Elastic under lock and keyαŸ– αž”αžΎαž€αž‡αž˜αŸ’αžšαžΎαžŸαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– cluster Elasticsearch αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž…αžΌαž›αž”αŸ’αžšαžΎαž–αžΈαžαžΆαž„αž€αŸ’αž“αž»αž„ αž“αž·αž„αžαžΆαž„αž€αŸ’αžšαŸ…

Elastic under lock and keyαŸ– αž”αžΎαž€αž‡αž˜αŸ’αžšαžΎαžŸαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– cluster Elasticsearch αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž…αžΌαž›αž”αŸ’αžšαžΎαž–αžΈαžαžΆαž„αž€αŸ’αž“αž»αž„ αž“αž·αž„αžαžΆαž„αž€αŸ’αžšαŸ…

Elastic Stack αž‚αžΊαž‡αžΆαž§αž”αž€αžšαžŽαŸαžŠαŸαž›αŸ’αž”αžΈαž˜αž½αž™αž“αŸ…αž€αŸ’αž“αž»αž„αž‘αžΈαž•αŸ’αžŸαžΆαžšαž”αŸ’αžšαž–αŸαž“αŸ’αž’ SIEM (αžαžΆαž˜αž–αž·αžαž‘αŸ… αž˜αž·αž“αžαŸ’αžšαžΉαž˜αžαŸ‚αž”αŸ‰αž»αžŽαŸ’αžŽαŸ„αŸ‡)αŸ” αžœαžΆαž’αžΆαž…αž”αŸ’αžšαž˜αžΌαž›αž‘αž·αž“αŸ’αž“αž“αŸαž™αžŠαŸ‚αž›αž˜αžΆαž“αž‘αŸ†αž αŸ†αžαž»αžŸαŸ—αž‚αŸ’αž“αžΆαž‡αžΆαž…αŸ’αžšαžΎαž“ αž‘αžΆαŸ†αž„αžšαžŸαžΎαž” αž“αž·αž„αž˜αž·αž“αžšαžŸαžΎαž”αžαŸ’αž›αžΆαŸ†αž„αŸ” αžœαžΆαž˜αž·αž“αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαž‘αžΆαŸ†αž„αžŸαŸ’αžšαž»αž„αž‘αŸ αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž€αžΆαžšαž…αžΌαž›αž‘αŸ…αž€αžΆαž“αŸ‹αž’αžΆαžαž» Elastic Stack αžαŸ’αž›αž½αž“αž―αž„αž˜αž·αž“αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αžΆαžšαž–αžΆαžšαŸ” αžαžΆαž˜αž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜ αž’αžΆαžαž» Elastic out-of-the-box αž‘αžΆαŸ†αž„αž’αžŸαŸ‹ (Elasticsearch, Logstash, Kibana, and Beats collectors) αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž›αžΎαž–αž·αž’αžΈαž€αžΆαžšαž”αžΎαž€αž…αŸ†αž αŸ” αž αžΎαž™αž“αŸ…αž€αŸ’αž“αž»αž„ Kibana αžαŸ’αž›αž½αž“αžœαžΆ αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž·αž‘αŸ” αž’αž“αŸ’αžαžšαž€αž˜αŸ’αž˜αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αž“αŸαŸ‡αž’αžΆαž…αž’αžΆαž“αžΆαž”αžΆαž“ αž αžΎαž™αž“αŸ…αž€αŸ’αž“αž»αž„αž’αžαŸ’αžαž”αž‘αž“αŸαŸ‡αž™αžΎαž„αž“αžΉαž„αž”αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αž“αž€αž–αžΈαžšαž”αŸ€αž”αž’αŸ’αžœαžΎαžœαžΆαŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž—αžΆαž–αž„αžΆαž™αžŸαŸ’αžšαž½αž› αž™αžΎαž„αž”αžΆαž“αž”αŸ‚αž„αž…αŸ‚αž€αž€αžΆαžšαž“αž·αž‘αžΆαž“αžšαžΏαž„αž‘αŸ…αž‡αžΆ 3 αž”αŸ’αž›αž»αž€ semantic:

  • αž‚αŸ†αžšαžΌαž…αžΌαž›αž”αŸ’αžšαžΎαž‘αž·αž“αŸ’αž“αž“αŸαž™αž•αŸ’αž’αŸ‚αž€αž›αžΎαžαž½αž“αžΆαž‘αžΈ
  • αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž‘αž·αž“αŸ’αž“αž“αŸαž™αž“αŸ…αž€αŸ’αž“αž»αž„αž…αž„αŸ’αž€αŸ„αž˜ Elasticsearch
  • αž€αžΆαžšαž’αžΆαž“αžΆαž‘αž·αž“αŸ’αž“αž“αŸαž™αž“αŸ…αžαžΆαž„αž€αŸ’αžšαŸ…αž€αŸ’αžšαž»αž˜ Elasticsearch

αž–αŸαžαŸŒαž˜αžΆαž“αž›αž˜αŸ’αž’αž·αžαž“αŸ…αž€αŸ’αžšαŸ„αž˜αž€αžΆαžšαž€αžΆαžαŸ‹αŸ”

αž‚αŸ†αžšαžΌαž…αžΌαž›αž”αŸ’αžšαžΎαž‘αž·αž“αŸ’αž“αž“αŸαž™αž•αŸ’αž’αŸ‚αž€αž›αžΎαžαž½αž“αžΆαž‘αžΈ

αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αž“αž€αžŠαŸ†αž‘αžΎαž„ Elasticsearch αž αžΎαž™αž˜αž·αž“αž€αŸ†αžŽαžαŸ‹αžœαžΆαžαžΆαž˜αž˜αž’αŸ’αž™αŸ„αž”αžΆαž™αžŽαžΆαž˜αž½αž™αž‘αŸ αž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎαž›αž·αž”αž·αž€αŸ’αžšαž˜αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αž“αžΉαž„αž”αžΎαž€αž…αŸ†αž αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž˜αž“αž»αžŸαŸ’αžŸαž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αž“αžΆαŸ” αž‡αžΆαž€αžΆαžšαž”αŸ’αžšαžŸαžΎαžšαžŽαžΆαžŸαŸ‹, αž¬αž’αŸ’αž“αž€αžŠαŸ‚αž›αž’αžΆαž…αž”αŸ’αžšαžΎ curl αŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž‡αŸ€αžŸαžœαžΆαž„αž”αž‰αŸ’αž αžΆαž“αŸαŸ‡ Elasticsearch αž˜αžΆαž“αž‚αŸ†αžšαžΌαž˜αž½αž™αžŠαŸ‚αž›αž’αžΆαž…αžšαž€αž”αžΆαž“αžŠαŸ„αž™αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž‡αžΆαž˜αž½αž™αž“αžΉαž„αž€αžΆαžšαž‡αžΆαžœ Basic (αžŠαŸ‚αž›αž˜αž·αž“αž‚αž·αžαžαŸ’αž›αŸƒ)αŸ” αžαžΆαž˜αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαžœαžΆαž˜αžΎαž›αž‘αŸ…αžŠαžΌαž…αž“αŸαŸ‡αŸ–

Elastic under lock and keyαŸ– αž”αžΎαž€αž‡αž˜αŸ’αžšαžΎαžŸαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– cluster Elasticsearch αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž…αžΌαž›αž”αŸ’αžšαžΎαž–αžΈαžαžΆαž„αž€αŸ’αž“αž»αž„ αž“αž·αž„αžαžΆαž„αž€αŸ’αžšαŸ…

αžαžΎαž˜αžΆαž“αž’αŸ’αžœαžΈαž“αŸ…αž€αŸ’αž“αž»αž„αžšαžΌαž”αž—αžΆαž–

  • αž’αŸ’αž“αž€β€‹αž”αŸ’αžšαžΎβ€‹αž‚αžΊβ€‹αž‡αžΆβ€‹αž’αŸ’αž“αž€β€‹αžšαžΆαž›αŸ‹β€‹αž‚αŸ’αž“αžΆβ€‹αžŠαŸ‚αž›β€‹αž’αžΆαž…β€‹αž…αžΌαž›β€‹αžŠαŸ„αž™β€‹αž”αŸ’αžšαžΎβ€‹αž›αž·αžαž·αžβ€‹αž”αž‰αŸ’αž‡αžΆαž€αŸ‹β€‹αžšαž”αžŸαŸ‹β€‹αž–αž½αž€β€‹αž‚αŸαŸ”
  • αžαž½αž“αžΆαž‘αžΈαž‚αžΊαž‡αžΆαžŸαŸ†αžŽαž»αŸ†αž“αŸƒαžŸαž·αž‘αŸ’αž’αž·αŸ”
  • αžŸαž·αž‘αŸ’αž’αž·αž‚αžΊαž‡αžΆαžŸαŸ†αžŽαž»αŸ†αž“αŸƒαžŸαž·αž‘αŸ’αž’αž·αŸ”
  • αžŸαž·αž‘αŸ’αž’αž·αž‚αžΊαž€αžΆαžšαž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αžŸαžšαžŸαŸαžš αž’αžΆαž“ αž›αž»αž” αž‡αžΆαžŠαžΎαž˜αŸ” (αž”αž‰αŸ’αž‡αžΈαž–αŸαž‰αž›αŸαž‰αž“αŸƒαžŸαž·αž‘αŸ’αž’αž·)
  • αž’αž“αž’αžΆαž“αž‚αžΊαž‡αžΆαž›αž·αž”αž·αž€αŸ’αžšαž˜ αž―αž€αžŸαžΆαžš αžœαžΆαž› αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ αž“αž·αž„αž’αž„αŸ’αž‚αž—αžΆαž–αž•αŸ’αž‘αž»αž€αž•αŸ’αžŸαŸαž„αž‘αŸ€αž (αž‚αŸ†αžšαžΌαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž’αž“αž’αžΆαž“αž˜αž½αž™αž…αŸ†αž“αž½αž“αž’αžΆαž…αž”αŸ’αžšαžΎαž”αžΆαž“αžαŸ‚αž‡αžΆαž˜αž½αž™αž€αžΆαžšαž‡αžΆαžœαžŠαŸ‚αž›αž”αžΆαž“αž”αž„αŸ‹)αŸ”

αžαžΆαž˜αž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜ Elasticsearch αž˜αžΆαž“ αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž”αŸ’αžšαž’αž”αŸ‹αžŠαŸ‚αž›αž–αž½αž€αž‚αŸαžαŸ’αžšαžΌαžœαž”αžΆαž“αž—αŸ’αž‡αžΆαž”αŸ‹ αžαž½αž“αžΆαž‘αžΈαž”αŸ’αžšαž’αž”αŸ‹. αž“αŸ…αž–αŸαž›αžŠαŸ‚αž›αž’αŸ’αž“αž€αž”αžΎαž€αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– αž’αŸ’αž“αž€αž’αžΆαž…αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž”αŸ’αžšαžΎαž–αž½αž€αžœαžΆαž—αŸ’αž›αžΆαž˜αŸ—αŸ”

αžŠαžΎαž˜αŸ’αž”αžΈαž”αžΎαž€αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž€αŸ’αž“αž»αž„αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹ Elasticsearch αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜αžœαžΆαž‘αŸ…αž€αŸ’αž“αž»αž„αž―αž€αžŸαžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ (αžαžΆαž˜αž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜ αž“αŸαŸ‡αž‚αžΊ elasticsearch/config/elasticsearch.yml) αž‡αž½αžšαžαŸ’αž˜αžΈαŸ–

xpack.security.enabled: true

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž―αž€αžŸαžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ αžŸαžΌαž˜αž”αžΎαž€αžŠαŸ†αžŽαžΎαžšαž€αžΆαžš αž¬αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜ Elasticsearch αž‘αžΎαž„αžœαž·αž‰αžŠαžΎαž˜αŸ’αž”αžΈαž±αŸ’αž™αž€αžΆαžšαž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž˜αžΆαž“αž”αŸ’αžšαžŸαž·αž‘αŸ’αž’αž—αžΆαž–αŸ” αž‡αŸ†αž αžΆαž“αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž‚αžΊαž€αžΆαžšαž•αŸ’αžαž›αŸ‹αž›αŸαžαžŸαž˜αŸ’αž„αžΆαžαŸ‹αžŠαž›αŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž”αŸ’αžšαž’αž”αŸ‹αŸ” αžαŸ„αŸ‡αž’αŸ’αžœαžΎαž’αž“αŸ’αžαžšαž€αž˜αŸ’αž˜αžŠαŸ„αž™αž”αŸ’αžšαžΎαž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-setup-passwords interactive
Initiating the setup of passwords for reserved users elastic,apm_system,kibana,logstash_system,beats_system,remote_monitoring_user.
You will be prompted to enter passwords as the process progresses.
Please confirm that you would like to continue [y/N]y


Enter password for [elastic]:
Reenter password for [elastic]:
Enter password for [apm_system]:
Reenter password for [apm_system]:
Enter password for [kibana]:
Reenter password for [kibana]:
Enter password for [logstash_system]:
Reenter password for [logstash_system]:
Enter password for [beats_system]:
Reenter password for [beats_system]:
Enter password for [remote_monitoring_user]:
Reenter password for [remote_monitoring_user]:
Changed password for user [apm_system]
Changed password for user [kibana]
Changed password for user [logstash_system]
Changed password for user [beats_system]
Changed password for user [remote_monitoring_user]
Changed password for user [elastic]

αž€αŸ†αž–αž»αž„αž–αž·αž“αž·αžαŸ’αž™:

[elastic@node1 ~]$ curl -u elastic 'node1:9200/_cat/nodes?pretty'
Enter host password for user 'elastic':
192.168.0.2 23 46 14 0.28 0.32 0.18 dim * node1

αž’αŸ’αž“αž€αž’αžΆαž…αžœαžΆαž™αžαŸ’αž›αž½αž“αž’αŸ’αž“αž€αž“αŸ…αžαžΆαž„αž€αŸ’αžšαŸ„αž™ - αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž“αŸ…αž•αŸ’αž“αŸ‚αž€ Elasticsearch αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž‰αŸ’αž…αž”αŸ‹αŸ” αž₯αž‘αžΌαžœαž“αŸαŸ‡αžœαžΆαžŠαž›αŸ‹αž–αŸαž›αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ Kibana αŸ” αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αž“αž€αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžœαžΆαž₯αž‘αžΌαžœαž“αŸαŸ‡ αž€αŸ†αž αž»αžŸαž“αžΉαž„αž›αŸαž…αž‘αžΎαž„ αžŠαžΌαž…αŸ’αž“αŸαŸ‡αžœαžΆαž˜αžΆαž“αžŸαžΆαžšαŸˆαžŸαŸ†αžαžΆαž“αŸ‹αžŽαžΆαžŸαŸ‹αž€αŸ’αž“αž»αž„αž€αžΆαžšαž”αž„αŸ’αž€αžΎαžαžƒαŸ’αž›αžΆαŸ†αž„αžŸαž˜αŸ’αž„αžΆαžαŸ‹αŸ” αž“αŸαŸ‡αžαŸ’αžšαžΌαžœαž”αžΆαž“αž’αŸ’αžœαžΎαž“αŸ…αž€αŸ’αž“αž»αž„αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαž–αžΈαžš (αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ αž‚αžΈαž”αŸŠαžΈαžŽαžΆ αž“αž·αž„αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αžŠαŸ‚αž›αž”αžΆαž“αž”αž‰αŸ’αž…αžΌαž›αž€αŸ’αž“αž»αž„αž‡αŸ†αž αžΆαž“αž”αž„αŸ’αž€αžΎαžαž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„ Elasticsearch)αŸ–

[elastic@node1 ~]$ ./kibana/bin/kibana-keystore add elasticsearch.username
[elastic@node1 ~]$ ./kibana/bin/kibana-keystore add elasticsearch.password

αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αžœαžΈαŸ—αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœ Kibana αž“αžΉαž„αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αžŸαŸ’αž“αžΎαžŸαž»αŸ†αž€αžΆαžšαž…αžΌαž› αž“αž·αž„αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αŸ” αž€αžΆαžšαž‡αžΆαžœαž‡αžΆαž˜αžΌαž›αžŠαŸ’αž‹αžΆαž“αžšαž½αž˜αž˜αžΆαž“αž‚αŸ†αžšαžΌαžŠαŸ‚αž›αž•αŸ’αž’αŸ‚αž€αž›αžΎαž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžαžΆαž„αž€αŸ’αž“αž»αž„αŸ” αžŠαŸ„αž™αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž‡αžΆαž˜αž½αž™ Gold αž’αŸ’αž“αž€αž’αžΆαž…αž—αŸ’αž‡αžΆαž”αŸ‹αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžαžΆαž„αž€αŸ’αžšαŸ… - LDAP, PKI, Active Directory αž“αž·αž„ Single sign-on systemsαŸ”

Elastic under lock and keyαŸ– αž”αžΎαž€αž‡αž˜αŸ’αžšαžΎαžŸαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– cluster Elasticsearch αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž…αžΌαž›αž”αŸ’αžšαžΎαž–αžΈαžαžΆαž„αž€αŸ’αž“αž»αž„ αž“αž·αž„αžαžΆαž„αž€αŸ’αžšαŸ…

αžŸαž·αž‘αŸ’αž’αž·αž…αžΌαž›αž”αŸ’αžšαžΎαžœαžαŸ’αžαž»αž“αŸ…αžαžΆαž„αž€αŸ’αž“αž»αž„ Elasticsearch αž€αŸαž’αžΆαž…αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αž•αž„αžŠαŸ‚αžšαŸ” αž‘αŸ„αŸ‡αž™αŸ‰αžΆαž„αžŽαžΆαž€αŸαžŠαŸ„αž™ αžŠαžΎαž˜αŸ’αž”αžΈαž’αŸ’αžœαžΎαžŠαžΌαž…αž‚αŸ’αž“αžΆαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž―αž€αžŸαžΆαžš αž¬αžœαžΆαž› αž’αŸ’αž“αž€αž“αžΉαž„αžαŸ’αžšαžΌαžœαž€αžΆαžšαž€αžΆαžšαž‡αžΆαžœαž”αž„αŸ‹αž”αŸ’αžšαžΆαž€αŸ‹ (αž”αŸ’αžšαžŽαžΈαžαž—αžΆαž–αž“αŸαŸ‡αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž‡αžΆαž˜αž½αž™αž“αžΉαž„αž€αž˜αŸ’αžšαž·αžαž•αŸ’αž›αžΆαž‘αžΈαž“)αŸ” αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž‘αžΆαŸ†αž„αž“αŸαŸ‡αž˜αžΆαž“αž“αŸ…αž€αŸ’αž“αž»αž„αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ Kibana αž¬αžαžΆαž˜αžšαž™αŸˆ API αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–. αž’αŸ’αž“αž€αž’αžΆαž…αž–αž·αž“αž·αžαŸ’αž™αž˜αžΎαž›αžαžΆαž˜αžšαž™αŸˆαž˜αŸ‰αžΊαž“αž»αž™αž§αž”αž€αžšαžŽαŸ Dev αžŠαŸ‚αž›αž’αŸ’αž›αžΆαž”αŸ‹αžŸαŸ’αž‚αžΆαž›αŸ‹αžšαž½αž…αž αžΎαž™αŸ–

αž€αžΆαžšαž”αž„αŸ’αž€αžΎαžαžαž½αž“αžΆαž‘αžΈ

PUT /_security/role/ruslan_i_ludmila_role
{
  "cluster": [],
  "indices": [
    {
      "names": [ "ruslan_i_ludmila" ],
      "privileges": ["read", "view_index_metadata"]
    }
  ]
}

αž€αžΆαžšαž”αž„αŸ’αž€αžΎαžαž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹

POST /_security/user/pushkin
{
  "password" : "nataliaonelove",
  "roles" : [ "ruslan_i_ludmila_role", "kibana_user" ],
  "full_name" : "Alexander Pushkin",
  "email" : "[email protected]",
  "metadata" : {
    "hometown" : "Saint-Petersburg"
  }
}

αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž‘αž·αž“αŸ’αž“αž“αŸαž™αž“αŸ…αž€αŸ’αž“αž»αž„αž…αž„αŸ’αž€αŸ„αž˜ Elasticsearch

αž“αŸ…αž–αŸαž›αžŠαŸ‚αž› Elasticsearch αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž€αŸ’αž“αž»αž„αž…αž„αŸ’αž€αŸ„αž˜ (αžŠαŸ‚αž›αž‡αžΆαžšαžΏαž„αž’αž˜αŸ’αž˜αžαžΆ) αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž“αŸ…αž€αŸ’αž“αž»αž„αž…αž„αŸ’αž€αŸ„αž˜αž€αŸ’αž›αžΆαž™αž‡αžΆαžŸαŸ†αžαžΆαž“αŸ‹αŸ” αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž‘αŸ†αž“αžΆαž€αŸ‹αž‘αŸ†αž“αž„αž”αŸ’αžšαž€αž”αžŠαŸ„αž™αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžšαžœαžΆαž„αžαŸ’αž“αžΆαŸ†αž„ Elasticsearch αž”αŸ’αžšαžΎαž–αž·αž’αžΈαž€αžΆαžš TLS αŸ” αžŠαžΎαž˜αŸ’αž”αžΈαžšαŸ€αž”αž…αŸ†αž’αž“αŸ’αžαžšαž€αž˜αŸ’αž˜αž”αŸ’αžšαž€αž”αžŠαŸ„αž™αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžšαžœαžΆαž„αž–αž½αž€αž‚αŸ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž€αžΆαžšαžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαŸ” αž™αžΎαž„αž”αž„αŸ’αž€αžΎαžαžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžš αž“αž·αž„αžŸαŸ„αž―αž€αž‡αž“αž€αŸ’αž“αž»αž„αž‘αž˜αŸ’αžšαž„αŸ‹ PEMαŸ–

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-certutil ca --pem

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαžαžΆαž„αž›αžΎαž“αŸ…αž€αŸ’αž“αž»αž„αžαž /../elasticsearch αž”αŸαžŽαŸ’αžŽαžŸαžΆαžšαž“αžΉαž„αž›αŸαž…αž‘αžΎαž„ elastic-stack-ca.zip. αž“αŸ…αžαžΆαž„αž€αŸ’αž“αž»αž„αž’αŸ’αž“αž€αž“αžΉαž„αžƒαžΎαž‰αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžš αž“αž·αž„αžŸαŸ„αž―αž€αž‡αž“αž˜αž½αž™αžŠαŸ‚αž›αž˜αžΆαž“αž•αŸ’αž“αŸ‚αž€αž”αž“αŸ’αžαŸ‚αž˜ crt ΠΈ αž‚αž“αŸ’αž›αžΉαŸ‡ αžšαŸ€αž„αŸ—αžαŸ’αž›αž½αž“αŸ” αžœαžΆαžαŸ’αžšαžΌαžœαž”αžΆαž“αžŽαŸ‚αž“αžΆαŸ†αž±αŸ’αž™αžŠαžΆαž€αŸ‹αž–αž½αž€αžœαžΆαž“αŸ…αž›αžΎαž’αž“αž’αžΆαž“αž…αŸ‚αž€αžšαŸ†αž›αŸ‚αž€ αžŠαŸ‚αž›αž‚αž½αžšαž’αžΆαž…αž…αžΌαž›αž”αŸ’αžšαžΎαž”αžΆαž“αž–αžΈαžαŸ’αž“αžΆαŸ†αž„αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„αž…αž„αŸ’αž€αŸ„αž˜αŸ”

αž₯αž‘αžΌαžœαž“αŸαŸ‡αžαŸ’αž“αžΆαŸ†αž„αž“αžΈαž˜αž½αž™αŸ—αžαŸ’αžšαžΌαžœαž€αžΆαžšαžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαž•αŸ’αž‘αžΆαž›αŸ‹αžαŸ’αž›αž½αž“ αž“αž·αž„αžŸαŸ„αž―αž€αž‡αž“ αžŠαŸ„αž™αž•αŸ’αž’αŸ‚αž€αž›αžΎαž’αŸ’αžœαžΈαžŠαŸ‚αž›αž“αŸ…αž€αŸ’αž“αž»αž„αžαžαžŠαŸ‚αž›αž”αžΆαž“αž…αŸ‚αž€αžšαŸ†αž›αŸ‚αž€αŸ” αž“αŸ…αž–αŸαž›αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆ αž’αŸ’αž“αž€αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŸαž½αžšαž±αŸ’αž™αž€αŸ†αžŽαžαŸ‹αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αŸ” αž’αŸ’αž“αž€αž’αžΆαž…αž”αž“αŸ’αžαŸ‚αž˜αž‡αž˜αŸ’αžšαžΎαžŸαž”αž“αŸ’αžαŸ‚αž˜ -ip αž“αž·αž„ -dns αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž–αŸαž‰αž›αŸαž‰αž“αŸƒαžαŸ’αž“αžΆαŸ†αž„αž’αž“αŸ’αžαžšαž€αž˜αŸ’αž˜αŸ”

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-certutil cert --ca-cert /shared_folder/ca/ca.crt --ca-key /shared_folder/ca/ca.key

αž‡αžΆαž›αž‘αŸ’αž’αž•αž›αž“αŸƒαž€αžΆαžšαž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆ αž™αžΎαž„αž“αžΉαž„αž‘αž‘αž½αž›αž”αžΆαž“αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžš αž“αž·αž„αžŸαŸ„αž―αž€αž‡αž“αž€αŸ’αž“αž»αž„αž‘αž˜αŸ’αžšαž„αŸ‹ PKCS#12 αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αžΆαžšαž–αžΆαžšαžŠαŸ„αž™αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αŸ” αž’αŸ’αžœαžΈαžŠαŸ‚αž›αž“αŸ…αžŸαž›αŸ‹αž‚αžΊαžαŸ’αžšαžΌαžœαž•αŸ’αž›αžΆαžŸαŸ‹αž‘αžΈαž―αž€αžŸαžΆαžšαžŠαŸ‚αž›αž”αžΆαž“αž”αž„αŸ’αž€αžΎαž p12 αž‘αŸ…αž€αžΆαž“αŸ‹αžαžαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αŸ–

[elastic@node1 ~]$ mv elasticsearch/elastic-certificates.p12 elasticsearch/config

αž”αž“αŸ’αžαŸ‚αž˜αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αž‘αŸ…αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαž€αŸ’αž“αž»αž„αž‘αž˜αŸ’αžšαž„αŸ‹ p12 αž“αŸ…αž€αŸ’αž“αž»αž„ keystore αž“αž·αž„ truststore αž“αŸ…αž›αžΎ node αž“αžΈαž˜αž½αž™αŸ—αŸ–

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password
[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password

αžŸαŸ’αž‚αžΆαž›αŸ‹αžšαž½αž…αž αžΎαž™ elasticsearch.yml αž’αŸ’αžœαžΈαžŠαŸ‚αž›αž“αŸ…αžŸαŸαžŸαžŸαž›αŸ‹αž‚αžΊαžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜αž”αž“αŸ’αž‘αžΆαžαŸ‹αž‡αžΆαž˜αž½αž™αž‘αž·αž“αŸ’αž“αž“αŸαž™αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαŸ–

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

αž™αžΎαž„αž”αžΎαž€αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžαŸ’αž“αžΆαŸ†αž„ Elasticsearch αž‘αžΆαŸ†αž„αž’αžŸαŸ‹ αž αžΎαž™αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž· curl. αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αžœαžΈαŸ—αž‚αŸ’αžšαž”αŸ‹αž™αŸ‰αžΆαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž’αŸ’αžœαžΎαž”αžΆαž“αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœ αž€αžΆαžšαž†αŸ’αž›αžΎαž™αžαž”αž‡αžΆαž˜αž½αž™αžαŸ’αž“αžΆαŸ†αž„αž‡αžΆαž…αŸ’αžšαžΎαž“αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αžαŸ’αžšαž‘αž”αŸ‹αž˜αž€αžœαž·αž‰αŸ–

[elastic@node1 ~]$ curl node1:9200/_cat/nodes -u elastic:password                                                                                    
172.18.0.3 43 75 4 0.00 0.05 0.05 dim * node2                                                                                                                     
172.18.0.4 21 75 3 0.00 0.05 0.05 dim - node3                                                                                                                     
172.18.0.2 39 75 4 0.00 0.05 0.05 dim - node1

αž˜αžΆαž“αž‡αž˜αŸ’αžšαžΎαžŸαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž˜αž½αž™αž•αŸ’αžŸαŸαž„αž‘αŸ€αž - αžαž˜αŸ’αžšαž„αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP (αž˜αžΆαž“αž“αŸ…αž€αŸ’αž“αž»αž„αž€αžΆαžšαž‡αžΆαžœαž–αžΈαž€αž˜αŸ’αžšαž·αžαž˜αžΆαžŸ)αŸ” αž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αž’αŸ’αž“αž€αž”αž„αŸ’αž€αžΎαžαž”αž‰αŸ’αž‡αžΈαžŸαž“αŸƒαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αžŠαŸ‚αž›αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αžΆαž“αž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αž…αžΌαž›αž”αŸ’αžšαžΎαžαŸ’αž“αžΆαŸ†αž„αŸ”

αž€αžΆαžšαž’αžΆαž“αžΆαž‘αž·αž“αŸ’αž“αž“αŸαž™αž“αŸ…αžαžΆαž„αž€αŸ’αžšαŸ…αž€αŸ’αžšαž»αž˜ Elasticsearch

αž“αŸ…αžαžΆαž„αž€αŸ’αžšαŸ…αž…αž„αŸ’αž€αŸ„αž˜αž˜αžΆαž“αž“αŸαž™αžαžΆαž—αŸ’αž‡αžΆαž”αŸ‹αž§αž”αž€αžšαžŽαŸαžαžΆαž„αž€αŸ’αžšαŸ…: Kibana, Logstash, Beats αž¬αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž—αŸ’αž‰αŸ€αžœαžαžΆαž„αž€αŸ’αžšαŸ…αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαŸ”

Elastic under lock and keyαŸ– αž”αžΎαž€αž‡αž˜αŸ’αžšαžΎαžŸαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– cluster Elasticsearch αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž…αžΌαž›αž”αŸ’αžšαžΎαž–αžΈαžαžΆαž„αž€αŸ’αž“αž»αž„ αž“αž·αž„αžαžΆαž„αž€αŸ’αžšαŸ…

αžŠαžΎαž˜αŸ’αž”αžΈαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž€αžΆαžšαž‚αžΆαŸ†αž‘αŸ’αžšαžŸαž˜αŸ’αžšαžΆαž”αŸ‹ https (αž‡αŸ†αž“αž½αžŸαž±αŸ’αž™ http) αž”αž“αŸ’αžαŸ‚αž˜αž”αž“αŸ’αž‘αžΆαžαŸ‹αžαŸ’αž˜αžΈαž‘αŸ… elasticsearch.ymlαŸ–

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: elastic-certificates.p12
xpack.security.http.ssl.truststore.path: elastic-certificates.p12

αžŠαŸ„αž™αžŸαžΆαžšαžαŸ‚ αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αžΆαžšαž–αžΆαžšαžŠαŸ„αž™αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹ αž”αž“αŸ’αžαŸ‚αž˜αžœαžΆαž‘αŸ… keystore αž“αž·αž„ truststore αž“αŸ…αž›αžΎ node αž“αžΈαž˜αž½αž™αŸ—αŸ–

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password
[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.http.ssl.truststore.secure_password

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž”αž“αŸ’αžαŸ‚αž˜αž€αžΌαž“αžŸαŸ„ αžαŸ’αž“αžΆαŸ†αž„ Elasticsearch αžšαž½αž…αžšαžΆαž›αŸ‹αžŠαžΎαž˜αŸ’αž”αžΈαž—αŸ’αž‡αžΆαž”αŸ‹αžαžΆαž˜αžšαž™αŸˆ https αŸ” αž₯αž‘αžΌαžœαž“αŸαŸ‡αž–αž½αž€αž‚αŸαž’αžΆαž…αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŠαžΆαž€αŸ‹αž±αŸ’αž™αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαŸ”

αž‡αŸ†αž αžΆαž“αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž‚αžΊαž”αž„αŸ’αž€αžΎαžαž€αžΌαž“αžŸαŸ„αžŠαžΎαž˜αŸ’αž”αžΈαž—αŸ’αž‡αžΆαž”αŸ‹ Kibana αž αžΎαž™αž”αž“αŸ’αžαŸ‚αž˜αžœαžΆαž‘αŸ…αž€αŸ’αž“αž»αž„αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αŸ” αžŠαŸ„αž™αž•αŸ’αž’αŸ‚αž€αž›αžΎαžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαžŠαŸ‚αž›αž˜αžΆαž“αž‘αžΈαžαžΆαŸ†αž„αž“αŸ…αž€αŸ’αž“αž»αž„αžαžαžŠαŸ‚αž›αž”αžΆαž“αž…αŸ‚αž€αžšαŸ†αž›αŸ‚αž€αžšαž½αž…αž αžΎαž™ αž™αžΎαž„αž“αžΉαž„αž”αž„αŸ’αž€αžΎαžαžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαž€αŸ’αž“αž»αž„αž‘αž˜αŸ’αžšαž„αŸ‹ PEM (PKCS#12 Kibana, Logstash αž“αž·αž„ Beats αž˜αž·αž“αž‘αžΆαž“αŸ‹αž‚αžΆαŸ†αž‘αŸ’αžš)αŸ–

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-certutil cert --ca-cert /shared_folder/ca/ca.crt --ca-key /shared_folder/ca/ca.key --pem

αž’αŸ’αžœαžΈαžŠαŸ‚αž›αž“αŸ…αžŸαŸαžŸαžŸαž›αŸ‹αž‚αžΊαžαŸ’αžšαžΌαžœαžŸαŸ’αžšαžΆαž™αžŸαŸ„αžŠαŸ‚αž›αž”αžΆαž“αž”αž„αŸ’αž€αžΎαžαž‘αŸ…αž€αŸ’αž“αž»αž„αžαžαž―αž€αžŸαžΆαžšαž‡αžΆαž˜αž½αž™αž“αžΉαž„αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ KibanaαŸ–

[elastic@node1 ~]$ unzip elasticsearch/certificate-bundle.zip -d kibana/config

αž‚αŸ’αžšαžΆαž”αŸ‹αž…αž»αž…αž‚αžΊαž“αŸ…αž‘αžΈαž“αŸ„αŸ‡ αžŠαžΌαž…αŸ’αž“αŸαŸ‡αž’αŸ’αžœαžΈαŸ—αžŠαŸ‚αž›αž“αŸ…αžŸαž›αŸ‹αž‚αžΊαžαŸ’αžšαžΌαžœαž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ Kibana αžŠαžΌαž…αŸ’αž“αŸαŸ‡αžœαžΆαž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž–αž½αž€αžœαžΆαŸ” αž“αŸ…αž€αŸ’αž“αž»αž„αž―αž€αžŸαžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ kibana.yml αž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžš http αž‘αŸ… https αž αžΎαž™αž”αž“αŸ’αžαŸ‚αž˜αž”αž“αŸ’αž‘αžΆαžαŸ‹αž‡αžΆαž˜αž½αž™αž“αžΉαž„αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž€αžΆαžšαžαž—αŸ’αž‡αžΆαž”αŸ‹ SSL αŸ” αž”αž“αŸ’αž‘αžΆαžαŸ‹αž”αžΈαž…αž»αž„αž€αŸ’αžšαŸ„αž™αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž‘αŸ†αž“αžΆαž€αŸ‹αž‘αŸ†αž“αž„αž”αŸ’αžšαž€αž”αžŠαŸ„αž™αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžšαžœαžΆαž„αž€αž˜αŸ’αž˜αžœαž·αž’αžΈαžšαž»αž€αžšαž€αžαžΆαž˜αž’αŸŠαžΈαž“αž’αžΊαžŽαž·αžαžšαž”αžŸαŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎ αž“αž·αž„ Kibana αŸ”

elasticsearch.hosts: ["https://${HOSTNAME}:9200"]
elasticsearch.ssl.certificateAuthorities: /shared_folder/ca/ca.crt
elasticsearch.ssl.verificationMode: certificate
server.ssl.enabled: true
server.ssl.key: /../kibana/config/instance/instance.key
server.ssl.certificate: /../kibana/config/instance/instance.crt

αžŠαžΌαž…αŸ’αž“αŸαŸ‡ αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž‰αŸ’αž…αž”αŸ‹ αž αžΎαž™αž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎαž‘αž·αž“αŸ’αž“αž“αŸαž™αž“αŸ…αž€αŸ’αž“αž»αž„αž…αž„αŸ’αž€αŸ„αž˜ Elasticsearch αžαŸ’αžšαžΌαžœαž”αžΆαž“αž’αŸŠαž·αž“αž‚αŸ’αžšαžΈαž”αŸ”

αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αž“αž€αž˜αžΆαž“αžŸαŸ†αžŽαž½αžšαž’αŸ†αž–αžΈαžŸαž˜αžαŸ’αžαž—αžΆαž–αžšαž”αžŸαŸ‹ Elastic Stack αž›αžΎαž€αžΆαžšαž‡αžΆαžœαž₯αžαž‚αž·αžαžαŸ’αž›αŸƒ αž¬αž”αž„αŸ‹αž”αŸ’αžšαžΆαž€αŸ‹ αž€αžΆαžšαžαŸ’αžšαž½αžαž–αž·αž“αž·αžαŸ’αž™αž—αžΆαžšαž€αž·αž…αŸ’αž… αž¬αž€αžΆαžšαž”αž„αŸ’αž€αžΎαžαž”αŸ’αžšαž–αŸαž“αŸ’αž’ SIEM αžŸαžΌαž˜αž‘αž»αž€αžŸαŸ†αžŽαžΎαž˜αž½αž™αž‘αŸ…αž€αžΆαž“αŸ‹ αž‘αž˜αŸ’αžšαž„αŸ‹αž˜αžαž·αžαŸ’αžšαž‘αž”αŸ‹ αž“αŸ…αž›αžΎαž‚αŸαž αž‘αŸ†αž–αŸαžšαžšαž”αžŸαŸ‹αž™αžΎαž„αŸ”

αž’αžαŸ’αžαž”αž‘αž…αŸ’αžšαžΎαž“αž‘αŸ€αžαžšαž”αžŸαŸ‹αž™αžΎαž„αž’αŸ†αž–αžΈ Elastic Stack on Habre:

αž€αžΆαžšαž™αž›αŸ‹αžŠαžΉαž„αž’αŸ†αž–αžΈ Machine Learning αž“αŸ…αž€αŸ’αž“αž»αž„ Elastic Stack (aka Elasticsearch, aka ELK)

αž€αžΆαžšαžŸαŸ’αžœαŸ‚αž„αžšαž€αž‘αŸ†αž αŸ† Elasticsearch

αž”αŸ’αžšαž—αž–: www.habr.com

αž”αž“αŸ’αžαŸ‚αž˜αž˜αžαž·αž™αŸ„αž”αž›αŸ‹