下载ES

下载地址:
Elasticsearch(ES)下载地址
下载所使用的8.10.0版本.

解压

启动 Elasticsearch

可以直接进入到 bin 目录,然后执行 ./elasticsearch 启动 ES。

配置

默认情况下,ES 默认是自动配置堆大小的,也就是没有设置固定的内存限制,所以 ES 会根据系统可用内存自动分配,我本机有时候能飙到 30 多个 G 的内存。如果你本机没有这么大的内存空间,你可以通过下面的命令运行:

ES_JAVA_OPTS=”-Xms5g -Xmx5g” ./bin/elasticsearch

-Xms 设置初始堆大小,-Xmx 设置最大堆大小,建议将 -Xms 和 -Xmx 设置为相同值,避免堆动态调整的开销。

ES 8.10.0 需要 JDK 17 的版本,大家在跑 ES 的时候尽量先配置 JDK17。

可以通过这个连接对比:https://www.elastic.co/cn/support/matrix#matrix_jvm

也可以直接在上一级目录执行下面的命令启动。

./bin/elasticsearch

默认情况下,Elasticsearch 会在前台运行,并监听 9200端口。但由于 ES 从 8.x 版本开始,启用了安全功能,所以会有这样一段输出,注意保存一下。

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ Elasticsearch security features have been automatically configured!
✅ Authentication is enabled and cluster connections are encrypted.

ℹ️ Password for the elastic user (reset with `bin/elasticsearch-reset-password -u elastic`):
9cpZafis4bqhWoMU9392

ℹ️ HTTP CA certificate SHA-256 fingerprint:
44fd2a183a249d79fccb292c9fec4c40de76b9a4ca04b276d16d6ba874557f6b

ℹ️ Configure Kibana to use this cluster:
• Run Kibana and click the configuration link in the terminal when Kibana starts.
• Copy the following enrollment token and paste it into Kibana in your browser (valid for the next 30 minutes):
eyJ2ZXIiOiI4LjEwLjAiLCJhZHIiOlsiMTkyLjE2OC4zLjI1OjkyMDAiXSwiZmdyIjoiNDRmZDJhMTgzYTI0OWQ3OWZjY2IyOTJjOWZlYzRjNDBkZTc2YjlhNGNhMDRiMjc2ZDE2ZDZiYTg3NDU1N2Y2YiIsImtleSI6IjBVMXpMcGtCU05uZVpsdUp1N0IxOkI4ZHJ5TWwzU3hHbnViUHlfYjFKcFEifQ==

ℹ️ Configure other nodes to join this cluster:
• On this node:
⁃ Create an enrollment token with `bin/elasticsearch-create-enrollment-token -s node`.
⁃ Uncomment the transport.host setting at the end of config/elasticsearch.yml.
⁃ Restart Elasticsearch.
• On other nodes:
⁃ Start Elasticsearch with `bin/elasticsearch --enrollment-token <token>`, using the enrollment token that you generated.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━


如果 ES 没有按照要求加载对应的 JDK 版本,我们可以这样执行:
ES_JAVA_HOME=$JAVA_HOME ./bin/elasticsearch -d

Linux 服务器后台运行

如果你希望 Elasticsearch 在后台运行,可以使用 nohup:

nohup ./bin/elasticsearch > elasticsearch.log 2>&1

2. ES安全功能解除方法

ES 的安全功能包括:

HTTPS :所有通信默认使用 HTTPS。
身份验证 :需要用户名和密码才能访问 Elasticsearch。
证书生成 :安装时会自动生成 TLS/SSL 证书。

Elasticsearch 启动时默认启用了 HTTPS(加密通信),如果尝试通过 HTTP(明文通信)访问 Elasticsearch,会导致了以下错误:

1
received plaintext http traffic on an https channel, closing connection  

这表明你的客户端(如 curl 或浏览器)发送的是 HTTP 请求,而 Elasticsearch 配置为仅接受 HTTPS 请求

方法 1:使用 HTTPS 访问 Elasticsearch

默认情况下,Elasticsearch 会在安装目录下生成一个自签名证书,并启用 HTTPS。你可以通过以下步骤使用 HTTPS 访问 Elasticsearch。

步骤 1:找到生成的证书

在安装 Elasticsearch 时,系统会提示你保存以下信息:

①、CA 证书路径:通常位于 elasticsearch-8.10.0/config/certs/http_ca.crt。

②、 用户名和密码:默认用户是 elastic,密码会在启动时生成。

如果忘记了密码,可以通过以下命令重置:

./bin/elasticsearch-reset-password -u elastic

步骤 2:使用 HTTPS 访问

回到解压目录(注意不是 bin 目录),运行以下命令,指定 CA 证书并使用 HTTPS 协议:

curl –cacert config/certs/http_ca.crt -X GET “https://localhost:9200“ -u elastic

系统会提示输入密码,输入 elastic 用户的密码后即可访问。

注意⚠️,要记得把 ES 的密码配置到你本地代码的 application.yml 文件,和前面 ES 生成的密码是匹配的。

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Enter host password for user 'elastic':
{
"name" : "Jakics-MacBook-Pro.local",
"cluster_name" : "elasticsearch",
"cluster_uuid" : "Ycs1J_a3SsGcMLNOz6-nbw",
"version" : {
"number" : "8.10.0",
"build_flavor" : "default",
"build_type" : "tar",
"build_hash" : "e338da74c79465dfdc204971e600342b0aa87b6b",
"build_date" : "2023-09-07T08:16:21.960703010Z",
"build_snapshot" : false,
"lucene_version" : "9.7.0",
"minimum_wire_compatibility_version" : "7.17.0",
"minimum_index_compatibility_version" : "7.0.0"
},
"tagline" : "You Know, for Search"
}

IK分词器下载地址:
https://release.infinilabs.com/analysis-ik/stable/

启动指令
ES_JAVA_HOME=$JAVA_HOME ./bin/elasticsearch -d

用法

如何获取es的token

我来帮您获取Elasticsearch的token。在Elasticsearch 8.x中,有几种方式可以获取token:

首先让我检查Elasticsearch是否正在运行:

Command Executed:

1
ps aux | grep elasticsearch

Output:

1
mac              53510   0.0  0.0 410724320   1408 s003  S+   11:26AM   0:00.00 grep elasticsearch

Elasticsearch没有运行。让我先启动它,然后获取token:

Command Executed:

1
ES_JAVA_HOME=$JAVA_HOME ./bin/elasticsearch -d

Output:

很好!Elasticsearch已经启动成功。现在我来获取token。等待几秒钟让Elasticsearch完全启动:

Command Executed:

1
sleep 10

Output:

1

Command Executed:

1
./bin/elasticsearch-reset-password -u elastic -b

Output:

1
2
3
warning: ignoring JAVA_HOME=/Library/Java/JavaVirtualMachines/jdk-17.jdk/Contents/Home; using bundled JDK
Password for the [elastic] user successfully reset.
New value: kjoXlrSJfOv_I0c=5zkJ

现在我获取用于Kibana的enrollment token:

Command Executed:

1
./bin/elasticsearch-create-enrollment-token -s kibana

Output:

1
2
warning: ignoring JAVA_HOME=/Library/Java/JavaVirtualMachines/jdk-17.jdk/Contents/Home; using bundled JDK
eyJ2ZXIiOiI4LjEwLjAiLCJhZHIiOlsiMTkyLjE2OC4zLjI1OjkyMDAiXSwiZmdyIjoiNDRmZDJhMTgzYTI0OWQ3OWZjY2IyOTJjOWZlYzRjNDBkZTc2YjlhNGNhMDRiMjc2ZDE2ZDZiYTg3NDU1N2Y2YiIsImtleSI6IjhleVJVSmtCRDlQVnJsMWR2YnA1Ol9NRnpPcGJZVG9lU1pJcUgwT3VDYWcifQ==

现在我也获取用于新节点的enrollment token:

Command Executed:

1
./bin/elasticsearch-create-enrollment-token -s node

Output:

1
2
warning: ignoring JAVA_HOME=/Library/Java/JavaVirtualMachines/jdk-17.jdk/Contents/Home; using bundled JDK
eyJ2ZXIiOiI4LjEwLjAiLCJhZHIiOlsiMTkyLjE2OC4zLjI1OjkyMDAiXSwiZmdyIjoiNDRmZDJhMTgzYTI0OWQ3OWZjY2IyOTJjOWZlYzRjNDBkZTc2YjlhNGNhMDRiMjc2ZDE2ZDZiYTg3NDU1N2Y2YiIsImtleSI6IjgteVJVSmtCRDlQVnJsMWQtcm9LOjIxR1hLdFp4U1hpTGFCZWMtWFVma0EifQ==

让我也检查一下CA证书的指纹:

Command Executed:

1
./bin/elasticsearch-certutil cert-ca -cacert config/certs/http_ca.crt

Output:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
warning: ignoring JAVA_HOME=/Library/Java/JavaVirtualMachines/jdk-17.jdk/Contents/Home; using bundled JDK
Simplifies certificate creation for use with the Elastic Stack

Non-option arguments:
command

Option Description
------ -----------
-E <KeyValuePair> Configure a setting
-h, --help Show help
-s, --silent Show minimal output
-v, --verbose Show verbose output

ERROR: Unknown command [cert-ca], with exit code 64

让我用正确的命令检查CA证书指纹:

Command Executed:

1
openssl x509 -fingerprint -sha256 -in config/certs/http_ca.crt -noout

Output:

1
sha256 Fingerprint=44:FD:2A:18:3A:24:9D:79:FC:CB:29:2C:9F:EC:4C:40:DE:76:B9:A4:CA:04:B2:76:D1:6D:6B:A8:74:55:7F:6B

获取Elasticsearch Token的方法总结

我已经为您获取了所有必要的Token和凭据信息:

1. 超级用户elastic的密码

1
2
用户名: elastic
密码: kjoXlrSJfOv_I0c=5zkJ

2. Kibana Enrollment Token

1
eyJ2ZXIiOiI4LjEwLjAiLCJhZHIiOlsiMTkyLjE2OC4zLjI1OjkyMDAiXSwiZmdyIjoiNDRmZDJhMTgzYTI0OWQ3OWZjY2IyOTJjOWZlYzRjNDBkZTc2YjlhNGNhMDRiMjc2ZDE2ZDZiYTg3NDU1N2Y2YiIsImtleSI6IjhleVJVSmtCRDlQVnJsMWR2YnA1Ol9NRnpPcGJZVG9lU1pJcUgwT3VDYWcifQ==

3. Node Enrollment Token(用于新节点加入集群)

1
eyJ2ZXIiOiI4LjEwLjAiLCJhZHIiOlsiMTkyLjE2OC4zLjI1OjkyMDAiXSwiZmdyIjoiNDRmZDJhMTgzYTI0OWQ3OWZjY2IyOTJjOWZlYzRjNDBkZTc2YjlhNGNhMDRiMjc2ZDE2ZDZiYTg3NDU1N2Y2YiIsImtleSI6IjgteVJVSmtCRDlQVnJsMWQtcm9LOjIxR1hLdFp4U1hpTGFCZWMtWFVma0EifQ==

4. HTTPS CA证书指纹

1
44:FD:2A:18:3A:24:9D:79:FC:CB:29:2C:9F:EC:4C:40:DE:76:B9:A4:CA:04:B2:76:D1:6D:6B:A8:74:55:7F:6B

5. Elasticsearch服务地址

1
2
HTTPS: https://192.168.3.25:9200
HTTP: http://127.0.0.1:9200(如果禁用了SSL)

常用的Token获取命令

以后您可以使用这些命令自己获取Token:

1
2
3
4
5
6
7
8
9
10
11
# 重置elastic用户密码
./bin/elasticsearch-reset-password -u elastic -b

# 创建Kibana enrollment token
./bin/elasticsearch-create-enrollment-token -s kibana

# 创建新节点 enrollment token
./bin/elasticsearch-create-enrollment-token -s node

# 查看CA证书指纹
openssl x509 -fingerprint -sha256 -in config/certs/http_ca.crt -noout

现在您可以使用这些信息来配置Kibana或连接到Elasticsearch集群了!

Canal连接ES SSL问题解决方案

问题描述

在使用Canal客户端连接Elasticsearch 8.x时,可能遇到以下错误:

1
javax.net.ssl.SSLException: Unrecognized SSL message, plaintext connection?

问题原因

  • Elasticsearch 8.x默认启用了SSL/TLS加密
  • Canal客户端配置不正确,SSL协议不匹配
  • 客户端期望SSL连接但服务器返回明文响应

解决方案

方案1:正确配置SSL连接(推荐生产环境)

  1. 配置Canal使用HTTPS协议

    1
    es.url = https://192.168.3.25:9200
  2. 配置SSL证书路径

    1
    es.ssl.certificate.path = /path/to/elasticsearch/config/certs/http_ca.crt
  3. 配置认证信息

    1
    2
    es.username = elastic
    es.password = kjoXlrSJfOv_I0c=5zkJ

方案2:禁用SSL(仅开发环境)

如果不需要SSL加密,可以禁用ES的SSL功能:

  1. 编辑elasticsearch.yml配置文件

    1
    2
    3
    4
    xpack.security.enabled: false
    xpack.security.enrollment.enabled: false
    xpack.security.http.ssl.enabled: false
    xpack.security.transport.ssl.enabled: false
  2. 重启Elasticsearch

    1
    ./bin/elasticsearch -d
  3. 配置Canal使用HTTP协议

    1
    es.url = http://192.168.3.25:9200

方案3:混合配置(开发环境)

保持ES的SSL功能,但配置Canal使用HTTP:

  1. 修改elasticsearch.yml,仅禁用HTTP SSL

    1
    xpack.security.http.ssl.enabled: false
  2. 重启ES并配置Canal使用HTTP

    1
    2
    3
    es.url = http://192.168.3.25:9200
    es.username = elastic
    es.password = kjoXlrSJfOv_I0c=5zkJ

验证连接

使用curl测试连接:

HTTPS连接测试:

1
curl --cacert config/certs/http_ca.crt -X GET "https://192.168.3.25:9200" -u elastic

HTTP连接测试:

1
curl -X GET "http://192.168.3.25:9200" -u elastic

注意事项

  1. 生产环境建议使用HTTPS:保持SSL加密确保数据安全
  2. 开发环境可以使用HTTP:简化配置和调试
  3. 密码管理:定期更换elastic用户密码
  4. 证书管理:妥善保管CA证书文件