出現這個問題是因為 elasticsearch 配置密碼以后 logstash啟動時連接 es 遇到認證問題,解決方法需要在logstash 配置文件中配置賬號密碼
vim /app/logstash/config/beat_es.conf
input { beats { port => 5044 } } filter { #只對nginx的json日志做json解析,系統message為其他格式,無需處理 if [fields][log_type] == "nginx"{ json { source => "message" remove_field => ["beat","offset","tags","prospector"] #移除字段,不需要采集 } date { match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"] #匹配timestamp字段 target => "@timestamp" #將匹配到的數據寫到@timestamp字段中 } } } output { if [fields][log_type] == "ruoyi" { elasticsearch { hosts => ["node1:9200","node2:9200"] user => elastic password => "123123" index => "ruoyi_log" timeout => 300 } } }