstrap.java:106) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:195) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:342) ~[elasticsearch-5.6.9.jar:5.6.9] at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:132) ~[elasticsearch-5.6.9.jar:5.6.9] ... 6 more
这是出于系统安全考虑设置的条件。因为ElasticSearch能够接收用户输入的脚本而且执行,为了系统安全考虑,
建议建立一个单独的用户用来运行ElasticSearch
建立elsearch用户组及elsearch用户
groupadd elsearch useradd elsearch -g elsearch -p elasticsearch cd /usr/local/src chown -R elsearch:elsearch elasticsearch-5.6.9
切换到elsearch用户再启动
su elsearch ./elasticsearch
这时你可能还会遇到下面的报错,max virtual memory areas vm.max_map_count [65530] is too low, increase to at least [262144]
解决方法是:
sudo sysctl -w vm.max_map_count=262144
再次启动
[elsearch@VM_35_1_centos elasticsearch-5.6.9]$ ./bin/elasticsearch [2018-05-23T15:09:55,323][INFO ][o.e.n.Node ] [] initializing ... [2018-05-23T15:09:55,546][INFO ][o.e.e.NodeEnvironment ] [ndB4c4F] using [1] data paths, mounts [[/ (rootfs)]], net usable_space [44.7gb], net total_space [49gb], spins? [unknown], types [rootfs] [2018-05-23T15:09:55,546][INFO ][o.e.e.NodeEnvironment ] [ndB4c4F] heap size [1015.6mb], compressed ordinary object pointers [true] [2018-05-23T15:09:55,547][INFO ][o.e.n.Node ] node name [ndB4c4F] derived from node ID [ndB4c4FLRxWlhH_94CN70Q]; set [node.name] to override [2018-05-23T15:09:55,548][INFO ][o.e.n.Node ] version[5.6.9], pid[3857], build[877a590/2018-04-12T16:25:14.838Z], OS[Linux/3.10.0-514.21.1.el7.x86_64/amd64], JVM[Oracle Corporation/Java HotSpot(TM) 64-Bit Server VM/1.8.0_171/25.171-b11] [2018-05-23T15:09:55,548][INFO ][o.e.n.Node ] JVM arguments [-Xms1g, -Xmx1g, -XX:+UseConcMarkSweepGC, -XX:CMSInitiatingOccupancyFraction=75, -XX:+UseCMSInitiatingOccupancyOnly, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -Djdk.io.permissionsUseCanonicalPath=true, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Dlog4j.skipJansi=true, -XX:+HeapDumpOnOutOfMemoryError, -Des.path.home=/usr/local/src/elasticsearch-5.6.9] [2018-05-23T15:09:57,152][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [aggs-matrix-stats] [2018-05-23T15:09:57,152][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [ingest-common] [2018-05-23T15:09:57,152][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [lang-expression] [2018-05-23T15:09:57,152][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [lang-groovy] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [lang-mustache] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [lang-painless] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [parent-join] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [percolator] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [reindex] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [transport-netty3] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] loaded module [transport-netty4] [2018-05-23T15:09:57,153][INFO ][o.e.p.PluginsService ] [ndB4c4F] no plugins loaded [2018-05-23T15:10:00,188][INFO ][o.e.d.DiscoveryModule ] [ndB4c4F] using discovery type [zen] [2018-05-23T15:10:01,225][INFO ][o.e.n.Node ] initialized [2018-05-23T15:10:01,225][INFO ][o.e.n.Node ] [ndB4c4F] starting ... [2018-05-23T15:10:01,505][INFO ][o.e.t.TransportService ] [ndB4c4F] publish_address {127.0.0.1:9300}, bound_addresses {127.0.0.1:9300} [2018-05-23T15:10:04,656][INFO ][o.e.c.s.ClusterService ] [ndB4c4F] new_master {ndB4c4F}{ndB4c4FLRxWlhH_94CN70Q}{HfnS160SQP2XrgYtuEKX0w}{127.0.0.1}{127.0.0.1:9300}, reason: zen-disco-elected-as-master ([0] nodes joined)[, ] [2018-05-23T15:10:04,728][INFO ][o.e.h.n.Netty4HttpServerTransport] [ndB4c4F] publish_address {127.0.0.1:9200}, bound_addresses {127.0.0.1:9200} [2018-05-23T15:10:04,728][INFO ][o.e.n.Node ] [ndB4c4F] started [2018-05-23T15:10:04,809][INFO ][o.e.g.GatewayService ] [ndB4c4F] recovered [0] indices into cluster_state
发现started关键字,而且发现监听127.0.0.1:9200端口,elasticsearch默认监听9200端口
使用curl测试是否安装成功
[root@VM_35_1_centos log]# curl localhost:9200 { "name" : "ndB4c4F", "cluster_name" : "elasticsearch", "cluster_uuid" : "X0k8EhwGThCjnf-cTkSpTg", "version" : { "number" : "5.6.9", "build_hash" : "877a590", "build_date" : "2018-04-12T16:25:14.838Z", "build_snapshot" : false, "lucene_version" : "6.6.1" }, "tagline" : "You Know, for Search" }
Kibana是一个为 ElasticSearch 提供的数据分析的 Web 接口。可以使用它对日志进行高效的搜索、可视化、分析等各类操做。
https://www.elastic.co/guide/en/kibana/5.6/install.html
cd /usr/local/src wget https://artifacts.elastic.co/downloads/kibana/kibana-5.6.9-linux-x86_64.tar.gz tar zxvf kibana-5.6.9-linux-x86_64.tar.gz cd kibana-5.6.9-linux-x86_64/
修改kibana配置,能够外网访问
vim ./config/kibana.yml
内容
server.port: 5601 server.host: "0.0.0.0"
能够浏览器访问xxx.xxx.xxx.xxx:5601
注意其中的Monitoring 默认是没有的,是由X-Pack集成提供的。该X-pack监控组件使您能够经过Kibana轻松地监控ElasticSearch。您能够实时查看集群的健康和性能,以及分析过去的集群、索引和节点度量。此外,能够监视Kibana自己性能。
Elasticsearch下载X-Pack
在Es的根目录(每一个节点),运行 bin/elasticsearch-plugin进行安装。
bin/elasticsearch-plugin install x-pack
若是你在Elasticsearch已禁用自动索引的建立,在elasticsearch.yml配置action.auto_create_index容许X-pack创造如下指标:
action.auto_create_index: ".security*,.monitoring*,.watches,.triggered_watches,.watcher-history*"
Kibana下载X-Pack
在Kibana根目录运行 bin/kibana-plugin 进行安装。
bin/kibana-plugin install x-pack
实际上一个服务器只会部署一个节点,可是为了学习elasticsearch的分布特性,这里探索启动多个节点。
使用elasticsearch-5.6.9再复制一份,而后更改用户组
cd /usr/local/src cp -r elasticsearch-5.6.9 elastic-slave1 chown -R elsearch:elsearch elastic-slave1
因为内存过小,因此再次调整了master和slave的配置
/usr/local/src/elasticsearch-5.6.9/config/jvm.options
/usr/local/src/elastic-slave1/config/jvm.options
-Xms256m -Xmx256m
/usr/local/src/elasticsearch-5.6.9/config/elasticsearch.yml
cluster.name: test node.name: master node.master: true network.host: 127.0.0.1 action.auto_create_index: ".security*,.monitoring*,.watches,.triggered_watches,.watcher-history*"
/usr/local/src/elastic-slave1/config/elasticsearch.yml
cluster.name: test node.name: slave1 network.host: 127.0.0.1 http.port: 8200 discovery.zen.ping.unicast.hosts: ["127.0.0.1"] action.auto_create_index: ".security*,.monitoring*,.watches,.triggered_watches,.watcher-history*"
分别运行master和slave的程序
./bin/elasticsearch
运行kibana
./bin/kibana
在浏览器上输入: http://xxx.xxx.xxx.xxx:5601/
,打开Kibana,要输入用户名和密码登陆,默认分别是 elastic
和 changeme
,能够很方便的看到节点的状况
注意:复制的elastic-salve1文件夹下包含了data文件中源文件节点数据,须要把elastic-salve1文件夹下data文件下的文件清空,不然会出现下面相似错误。
[2018-05-23T17:52:48,839][INFO ][o.e.d.z.ZenDiscovery ] [slave-2] failed to send join request to master [{master}{iErWGFrwSuCTjXaOD9jE5g}{JHJNb1U_TVaqdNVoJmEBZw}{127.0.0.1}{127.0.0.1:9300}{ml.max_open_jobs=10, ml.enabled=true}], reason [RemoteTransportException[[master][127.0.0.1:9300][internal:discovery/zen/join]]; nested: IllegalArgumentException[can't add node {slave-2}{iErWGFrwSuCTjXaOD9jE5g}{uo1SvmJyTESE_Z6bcQrOeg}{127.0.0.1}{127.0.0.1:9301}{ml.max_open_jobs=10, ml.enabled=true}, found existing node {master}{iErWGFrwSuCTjXaOD9jE5g}{JHJNb1U_TVaqdNVoJmEBZw}{127.0.0.1}{127.0.0.1:9300}{ml.max_open_jobs=10, ml.enabled=true} with the same id but is a different node instance]; ]
http://www.ruanyifeng.com/blog/2017/08/elasticsearch.html
https://www.cnblogs.com/wxw16/p/6156335.html