elasticsearch X-Pack 401 Logstash无法连接到Elasticsearch,elasticsearch,logstash,elastic-stack,http-status-code-401,elk,elasticsearch,Logstash,Elastic Stack,Http Status Code 401,Elk" /> elasticsearch X-Pack 401 Logstash无法连接到Elasticsearch,elasticsearch,logstash,elastic-stack,http-status-code-401,elk,elasticsearch,Logstash,Elastic Stack,Http Status Code 401,Elk" />

elasticsearch X-Pack 401 Logstash无法连接到Elasticsearch

elasticsearch X-Pack 401 Logstash无法连接到Elasticsearch,elasticsearch,logstash,elastic-stack,http-status-code-401,elk,elasticsearch,Logstash,Elastic Stack,Http Status Code 401,Elk,重新启动Elasticsearch后,我更改了JVM堆大小,Logstash无法连接到Elasticsearch logstash.yml xpack.monitoring.enabled: true xpack.monitoring.elasticsearch.hosts: ["es:9200"] xpack.monitoring.elasticsearch.username: logstash_system xpack.monitoring.elasticsearch.password: p

重新启动Elasticsearch后,我更改了JVM堆大小,Logstash无法连接到Elasticsearch

logstash.yml

xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.hosts: ["es:9200"]
xpack.monitoring.elasticsearch.username: logstash_system
xpack.monitoring.elasticsearch.password: pass

原木仓库

[WARN][logstash.outputs.elasticsearch][main]试图恢复与已死亡ES实例的连接,但出现错误。{:url=>,:error\u type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError,:error=>“在url“”处获取了与ElasticSearch联系的响应代码'401'”}


使用相同凭证从logstash卷曲到es

logstash: curl -ulogstash_system es:9200
Enter host password for user 'logstash_system':
{
  "name" : "elasticsearch",
  "cluster_name" : "elasticsearch",
  "cluster_uuid" : "",
  "version" : {
    "number" : "7.5.0",
    "build_flavor" : "default",
    "build_type" : "rpm",
    "build_hash" : "",
    "build_date" : "2019-11-26T01:06:52.518245Z",
    "build_snapshot" : false,
    "lucene_version" : "8.3.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

您发布的日志存储配置主要关注xpack监控。我认为错误消息来自使用elasticsearch输出插件的管道。你们有这样的管道吗?如果是,请使用pipeline configuration.pipeline.yml
-pipeline.id:beats path.config:“{ls_conf_dir}}/beats.conf”-pipeline.id:rsyslog path.config:“{ls_conf_dir}/rsyslog.conf”
configs without creds这只是pipelines.yml中的声明。我们需要实际的实现(conf文件)。正如我之前问过你的,请用适当的缩进将代码添加到原始问题中……你发布的日志存储配置集中在xpack监控上。我认为错误消息来自使用elasticsearch输出插件的管道。你们有这样的管道吗?如果是,请使用pipeline configuration.pipeline.yml
-pipeline.id:beats path.config:“{ls_conf_dir}}/beats.conf”-pipeline.id:rsyslog path.config:“{ls_conf_dir}/rsyslog.conf”
configs without creds这只是pipelines.yml中的声明。我们需要实际的实现(conf文件)。正如我之前问过你的,请在你的原始问题中添加代码,并加上适当的缩进。。。