Elasticsearch 7.1.1 cluster construction

1 prepare the installation environment

1.1 installing JDK

elasticsearch 7.1.1 configuring java8, java11

1.2 change system resource configuration

  • Modify / etc / sysctl Conf file, add VM. Conf at the end of the file max_ map_ count=262144

    Note: after modification, execute sysctl -p, and load system parameters from the specified file. If not specified, start / etc / sysctl Loading in conf

    View the result sysctl - a|grep VM max_ map_ count

  • Modify / etc / security / limits Conf file

    # Add the following permanent system tuning at the end of the file, modify the file descriptor size (65536) and the maximum number of processes
    # *Represents the user name of all services. Users can also be set, such as esuser
    * soft nofile 65536
    * hard nofile 65536
    * soft nproc 4096
    * hard nproc 4096

2. Install Elasticsearch cluster

2.1 preparing cluster configuration

The three machines are used to save data and can be selected as the master node

Machine ipmaster nodedata nodeedition

2.1.1 create esuser user

# Add user group
groupadd esuser
# Add user
useradd -m -g esuser esuser
# Configure Ciphers
passwd esuser
# Add sudo permission at the end

2.2 download & install

# download
wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.1.1-linux-x86_64.tar.gz
# decompression
tar xvf elasticsearch-7.1.1-linux-x86_64.tar.gz
# Soft chain
ln -s elasticsearch-7.1.1 elasticsearch

2.3 configuration

2.3.1 configuration description

cluster.nameCluster name. The same name is a cluster
node.nameNode name. Each node name is unique in cluster mode
node.masterWhether the current node can be elected as a master node: true, No: false
node.dataWhether the current node is used to store data. Yes: true, No: false
path.dataLocation of index data
path.logsLocation of log files
bootstrap.memory_lockPhysical memory needs to be locked. Yes: true, No: false
bootstrap.system_call_filterSecComp detection, yes: true, No: false
network.hostListening address, used to access the es
network.publish_hostIt can be set as intranet ip for communication between machines in the cluster
http.portThe http port provided by es is 9200 by default
discovery.seed_hostses7. For the configuration added after X, write the device address of the candidate master node. After the service is started, it can be selected as the master node
cluster.initial_master_nodeses7.x. This configuration is required to elect a master when initializing a new cluster
http.cors.enabledWhether cross domain is supported is: true. This configuration is required when using the head plug-in
http.cors.allow-origin"*" indicates that all domain names are supported

2.3.2 detailed configuration

  • configuration

    # 7.1.1 configuration
    # Add the following:
    cluster.name: my-application
    node.name: node-1
    node.master: true
    node.data: true
    path.data: /data/es/9200/data1,/data/es/9200/data2,/data/es/9200/data3
    path.logs: /data/es/9200/logs
    bootstrap.memory_lock: false
    bootstrap.system_call_filter: false
    # Sometimes this configuration is not required, but I need it here
    # network.publish_host:
    transport.tcp.port: 9300
    http.port: 9200
    # discovery.seed_hosts: ["","",""]
    discovery.seed_hosts: ["","",""]
    cluster.initial_master_nodes: ["","",""]
    gateway.recover_after_nodes: 2
    cluster.routing.allocation.disk.threshold_enabled: false
    http.cors.enabled: true
    http.cors.allow-origin: "*"

  • configuration

    # 7.1.1 configuration
    # Add the following:
    cluster.name: my-application
    node.name: node-2
    node.master: true
    node.data: true
    path.data: /data/es/9200/data1,/data/es/9200/data2,/data/es/9200/data3
    path.logs: /data/es/9200/logs
    bootstrap.memory_lock: false
    bootstrap.system_call_filter: false
    # Sometimes this configuration is not required, but I need it here
    # network.publish_host:
    transport.tcp.port: 9300
    http.port: 9200
    # discovery.seed_hosts: ["","",""]
    discovery.seed_hosts: ["","",""]
    cluster.initial_master_nodes: ["","",""]
    gateway.recover_after_nodes: 2
    cluster.routing.allocation.disk.threshold_enabled: false
    http.cors.enabled: true
    http.cors.allow-origin: "*"

  • configuration

    # 7.1.1 configuration
    # Add the following:
    cluster.name: my-application
    node.name: node-3
    node.master: true
    node.data: true
    path.data: /data/es/9200/data1,/data/es/9200/data2,/data/es/9200/data3
    path.logs: /data/es/9200/logs
    bootstrap.memory_lock: false
    bootstrap.system_call_filter: false
    # Sometimes this configuration is not required, but I need it here
    # network.publish_host:
    transport.tcp.port: 9300
    http.port: 9200
    # discovery.seed_hosts: ["","",""]
    discovery.seed_hosts: ["","",""]
    cluster.initial_master_nodes: ["","",""]
    gateway.recover_after_nodes: 2
    cluster.routing.allocation.disk.threshold_enabled: false
    http.cors.enabled: true
    http.cors.allow-origin: "*"

2.3.3 modify the JVM option


2.3.4 add es installation directory permission

chown -R esuser:esuser /opt/es

2.3.5 start the cluster

# Background operation
./elasticsearch -d

The successful startup interface is as follows:



2.3.6 setting cluster authentication password generate certificate on the machine:

bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""

Note: the password needs to be set separately. Here is the cluster security authentication. It is recommended not to set the password. The certificate generated after success is in the config directory of es by default p12; Copy a copy to the config of other nodes (default directory) in elasticsearch YML configuration add configuration

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12 restart the cluster and change the password

bin/elasticsearch-setup-passwords interactive
  • elastic account: it has the super user role and is a built-in super user.

  • Kibana account: own kibana_system role. Kibana is used to connect and communicate with elasticsearch. The kibana server submits a request as the user to access the cluster monitoring API and Kibana index. Cannot access index.

  • logstash_system account: own logstash_system role. The user Logstash is used when storing monitoring information in Elasticsearch.

  • beats_system account: owned beats_system role. User Beats is used when storing monitoring information in Elasticsearch.

3 install Kibana

# kibana.yml configuration
server.port: 5601
server.host: ""
elasticsearch.hosts: ["","",""]
elasticsearch.username: "elastic"
elasticsearch.password: "123456"

Attachment: complete configuration

  • configuration

    # 7.1.1 configuration
    # Add the following:
    cluster.name: my-application
    node.name: node-1
    node.master: true
    node.data: true
    path.data: /data/es/9200/data1,/data/es/9200/data2,/data/es/9200/data3
    path.logs: /data/es/9200/logs
    bootstrap.memory_lock: false
    bootstrap.system_call_filter: false
    # Sometimes this configuration is not required, but I need it here
    # network.publish_host:
    transport.tcp.port: 9300
    http.port: 9200
    # discovery.seed_hosts: ["","",""]
    discovery.seed_hosts: ["","",""]
    cluster.initial_master_nodes: ["","",""]
    gateway.recover_after_nodes: 2
    cluster.routing.allocation.disk.threshold_enabled: false
    http.cors.enabled: true
    http.cors.allow-origin: "*"
    xpack.security.enabled: true
    xpack.security.transport.ssl.enabled: true
    xpack.security.transport.ssl.verification_mode: certificate
    xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
    xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

  • configuration

    # 7.1.1 configuration
    # Add the following:
    cluster.name: my-application
    node.name: node-2
    node.master: true
    node.data: true
    path.data: /data/es/9200/data1,/data/es/9200/data2,/data/es/9200/data3
    path.logs: /data/es/9200/logs
    bootstrap.memory_lock: false
    bootstrap.system_call_filter: false
    # Sometimes this configuration is not required, but I need it here
    # network.publish_host:
    transport.tcp.port: 9300
    http.port: 9200
    # discovery.seed_hosts: ["","",""]
    discovery.seed_hosts: ["","",""]
    cluster.initial_master_nodes: ["","",""]
    gateway.recover_after_nodes: 2
    cluster.routing.allocation.disk.threshold_enabled: false
    http.cors.enabled: true
    http.cors.allow-origin: "*"
    xpack.security.enabled: true
    xpack.security.transport.ssl.enabled: true
    xpack.security.transport.ssl.verification_mode: certificate
    xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
    xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

  • configuration

    # 7.1.1 configuration
    # Add the following:
    cluster.name: my-application
    node.name: node-3
    node.master: true
    node.data: true
    path.data: /data/es/9200/data1,/data/es/9200/data2,/data/es/9200/data3
    path.logs: /data/es/9200/logs
    bootstrap.memory_lock: false
    bootstrap.system_call_filter: false
    # Sometimes this configuration is not required, but I need it here
    # network.publish_host:
    transport.tcp.port: 9300
    http.port: 9200
    # discovery.seed_hosts: ["","",""]
    discovery.seed_hosts: ["","",""]
    cluster.initial_master_nodes: ["","",""]
    gateway.recover_after_nodes: 2
    cluster.routing.allocation.disk.threshold_enabled: false
    http.cors.enabled: true
    http.cors.allow-origin: "*"
    xpack.security.enabled: true
    xpack.security.transport.ssl.enabled: true
    xpack.security.transport.ssl.verification_mode: certificate
    xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
    xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

Keywords: Big Data ElasticSearch nosql

Added by Wabin on Mon, 17 Jan 2022 06:25:44 +0200