Pulogalamu ya ProHoster > Blog > Ulamuliro > Elastic pansi pa loko ndi kiyi: kuthandizira zosankha zachitetezo chamagulu a Elasticsearch kuti mufikire mkati ndi kunja
Elastic pansi pa loko ndi kiyi: kuthandizira zosankha zachitetezo chamagulu a Elasticsearch kuti mufikire mkati ndi kunja
Elastic Stack ndi chida chodziwika bwino pamsika wamakina a SIEM (kwenikweni, osati iwo okha). Ikhoza kusonkhanitsa deta yambiri yosiyana-siyana, yomwe imakhala yovuta komanso yosamvetsetseka. Sizolondola kwenikweni ngati kupeza zinthu za Elastic Stack sikutetezedwa. Mwachikhazikitso, zinthu zonse za Elastic-of-the-box (Elasticsearch, Logstash, Kibana, ndi osonkhanitsa a Beats) amayendetsa ma protocol otseguka. Ndipo ku Kibana komweko, kutsimikizika kwayimitsidwa. Zochita zonsezi zitha kutetezedwa ndipo m'nkhaniyi tikuuzani momwe mungachitire izi. Kuti zitheke, tidagawa nkhaniyo m'magawo atatu a semantic:
Njira yofikira deta yotengera ntchito
Chitetezo cha data mkati mwa gulu la Elasticsearch
Kuteteza deta kunja kwa gulu la Elasticsearch
Tsatanetsatane pansi pa odulidwa.
Njira yofikira deta yotengera ntchito
Mukayika Elasticsearch ndipo osayisintha mwanjira ina iliyonse, mwayi wopeza ma index onse udzatsegulidwa kwa aliyense. Chabwino, kapena omwe angagwiritse ntchito kupindika. Kuti mupewe izi, Elasticsearch ili ndi chitsanzo chomwe chilipo kuyambira ndikulembetsa kwa Basic (komwe kuli kwaulere). Mwadongosolo zikuwoneka motere:
Zomwe zili pachithunzichi
Ogwiritsa ndi onse omwe angalowemo pogwiritsa ntchito zidziwitso zawo.
Zothandizira ndi zolemba, zolemba, minda, ogwiritsa ntchito, ndi mabungwe ena osungira (chitsanzo chazinthu zina chimapezeka kokha ndi olembetsa omwe amalipidwa).
Mwachikhazikitso Elasticsearch ili ogwiritsa bokosi, kumene amamangiriridwa maudindo a bokosi. Mukatsegula zoikamo zachitetezo, mutha kuyamba kugwiritsa ntchito nthawi yomweyo.
Kuti mutsegule makonda a Elasticsearch, muyenera kuwonjezera pa fayilo yosinthira (mwachisawawa izi ndi elasticsearch/config/elasticsearch.yml) mzere watsopano:
[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-setup-passwords interactive
Initiating the setup of passwords for reserved users elastic,apm_system,kibana,logstash_system,beats_system,remote_monitoring_user.
You will be prompted to enter passwords as the process progresses.
Please confirm that you would like to continue [y/N]y
Enter password for [elastic]:
Reenter password for [elastic]:
Enter password for [apm_system]:
Reenter password for [apm_system]:
Enter password for [kibana]:
Reenter password for [kibana]:
Enter password for [logstash_system]:
Reenter password for [logstash_system]:
Enter password for [beats_system]:
Reenter password for [beats_system]:
Enter password for [remote_monitoring_user]:
Reenter password for [remote_monitoring_user]:
Changed password for user [apm_system]
Changed password for user [kibana]
Changed password for user [logstash_system]
Changed password for user [beats_system]
Changed password for user [remote_monitoring_user]
Changed password for user [elastic]
Kufufuza:
[elastic@node1 ~]$ curl -u elastic 'node1:9200/_cat/nodes?pretty'
Enter host password for user 'elastic':
192.168.0.2 23 46 14 0.28 0.32 0.18 dim * node1
Mutha kudzisisita kumbuyo - zokonda kumbali ya Elasticsearch zamalizidwa. Tsopano ndi nthawi yokonza Kibana. Ngati mutayendetsa tsopano, zolakwika zidzawonekera, choncho ndikofunikira kupanga sitolo yaikulu. Izi zimachitika mu malamulo awiri (user chibana ndi mawu achinsinsi omwe adalowa pagawo lopanga mawu achinsinsi mu Elasticsearch):
Palinso njira ina yachitetezo - kusefa adilesi ya IP (yopezeka polembetsa kuchokera pamlingo wa Golide). Imakulolani kuti mupange mindandanda yoyera ya ma adilesi a IP omwe mumaloledwa kupeza ma node.
Kuteteza deta kunja kwa gulu la Elasticsearch
Kunja kwa tsango kumatanthauza kulumikiza zida zakunja: Kibana, Logstash, Beats kapena makasitomala ena akunja.
Kukonza chithandizo cha https (m'malo mwa http), onjezani mizere yatsopano ku elasticsearch.yml:
Ngati muli ndi mafunso okhudzana ndi kuthekera kwa Elastic Stack pa zolembetsa zaulere kapena zolipiridwa, kuyang'anira ntchito kapena kupanga dongosolo la SIEM, siyani pempho kwa mawonekedwe a ndemanga patsamba lathu.