部署graylog
设置密码
root@awen:/apps/graylog-4.3.13# echo -n "Enter Password: " && head -1 </dev/stdin | tr -d '\n' | sha256sum | cut -d" " -f1
Enter Password: admin
8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918
root@awen:/apps/graylog-4.3.13# pwgen -N 1 -s 96
YNAb6FdZUSiRqzc80SHE2lvTGzeq9MwSjOrdebYTl4GQ8EJdYUygKr8UfZSIXu6xYuyKftT0wcTP63UZhVr2fTh0u1wPkmvH
root@awen:/apps/graylog-4.3.13# cat /etc/mongod.conf | grep '#|^$' -vE
storage:
dbPath: /var/lib/mongodb
journal:
enabled: true
systemLog:
destination: file
logAppend: true
path: /var/log/mongodb/mongod.log
net:
port: 27017
bindIp: 10.4.7.131
processManagement:
timeZoneInfo: /usr/share/zoneinfo
root@awen:/apps/graylog-4.3.13# cat /etc/elasticsearch/elasticsearch.yml | grep '#|^$' -vE
cluster.name: graylog
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
action.destructive_requires_name: true
action.auto_create_index: false
root@awen:/apps/graylog-4.3.13# cat /etc/graylog/server/server.conf | grep '#|^$' -vE
is_leader = true
node_id_file = /etc/graylog/server/node-id
password_secret = YNAb6FdZUSiRqzc80SHE2lvTGzeq9MwSjOrdebYTl4GQ8EJdYUygKr8UfZSIXu6xYuyKftT0wcTP63UZhVr2fTh0u1wPkmvH
root_username = admin
root_password_sha2 = 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918
root_timezone = Asia/Shanghai
bin_dir = bin
data_dir = data
plugin_dir = plugin
http_bind_address = 10.4.7.131:9000
elasticsearch_hosts = http://127.0.0.1:9200
rotation_strategy = count
elasticsearch_max_docs_per_index = 20000000
elasticsearch_max_number_of_indices = 20
retention_strategy = delete
elasticsearch_shards = 4
elasticsearch_replicas = 0
elasticsearch_index_prefix = graylog
allow_leading_wildcard_searches = false
allow_highlighting = true
elasticsearch_analyzer = standard
output_batch_size = 500
output_flush_interval = 1
output_fault_count_threshold = 5
output_fault_penalty_seconds = 30
processbuffer_processors = 5
outputbuffer_processors = 3
processor_wait_strategy = blocking
ring_size = 65536
inputbuffer_ring_size = 65536
inputbuffer_processors = 2
inputbuffer_wait_strategy = blocking
message_journal_enabled = true
message_journal_dir = data/journal
lb_recognition_period_seconds = 3
mongodb_uri = mongodb://10.4.7.131/graylog
mongodb_max_connections = 1000
mongodb_threads_allowed_to_block_multiplier = 5
proxied_requests_thread_pool_size = 32
root@awen:/apps# dpkg -i elasticsearch-7.13.1-amd64.deb ^C
root@awen:/apps# dpkg -i mongodb-org-server_4.4.19_amd64.deb ^C
root@awen:/apps# tar xf graylog-4.3.13.tgz
root@awen:/apps/graylog-4.3.13/log# cp -ar graylog.conf /etc/graylog/server/server.conf
访问验证
http://10.4.7.131:9000


浙公网安备 33010602011771号