二,开启ELK安全认证
从Elastic Stack6.8开始,原X-PACK中的安全功能已免费开放。
步骤1:在Elasticsearch主节点中配置TLS
/usr/share/elasticsearch/bin/elasticsearch-certutil cert -out /etc/elasticsearch/elastic-certificates.p12 -pass ""
编辑/etc/elasticsearch/elasticsearch.yml配置文件,添加如下配置,重启es服务
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
步骤2:配置Elasticsearch密码,执行以下命令,输入自定义密码
/usr/share/elasticsearch/bin/elasticsearch-setup-passwords interactive
步骤3:在Kibana中配置安全性,编辑/etc/kibana/kibana.yml配置文件,添加如下配置,重启kibana服务
elasticsearch.username: "kibana"
elasticsearch.password: "密码"